It is the record of your customers, people, products and suppliers. MDM Studio is built so that this data stays isolated, access is least-privilege, sensitive fields are classified and masked, and every privileged action is on the record — on infrastructure you control.
Run many organisations on one deployment with every model, source, rule, golden record and audit entry scoped to its tenant. A tenant only ever sees its own data; there is no cross-tenant leakage and no shared record pool.
Sign in with a local password, Active Directory / LDAP, or single sign-on (OIDC) against your identity provider — chosen per user. Time-based two-factor authentication adds a one-time code on top of the password, and higher editions add SCIM provisioning and SAML.
Permissions are enforced down to the page and action for every role, so people reach exactly what their job requires — no more. Administration, stewardship, analysis and read-only consumption are cleanly separated.
Classify domains, entities, attributes and records from Public to Restricted. Per-user clearance grants control who sees what; values are masked at serve time across every surface and export, and restricted records are hidden outright — before and after publish.
Access groups control which records a person may see — scoped by domain, hierarchy tier, value hierarchy or a column value, and composed across their groups. Where clearances mask values, access groups decide which rows appear at all. One rule is applied by every surface, so counts, quality scores, queues and exports agree. A domain is governed only once armed; a refusal is a named answer, never an empty grid; and a surface a role cannot use isn't shown at all.
Connection credentials and directory service accounts are stored encrypted, never in plaintext, and a connection test never echoes a secret back. Secrets stay on your infrastructure, decrypted only in memory when a connection runs.
Every privileged action — sign-in, model and config change, approval, sensitive-data access, license change — is written to a per-event audit trail with the who, what and when, so an assessor can reconstruct exactly what happened.
Changes flow through review and approval workflows with a full audit trail; a per-model review bypass — which visibly marks when governance has been suspended — and a strict pipeline mode make Survive and Publish earn their run. Governance is enforced by the product, not bolted on beside it.
MDM Studio runs on infrastructure you control — a lean service and a modern web studio, next to the databases it masters. There is no SaaS middleman and no third-party data egress; master data, credentials and audit trails stay within your deployment's boundary.
For personal-data domains like Customer and Employee, the controls line up with what regulators ask for — data minimisation through classification, purpose-bound access through clearance, subject protection through masking and restricted-record hiding, and accountability through the audit trail.
Tag data Public → Restricted, cascading domain → entity → attribute, so the platform knows what to protect.
Per-user clearance decides who can see each level; everyone else sees masked or hidden values.
Sensitive values are masked on every screen, API and export — and restricted records are hidden outright.
Sensitive-access and every privileged action are audited, so compliance is demonstrable, not asserted.
Security isn't only about access — it's about staying up, staying observable, and being able to show an assessor exactly what happened. MDM Studio ships the operational side too.
Run clustered serving workers behind your load balancer with the scheduler pinned to one host, plus documented backup and disaster-recovery runbooks — so mastering keeps running through a node loss and recovers to a known-good state.
Live health diagnostics, a Prometheus metrics endpoint and a point-in-time metrics snapshot make throughput, queue depth and recent errors visible to your operators and to support — no server login required.
Text and interface contrast is swept across every page of the product in both the light and dark themes as part of the build, against the WCAG AA thresholds. A regression fails the build rather than shipping — and the report visual palette is measured the same way, so charts stay legible for readers who need the contrast.
Capture configuration and a metrics snapshot in a single bundle with secrets automatically redacted — safe to share with support, so an incident is diagnosed from evidence, fast, instead of guesswork.
A report is not a side channel. Sensitivity clearance, row-level access groups and tenant isolation apply to Report Studio exactly as they apply to the record screen; filter and sort keys are allow-listed against the source catalog rather than trusted from the request; and a scheduled subscription runs as the subscriber, so nobody is emailed rows they could not open themselves.
Administrators see every signed-in session and where it is, can end a session immediately, and keep a break-glass local admin so access is never lost — every action written to the tamper-evident audit trail.
We'll walk your team through isolation, identity, sensitive-data handling and deployment — and answer your assessment questionnaire.