Exactly the access they need.
No more, and not forever.
Sharing project information with another company usually means one of three bad options: email the files and lose the trail, hand over a full seat and over-share, or pay for a bespoke portal. XO Federation is the fourth. A contract between your company and theirs, grants specific down to the individual resource and action, an expiry date, and an audit trail neither side can edit.
Access is not a checkbox
A grant names the resource type, the access level and the scope, and it is evaluated on every single request.
Seventeen resource types, three access levels, four scopes
Access is resource type multiplied by access level multiplied by scope, decided per request and per resource. Not one switch labelled "partner".
It ends without anyone remembering
Contracts and grants carry an expiry, and a nightly job retires them. Access that was meant to last six weeks does not quietly last three years.
Every decision, including the refusals
Each access decision is recorded with its reason, and the trail filters by event, actor, resource and date. A refusal is evidence too.
What controlled access changes
A partner sees the resources you named, at the level you set, for as long as the contract runs.
Every allow and every refusal is on the record, with a reason, filterable when someone asks.
A legal hold freezes a contract's artifacts, and support access is requested, approved and time-boxed rather than standing.
Contracts, grants and the trail they leave
A contract between two companies, scoped to a project
The relationship is the unit, not the user account. A contract ties your company to a partner's, scoped to a project, with an expiry, and grants hang off it.
- Named down to the resourceSeventeen resource types, three access levels and four scope types
- Reusable role templatesIssue the common patterns once instead of rebuilding them per partner
- Region matching per contractCan be enforced on a contract where you need it
Queues the partner actually works in
Rather than a folder of files, a partner gets queues for the work that concerns them: RFIs, fabrication work orders, RAMS submissions, time shifts, bid and chain packages.
- Queues per work typeRFI, fabrication, RAMS, time, bid and chain packages
- Read and reply are separateLetting a partner see a thread is a different permission from letting them answer
- Refusals reveal nothingA refusal does not leak your catalogue or your policy detail
The trail, the freeze, and the way in for support
When someone asks what a partner could see and when, the answer is a filter rather than an investigation.
- Filterable audit trailBy event, by actor, by resource and by date
- Legal holdsFreeze a contract's artifacts when a dispute starts
- Support access is never standingRequested, approved, time-boxed and recorded
Frequently asked questions
How specific can partner access be?
A grant names a resource type, an access level and a scope. There are seventeen resource types, three access levels and four scope types, and the combination is evaluated on every request for every resource.
Does access expire on its own?
Yes. Contracts and grants carry an expiry and a nightly job retires them, so access granted for a package does not outlive the package.
What does a refusal tell the partner?
That they cannot do it. Refusals deliberately reveal nothing about your catalogue or your policy, so a partner cannot map what exists by probing.
Can partners reply to us?
Threads separate reading from replying, and two-way collaboration is off by default and enabled per project. A contract on its own does not open a conversation.
Can we keep data in a particular region?
Region matching can be enforced on a contract where you need it. It is a per-contract setting rather than a platform-wide default.
How does BrieXO support get access?
It is requested, approved, time-boxed and recorded. There is no standing support access to your project data.
Give them the access, keep the record
XO Federation is a paid add-on. Talk to us about the partners you need to bring in and what they should be able to see.