Coactix is in early access. The security model described here reflects what is built today. We are not yet SOC 2 audited or certified.
Coactix isn't a replacement for your existing systems. It's a controlled collaboration layer that bridges the gaps between them. We operate on the principles of neutral ground, least-privilege access, and clear shared visibility.
Keep your Jira, Salesforce or ServiceNow. Coactix is designed to sit alongside those systems as a neutral bridge, not replace your internal team's workflow.
Participants see the shared cases and context they are authorised to access. Internal notes are designed to remain internal through role-scoped visibility.
Status changes, evidence uploads and shared comments are recorded on the shared case timeline for operational review.
Participant visibility is case-scoped, so external organisations do not see unrelated cases, internal notes or another participant's private activity.
Trust isn't about sharing everything. It's about sharing the right things at the right time. Coactix maintains a strict boundary between internal operations and shared collaboration.
Coactix does not let AI silently close cases, publish customer updates or invite external organisations. Human operators remain responsible for routing, approvals and customer-facing wording.
Operator review remains part of intake and participant routing.
Customer-safe updates are prepared and reviewed before release.
AI-assisted extraction and prompts remain tied to the case record.
Coactix starts with manual coordination and has a clear path toward deeper system integrations.
Bring invited organisations into a shared web UI. Capture updates, ownership and evidence in a structured shared case.
Planned and setup-dependent connectors for Jira, ServiceNow and Zendesk will let Coactix updates flow into internal tasks.
Planned telemetry-assisted incident creation and evidence checks for teams with connected site infrastructure.
Cloud-hosted application architecture with organisation-scoped access boundaries and explicit sharing rules.
Email and password authentication today. Enterprise SSO and MFA are planned capabilities, not active in early access.
Shared case data and evidence metadata are stored in Supabase tables with RLS policies. Per-update cryptographic hashing is not part of early access.
Organisation isolation is enforced with Supabase Row-Level Security and explicit shared case participation links.
Ticket activity is captured in audit events for operational review. SOC 2 and ISO 27001 readiness work are future scope, not current certifications.
Granular permissions at the organisation, workspace and shared case level. Guests only see cases they are explicitly invited to.