Role-based visibility
A user should access a case only when ownership, organisation, assignment or administrative permission allows it.
Valentry is designed for regulated insurance work where access, versions, decisions, evidence and report integrity must remain clear long after the task is complete.

Valentry applies control through permissions, versioning, audit events, governed review and protected report access. Deployment-specific architecture and contractual commitments are confirmed during implementation.
A user should access a case only when ownership, organisation, assignment or administrative permission allows it.
Important login, case, file, analysis, review, report and administrative actions should remain recorded and attributable.
Completed analyses create new versions. Final reports remain immutable and tied to the exact analysis version used.
Users should be authenticated, authorised for the case and limited to reports that are available and not revoked.
User credentials, personal information, insurance documents, analysis results, reports and organisation data are protected by design.
Reviewers can approve, reject, request information and record quality or compliance concerns against the relevant version.
This simplified matrix shows the role separation between standard users, reviewers, organisation administrators and platform administrators.
| Capability | Standard user | Reviewer | Organisation admin | Platform admin |
|---|---|---|---|---|
| Create and manage permitted cases | Yes | Yes | Organisation scope | Permitted scope |
| Upload and categorise documents | Yes | Yes | Organisation scope | Permitted scope |
| Approve or reject analysis | Not by default | Yes | Role dependent | Role dependent |
| Mark reports final | If permitted | If permitted | If permitted | If permitted |
| Manage organisation users | No | No | Yes | Yes |
| Manage prompts, schemas and templates | No | No | Configured scope | Yes |
| View audit and job monitoring | Own activity | Relevant work | Organisation scope | Administrative scope |
The model should show what documents were used, which workflow and version produced the output, what information is missing and who approved the final client-facing result.
Confirm access, required information, documents, credits and that no conflicting analysis is running.
Show queued, extracting, processing, analysing, validating, saving and report-generation stages.
Present policy detail, exclusions, warranties, gaps, risks, recommendations, missing information and confidence context.
Approve, approve with changes, reject or request more information with notes and quality concerns.
Generate the report from a selected analysis version and preserve every previous report version.
Production trust depends on verified implementation details, not only polished interface copy.
No ISO 27001, SOC 2 or other third-party certification claim is made on this website. Independent assurance is stated only when formally verified.
Role and permission management, organisation boundaries, assignment and administrative access are stated platform requirements. Exact permission sets are configured and tested during implementation.
Completed analysis versions should not be edited, final reports should not be overwritten and significant audit records should remain protected from alteration.
The workflow includes eligibility checks, visible progress, structured results, versioning, reviewer decisions and a rule that client-facing advice remains subject to authorised human review.
This static website does not specify a production hosting region or provider. Hosting location, subprocessors, encryption, backups, retention and incident processes must be documented in the production agreement.
The platform uses POPIA-aware handling and protection of personal information. Legal compliance also depends on implemented controls, contracts, operator relationships and each organisation’s own lawful processing practices.

A serious product conversation should include permissions, audit events, versioning, AI review, report control, hosting and data-processing responsibilities — not avoid them.