XO Federation

Exactly the access they need.
No more, and not forever.

Sharing project information with another company usually means one of three bad options: email the files and lose the trail, hand over a full seat and over-share, or pay for a bespoke portal. XO Federation is the fourth. A contract between your company and theirs, grants specific down to the individual resource and action, an expiry date, and an audit trail neither side can edit.

Access expires on its own
Every decision recorded
Refusals give nothing away
Legal holds freeze the record
Why It Matters

Access is not a checkbox

A grant names the resource type, the access level and the scope, and it is evaluated on every single request.

Seventeen resource types, three access levels, four scopes

Access is resource type multiplied by access level multiplied by scope, decided per request and per resource. Not one switch labelled "partner".

It ends without anyone remembering

Contracts and grants carry an expiry, and a nightly job retires them. Access that was meant to last six weeks does not quietly last three years.

Every decision, including the refusals

Each access decision is recorded with its reason, and the trail filters by event, actor, resource and date. A refusal is evidence too.

Outcomes

What controlled access changes

01

A partner sees the resources you named, at the level you set, for as long as the contract runs.

02

Every allow and every refusal is on the record, with a reason, filterable when someone asks.

03

A legal hold freezes a contract's artifacts, and support access is requested, approved and time-boxed rather than standing.

Features

Contracts, grants and the trail they leave

A contract between two companies, scoped to a project

The relationship is the unit, not the user account. A contract ties your company to a partner's, scoped to a project, with an expiry, and grants hang off it.

  • Named down to the resourceSeventeen resource types, three access levels and four scope types
  • Reusable role templatesIssue the common patterns once instead of rebuilding them per partner
  • Region matching per contractCan be enforced on a contract where you need it
Setup is deliberate. Federation is a paid add-on, and switching it on takes an operator step rather than a toggle. It is not something a project quietly ends up with.
How a grant is decided
Resource type×Access level×Scope
17resource types
3access levels
4scope types
Evaluated per request, per resource

Queues the partner actually works in

Rather than a folder of files, a partner gets queues for the work that concerns them: RFIs, fabrication work orders, RAMS submissions, time shifts, bid and chain packages.

  • Queues per work typeRFI, fabrication, RAMS, time, bid and chain packages
  • Read and reply are separateLetting a partner see a thread is a different permission from letting them answer
  • Refusals reveal nothingA refusal does not leak your catalogue or your policy detail
Two-way collaboration is opt-in. Partners replying into your project is off by default and enabled per project, so a contract alone does not open a conversation you did not intend.
Partner queues
RFIs
Fabrication work orders
RAMS submissions
Time shifts
Bid packages
Chain packages

The trail, the freeze, and the way in for support

When someone asks what a partner could see and when, the answer is a filter rather than an investigation.

  • Filterable audit trailBy event, by actor, by resource and by date
  • Legal holdsFreeze a contract's artifacts when a dispute starts
  • Support access is never standingRequested, approved, time-boxed and recorded
Emergencies are time-boxed too. If enforcement has to be relaxed, the relaxation is bounded and reverts on its own rather than waiting for someone to remember.
Access decision log
PermittedDrawing revision, read, project scope
PermittedRAMS submission, write, package scope
RefusedCommercial record, read, out of scope
RefusedDrawing revision, write, contract expired
Filter by event, actor, resource or date. Refusals carry their reason without revealing what else exists.
FAQ

Frequently asked questions

How specific can partner access be?

A grant names a resource type, an access level and a scope. There are seventeen resource types, three access levels and four scope types, and the combination is evaluated on every request for every resource.

Does access expire on its own?

Yes. Contracts and grants carry an expiry and a nightly job retires them, so access granted for a package does not outlive the package.

What does a refusal tell the partner?

That they cannot do it. Refusals deliberately reveal nothing about your catalogue or your policy, so a partner cannot map what exists by probing.

Can partners reply to us?

Threads separate reading from replying, and two-way collaboration is off by default and enabled per project. A contract on its own does not open a conversation.

Can we keep data in a particular region?

Region matching can be enforced on a contract where you need it. It is a per-contract setting rather than a platform-wide default.

How does BrieXO support get access?

It is requested, approved, time-boxed and recorded. There is no standing support access to your project data.

Give them the access, keep the record

XO Federation is a paid add-on. Talk to us about the partners you need to bring in and what they should be able to see.