Security built in. Governance enforced.

Certyze holds accreditation-critical data — client records, audit findings, auditor competency, and certificates. Every role, every assignment, and every change is controlled and logged by the system itself, not left to policy documents nobody checks.

Access control

Role-Based Access Control, down to the individual permission.

Every user in Certyze — Head Office, franchise rep, auditor, or client — operates inside a role scoped to exactly what they need, nothing more.

HO

CB Admin / Head Office

Full visibility and approval authority across every client, franchise location, and audit.

FR

Franchise Representative

Executes client intake and activity up to audit stage; key decisions route back to Head Office.

AU

Auditor

Sees only assigned audits, within the schemes and IAF codes they're approved for.

CL

Client

Restricted to their own application, audit status, NCs, and certificate — nothing else.

The four pillars

Security and governance, working together.

Role-Based Access Control

Granular, role-scoped permissions control exactly what each user can view, edit, or approve — enforced at the record level, not just the menu level.

  • Separate permission sets for Head Office, franchise reps, auditors, and clients
  • Instant access revocation and deactivation when a user leaves or changes role
  • No user can act outside their assigned scope, by design

Complete Audit Trail

Every change — who changed what, when, on which record — is logged and traceable, so the system itself stands up to Accreditation scrutiny.

  • Record-level history on clients, audits, NCs, and certificates
  • Immutable change log, not an editable spreadsheet
  • Built for Accreditation Body oversight visits, not just internal review

System-Wide Activity Log

Head Office gets a running view of user activity across every franchise location — logins, submissions, approvals, and assignments — not just per-record history.

  • Cross-franchise visibility into who did what, and when
  • Surfaces unusual activity before it becomes a compliance problem
  • Supports internal reviews without chasing down individual users

Governance: Auditor Validation & Assignment

The Resource Matrix is the enforcement layer behind every audit — not a reference document, a hard gate.

  • An auditor not approved for a scheme, IAF code, or technical area cannot be assigned to it
  • Conflict-of-interest (COI) declarations checked before assignment, not after
  • Franchise decisions route to Head Office for approval before they take effect

Data handling built for accreditation-critical information.

Encryption in transit, role-based access at every layer, and continuous review of safeguards as the platform evolves — see the full details in the Privacy Policy.

ISO/IEC 17021-1ISO/IEC 17025ISO/IEC 17065IAF MD Documents

Ask us about security on your own schemes.

Bring your standards, your scope, your franchise structure — we'll walk through exactly how access, audit trail, and governance apply to your program.