Identity
Who Is This Person?
Maintain the user account, profile, authentication context, contact information, and appropriate relationship with the organization.
Brilliance One Users
Manage users, identities, roles, permissions, security groups, profiles, account relationships, departments, module access, and operational responsibilities from one connected platform.
Brilliance One Users connects platform access with the employee, customer, vendor, contractor, partner, organization, or other real business relationship behind the login.

Identity & Access
Brilliance One connects authentication and access with the relationships, departments, roles, modules, responsibilities, and business workflows that explain why a user needs the system in the first place.
Identity
Maintain the user account, profile, authentication context, contact information, and appropriate relationship with the organization.
Responsibility
Connect users with employees, customers, vendors, contractors, partners, departments, teams, projects, locations, and other business responsibilities.
Access
Apply roles, permissions, security groups, module access, administrative controls, and other supported visibility rules according to responsibility.
Beyond Login Management
User management becomes more useful when access is connected to the person, organization, employment relationship, customer account, vendor relationship, or operational role behind it.
Identity + Business Context
Brilliance One separates identity from authorization while allowing both to remain connected to the underlying business relationship.
That makes the user record part of the Business Operating System instead of simply a username with a collection of switches.
User Relationships
Different people can interact with the same business for very different reasons. Their access should reflect the relationship they actually have with the organization.
Relationship-Aware Identity
A platform identity can connect with the underlying customer, employee, vendor, contractor, supplier, partner, organization, department, or other relationship that gives the access business meaning.
Relationship Context
An employee may need internal operational access. A customer may need a portal. A vendor may need access to specific records. A contractor may participate in one project without seeing unrelated company information.
Linking identity with the real relationship helps Brilliance One keep access, communication, history, and responsibility understandable.
User vs. Employee
Human Resources describes the employment relationship. Users controls access to Brilliance One. Connecting them allows both records to remain useful without forcing them to become the same thing.
Employee
Represents employment status, department, manager, role, location, training, attendance, reviews, documents, responsibilities, and other workforce context.
User
Represents authentication, roles, permissions, modules, security groups, administrative privileges, preferences, and the ability to use Brilliance One.
Roles
Roles can group repeatable access patterns so users performing similar work do not require every permission to be configured independently.
Reusable Access
Role-based access can reduce repetitive administration when multiple users need similar module, action, data, and workflow permissions.
Individual exceptions can still be handled where the permission model supports more specific control.
Permissions
Permissions provide more specific control over which modules, records, actions, tools, administrative functions, and sensitive workflows are available to an authenticated user.
Modules
Control which supported Brilliance One modules and functional areas are available to a user or role.
Actions
Limit appropriate create, update, approval, administrative, financial, export, configuration, or other supported actions according to responsibility.
Data
Apply supported rules that help restrict sensitive customer, employee, financial, document, firearms, project, or other information to appropriate users.
Administration
Restrict security, settings, users, licensing, integrations, billing configuration, exports, and other higher-impact administrative capabilities.
Documents
Use supported document and module permissions to help keep appropriate files visible only to users who require them.
Operations
Align supported permissions with the work users are expected to perform instead of giving every authenticated person the same level of access.
Least Necessary Access
A connected Business Operating System can contain customer, accounting, HR, project, document, POS, firearms, administrative, and other sensitive information. Access should reflect responsibility.
Permission Strategy
Adding more modules to Brilliance One should not mean every user automatically gains access to every new capability.
Roles, security groups, module permissions, and supported record-level controls help maintain separation as the platform expands.
Security Groups
Security groups can help administrators apply related access controls to collections of users whose responsibilities require similar treatment.
Department
Group users around sales, accounting, HR, operations, technology, customer service, or other organizational functions where appropriate.
Management
Provide additional visibility or administrative capability to users responsible for supervising a team or operational area.
Specialized
Use appropriate access groups around financial, HR, firearms, security, document, or other specialized information.
User Profiles
Profiles can provide the display, contact, organization, department, role, communication, and presentation information used across supported internal and external experiences.
Maintain supported name, title, role, and presentation information.
Associate appropriate email, phone, address, and other communication information.
Connect the user with the company, customer, vendor, partner, department, or team they represent.
Represent the user's responsibilities and access within the platform.
Maintain supported user-specific presentation, notification, or communication preferences.
Associate appropriate user activity with broader business workflows and operational records.
Role-Aware Experience
Supported dashboards, navigation, modules, and workspace experiences can reflect the user's permissions, responsibilities, relationship, branding, and available capabilities.
Focused Workspace
The platform can contain many capabilities while individual users remain focused on the modules and information relevant to their responsibilities.
Broad platform capability does not have to create broad user complexity.
Access Lifecycle
User access is not a one-time decision. Roles, departments, assignments, employment, customer relationships, projects, and responsibilities can all change over time.
Create the identity, connect the appropriate relationship, assign roles, establish permissions, enable required modules, and provide the initial workspace.
Adjust roles, permissions, modules, departments, teams, relationships, administrative privileges, and responsibilities as the person's work changes.
Remove, restrict, or disable access when the person no longer requires the same privileges while preserving appropriate historical business records.
User Onboarding
User setup can connect identity, relationship, role, department, permissions, modules, security requirements, and workspace responsibilities instead of treating account creation as an isolated IT task.
Consistent Provisioning
Roles and reusable permission structures can reduce repetitive setup while still allowing administrators to review access appropriate to the individual.
The objective is consistent access without blindly cloning privileges that the new user does not need.
User Offboarding
When an employee, contractor, partner, vendor, or other user no longer requires access, the platform identity can be restricted or disabled without erasing the legitimate business history associated with that person.
Identity History
Project work, customer communication, approvals, documents, sales activity, accounting actions, and other historical records can still require attribution after the user's access ends.
Access lifecycle and business-history lifecycle are related, but they are not identical.
Authentication
Brilliance One Users relies on the shared Security foundation for credential protection, authentication, account controls, sessions, and other supported identity protections.
Credentials
Use Argon2id password hashing with unique salts and additional application-level protection to help protect stored credential material.
Multi-Factor
Where enabled, multi-factor authentication adds another verification requirement beyond the primary account credential.
Sessions
Session validation, expiration, account controls, authorization checks, and other supported protections help govern ongoing authenticated access.
Authentication + Authorization
Successfully proving identity should not automatically provide unrestricted access to every function and record in the platform.
Identity Is Not Permission
Authentication and authorization solve different security problems.
Brilliance One keeps both connected so the platform can know who the user is while separately evaluating what that user should be permitted to access.
Users + Human Resources
When the user is also an employee, Brilliance One can connect application identity with the workforce record describing department, role, manager, location, training, availability, and other employee context.
Employment
Keep employment context in HR while connecting the appropriate employee to the user identity responsible for platform access.
Responsibility
Use organizational role and department context when administrators evaluate which platform capabilities the employee requires.
Lifecycle
Coordinate access decisions with appropriate workforce changes while maintaining separate historical records for employment and system activity.
Users + Technology
Employee onboarding and offboarding can involve application access as well as laptops, phones, vehicles, tools, equipment, software, and other technology resources.
Digital + Physical Access
Technology can identify equipment assigned to the employee while Users governs the application identity and Human Resources preserves the employment context.
That is the advantage of connecting workforce, access, and asset operations inside the same system.
Users + Projects
Project activity can retain appropriate user context around ownership, tasks, approvals, communication, documents, updates, and other delivery activity.
Ownership
Associate projects, tasks, milestones, or other supported responsibilities with the users or employees responsible for them.
Access
Use applicable permissions and project visibility to help restrict information according to responsibility.
History
Preserve available user context around supported project activity and operational changes.
Users + Scheduling
Where configured, user and employee context can participate in scheduling workflows involving availability, appointments, service responsibility, teams, and operational calendars.
Person + Schedule
Users provides identity and access while Human Resources and Scheduling provide the workforce and calendar context around the person performing the work.
External Users
Customers, vendors, contractors, partners, and other external users may need access to selected information without gaining visibility into unrelated internal operations.
Customers
Provide supported portal or customer-facing access connected to the appropriate CRM relationship and authorized information.
Vendors
Provide appropriate vendor or supplier access where workflows require external participation.
Contractors
Give contractors access to supported projects, records, documents, or workflows required for their work without exposing unrelated areas.
Users + Security
Brilliance One applies the shared Security foundation around authentication, authorization, credentials, sessions, administrative access, permissions, logging, and sensitive workflows.
Access Foundation
Users establishes identity context. Security applies the controls responsible for verifying that identity and determining whether the requested action should be allowed.
User & Access History
Available user, permission, security, administrative, and operational history can help organizations understand important access changes and activity over time.
Maintain appropriate information around active, restricted, disabled, or other configured user states.
Preserve available context when a user's organizational or access role changes.
Maintain available administrative information around significant access changes.
Record supported higher-impact user and access-management actions for authorized review.
Use supported authentication and security history when investigating access concerns.
Keep available user context around important business activity performed throughout the platform.
Access Governance
People change jobs. Employees leave. Contractors finish projects. Vendors change. Customers close accounts. Administrative responsibility moves between people.
Access Is Temporary
Brilliance One provides identity and access controls, while the organization remains responsible for determining which users should have which privileges.
Periodic access reviews help keep old responsibilities from becoming permanent privileges.
No Per-User Platform Pricing
Brilliance One standard platform pricing is based on Core and the business modules the organization activates rather than charging another recurring platform subscription simply because another authorized user needs an account.
Pricing Philosophy
The organization should be able to give the right employees appropriate access without evaluating whether every additional user is worth another recurring software seat.
No per-user pricing does not mean unrestricted access. Authentication, roles, permissions, security groups, and module controls still determine what each user can do.
Connected Identity
User identity and access context can participate across CRM, HR, Projects, Scheduling, Technology, Accounting, Communications, Courses, Security, Documents, POS, and other Brilliance One workflows.
Accounts
Connect user identity with customers, vendors, partners, suppliers, contractors, organizations, and other relationship records.
Human Resources
Connect employee records with appropriate user identities, roles, departments, permissions, and workspace responsibilities.
Projects
Use identity context for project ownership, task responsibility, updates, documents, approvals, and delivery activity.
Scheduling
Associate appropriate users and employees with schedules, availability, appointments, services, and operational responsibility where configured.
Technology
Connect employees and users with laptops, devices, vehicles, tools, equipment, software, and other supported operational assets.
Accounting
Apply appropriate identity and access controls around financial information, approvals, payment activity, vendors, reporting, and administrative accounting actions.
Courses
Connect appropriate employee or user identity with course participation, training, completion, certification, and learning history.
Documents
Apply appropriate identity and permission context around business documents and sensitive supporting files.
Security
Use the shared security foundation for credential protection, sessions, permissions, security groups, administrative access, and security history.
Identity Platform Strategy
Modern CRM and customer platforms already provide sophisticated user administration, teams, permission sets, module controls, assigned-record visibility, and granular permissions. Brilliance One extends identity and access into a broader combination of CRM, ERP, workforce, commerce, content, projects, assets, industry workflows, and other business operations.
Identify
Connect the user identity with the employee, customer, vendor, contractor, partner, department, or organization the person represents.
Authorize
Apply the access required for the person's modules, records, actions, responsibilities, and administrative functions.
Operate
Use that identity across projects, schedules, HR, technology, documents, accounting, communications, training, commerce, and other operational workflows.
Identity Controls
A useful identity system should establish who the user is, connect the user to the appropriate business relationship, limit access according to responsibility, and preserve useful history around significant activity.
Authentication
Use protected credentials, multi-factor authentication where enabled, sessions, account controls, and other supported security measures.
Authorization
Apply roles, permissions, security groups, module access, record rules, and administrative controls according to responsibility.
Relationships
Associate users with the employee, customer, vendor, supplier, contractor, partner, department, or organization behind the access.
Experience
Use available modules, permissions, dashboards, navigation, branding, and preferences to keep the user experience appropriate to the person's responsibilities.
Lifecycle
Provision, adjust, review, restrict, and disable user access as relationships and responsibilities change over time.
Accountability
Maintain available identity and user context around supported business, administrative, and security activity.
Brilliance One Core
Core provides the relationship, communication, automation, identity, security, configuration, and administrative capabilities that support the broader Brilliance One Business Operating System.
CRM & Relationships
Manage customers, prospects, leads, organizations, contacts, vendors, suppliers, partners, and relationship history through one connected business record.
Explore AccountsLocations
Maintain billing, shipping, service, customer, employee, vendor, job-site, and operational locations as reusable records connected to the business activity that depends on them.
Explore AddressesEmail, SMS & Messaging
Connect email, SMS, MMS, campaigns, templates, lists, replies, delivery activity, and communication history with the customers and business records behind every conversation.
Explore CommunicationsWorkflow Automation
Automate supported email, SMS, tagging, notifications, delays, follow-up, and repeatable processes so people can focus on decisions while software handles routine work.
Explore AutomationsIdentity & Access
Manage identities, roles, permissions, security groups, profiles, account relationships, module access, authentication, and operational responsibilities across Brilliance One.
Explore UsersPlatform Protection
Protect business information with authentication, authorization, roles, permissions, security groups, encryption, session controls, logging, monitoring, and administrative safeguards.
Explore SecurityPlatform Configuration
Configure organization defaults, branding, permissions, communication providers, payment services, AI preferences, integrations, module behavior, and shared platform settings.
Explore SettingsData Operations
Import, export, map, validate, review, migrate, clean, and maintain supported business information with administrative workflows designed for controlled data operations.
Explore ToolsBrilliance One Users
Connect employees, customers, vendors, contractors, partners, administrators, roles, permissions, security groups, profiles, modules, authentication, relationships, and operational responsibilities through the shared identity foundation of Brilliance One.
Brilliance One • Users • Identity • Roles • Permissions • Access