Security & administration

Accounts and access

How company-scoped records, roles, and permissions control who can see or change a project in the authenticated application.

Updated 2026-08-23

Access in Infrenta is organization-scoped. A user signs in to the authenticated application, not the public marketing site. Session, company membership, and role determine which projects and workflows they can open.

This page describes the access model customers should expect. The Security Trust Center is the public statement of controls. The Privacy Policy covers Customer Data.

Accounts

People receive access when an administrator invites them into a company. There is no self-serve checkout that creates a production workspace from the marketing site. Onboarding is provisioned as part of the commercial agreement.

The marketing host and the application host are separate. Signing in happens on the application host.

Company boundary

Customer records are associated with companies. Supported data paths use membership checks so one organization cannot read another organization’s projects, estimates, documents, or field records.

Treat “not found” and “not allowed” as equivalent when diagnosing access issues. Do not probe another tenant.

Roles and permissions

Authorized users receive role- and permission-based access inside their organization. Administrators grant, change, or revoke that access. Module visibility is permissioned — not every user sees Estimating, GeoLab, Procurement, Project Controls, or Execution.

Exact role names can vary by implementation. The contract is that access is granted, not assumed.

Project access

A project is not a public object. It lives in the authenticated application. Users see projects their company membership and permissions allow. Downstream records — estimates, RFQs, budgets, daily reports — inherit that project scope.

Authentication

Sign-in and sessions use managed authentication (Supabase Auth). Enterprise sign-in options are discussed during implementation. See Authentication if you are scoping a system integration, and Security for the public control summary.