CRM
✓ Contacts
✓ Companies
✓ Pipeline
✓ Approved fields only
✕ Delete not permitted
Tandem security
Tandem is designed around scoped access, clear permissions, human approval and observable workflows so AI can support your team without becoming an uncontrolled layer across the business.
Access should be deliberate. Actions should be visible.
Least privilege
Tandem should receive the minimum access required to perform an agreed workflow. More access is not automatically better.
Client-controlled access
Not every vendor supports service accounts or identical controls.
Credentials
Passwords and API keys should not be pasted into prompts or committed to source control. Appropriate server-side secret systems, separation, rotation and revocation should be used.
The code can be shared or reviewed without exposing credentials.Client separation
Reusable technology can be shared. Client data should not be.
Separation should cover configuration, credentials, API projects, tenant boundaries, environments, logs, documentation and client-specific instructions.
Source of truth
Important business state should remain tied to an agreed authoritative system using stable identifiers, duplicate checks and approved write-back where appropriate.
Explore integrations →Permissions and approvals
An approval screen should not be the only control. Underlying permissions should also limit what an agent can do.
See approval workflows →Activity logging
Observable workflows are easier to trust, support and debug. This is illustrative, not a claim of immutable or regulatory-grade auditing.
Data minimisation
The client's legal and privacy obligations remain theirs; implementations should support those requirements.
Sensitive data
Environment progression
A working demo is not the same as a production-ready workflow.
Production changes
Material changes to permissions, authority, integrations, scoring, workflows, prompts or data models should be reviewed and tested.
A practical control pattern, not a claim of certified enterprise change management.
Recovery
Access reviews
Does this integration still need access?
Does this user still approve?
Does this workflow still need write permission?
Has a staff member left?
Has the process changed?
Offboarding
Offboarding is a deliberate process, not presented as automatically complete.
Implementation review
Integration security
CRMRead + approved enrichment
EmailSelected context + draft
CalendarRead meetings
CollaborationInternal alerts
AccountingNo access · not required
AI-specific safeguards
Untrusted content
Emails, documents, websites and forms may contain text that must not override approved rules.
Public workflows
Public forms and endpoints should use controls appropriate to their exposure. This is design guidance, not a claim these protections are universally live site-wide.
Honest claims
If a client requires a particular standard, we review it before agreeing the implementation.
Tandem does not claim certifications or controls unless they have actually been achieved and verified.
Enterprise requirements
These requirements may affect architecture, scope and pricing; they are not presented as standard features.
Incident response
This is a responsible response pattern, not a claim of a 24/7 SOC or guaranteed SLA.
Security FAQ
Detailed requirements are reviewed during implementation.
No. Access should be limited to the systems and permissions required for the agreed workflow.
They should be stored in appropriate server-side secret or environment systems, not prompts or public source code.
Only if explicitly permitted. High-risk actions can remain prohibited or human-only.
Where the underlying system supports it, access can be removed or credentials rotated.
Tandem does not currently present itself as certified. Client-specific requirements are reviewed during scoping.
Implementations should use appropriate data-protection controls, but compliance depends on the processing, systems, client obligations and contracts. Requirements must be reviewed for each implementation.
Potentially, depending on technical and security requirements and the agreed architecture.
Clear boundaries
Take the free Tandem Assessment and identify where AI could support your business with the right controls around access, approval and risk.