Limpopo Guardian Engine is a universal context-aware security layer. It turns complex relationships between users, data and objects into a single, manageable access model. Each decision depends on who is accessing the object, what action they perform and in what context, and the rules are enforced at the data level, independently of the application interface.
The system answers one question: may this user perform this action on this object in this context? It considers not only who does what, but also under which conditions.
Organization, project or scope, group, role and the scope of that role, object publication, ownership, delegated access, object type and the specific action.
Access is determined not by a single property of the user or the object, but by their relationships and the current context of the interaction.
The decision is made for the requested object and context, not for the open screen. Rules are not hard-coded into application business logic.
Guardian is not tied to any one domain. The same mechanism controls access to documents and projects in PLM, to knowledge chunks and sources in RAG, and to customer data in SaaS.
Policies are enforced with PostgreSQL Row-Level Security. Different applications and services rely on one access model and do not duplicate it.
We consult on users, objects and access contexts in your applications. Limpopo Guardian Engine is preparing for launch, and you can already discuss how to build a single access model for your data.
Describe your systems, roles and the database you use — we will come back with a proposal for a context-based access model.