Skip to main content
Every partner program runs on trust, and trust starts with access. Decide exactly what your internal team can do, what each partner’s people can do, and how everyone signs in, all configured by your team without engineering.

The problem it solves

Impact

Partners notice a program that lets them run their own side of it. Adding their own colleagues and signing in with their own identity is a small thing that decides whether they use the portal at all.

How this area works

Access and security covers three capabilities. Provisioning is how people get in: partners, their owners, and their contacts sync live from your CRM, and your own team is created, given a role, and deactivated through single sign-on and SCIM. Team management is where you invite your internal team, assign roles built from clear permission categories, and limit users to the partners they own. It is also where you define partner team roles and assign the people who manage each partner. Single sign-on lets your own team and your partners log in through your identity provider, so access follows your existing security policies. Where this sits in a setup. Access is foundation work: every setup track does it before anything a partner sees, because a portal nobody can get into is not a program. All three are configured by partner operations and admins directly, with no code, and the permissions you set apply consistently across every surface a user touches.
These permissions also scope Introw’s AI agents. When an assistant connects over MCP, its data access follows the signed-in user’s partner scope - a partner’s assistant reaches only that partner’s data. What an agent may do on its own is governed by a vendor-configured capability matrix, with sensitive actions kept behind human approval.

Introw’s own access to your organisation

Security reviews ask this one, so it is worth stating plainly. Introw support can, by default, sign in as one of your users to reproduce a problem, and use internal CRM tooling against your connected CRM to diagnose a sync. Both are audited. Either can be switched off for your organisation. Ask your Introw contact and we set it on our side, per organisation:
  • Impersonation off means no Introw employee can sign in as one of your users or your partners’ users, for any reason.
  • CRM tools off means Introw’s internal CRM tooling cannot be pointed at your connected CRM. It can also be narrowed to a named list of Introw staff instead of switched off entirely, so a nominated support contact keeps working while nobody else can.
Turning them off is a real trade-off, not a free win. With impersonation off, “can you see what my partner sees” becomes a screenshare rather than something support can check alone. Expect slower diagnosis on portal-specific issues. Regulated programs usually take that trade; most do not need to.

Run it from your AI assistant