AyMINE – Technical documentation
Interfaces to other systems
Enterprise Architect Connector
Business excelenece
Balance Scroecards
Task & Project Control
- Send customer answer in regards to the complaint
- Bundle of Documentation and records
- Test
- Qualification of user or contact
- Project role
- What are the parts of the QMS documentation and model
- dragdrop
- Location
- My areas
- Kanban Task Overview
- Personal Task
- Internal helpdesk
- Customer Care Centre
- Project baseline
- Return project plan by baseline
- Project Schedule
- Processing time sheets
- Project management items
- Activation buttons
- Why some data can't be deleted
- Starting events
- Qualification of user or contact
- task_taskobjects
- Project
- Reminders and Messages
- eventobj_raisingevents
- decision_decobjects
- eventobj_startingevents
- eventobj_eventbuttons
- Hierarch of testing and developing tests from requirements
- Deal management
- FMEA criteria for detection evaluation
- FMEA system functionality analysis
- Methodology how to conduct FMEA
- FMEA analysis of the failure occurence
- Analysis of the FMEA Severity
- Support for FMEA Analysis
- Management of responsibilities - RACI Matrix
- RACI matrix for project
- Improvements and Preventive Measures
- Notice – example of use
- tskproblem_terminology
- 8D report - quality problem resolution
- Task Scheduling to the right time and scope
- Administration of the Task Management Module
- Adminitration of areas, projects, calendars
- Discussion
- System rights for the task management module
- Project Planning
- Employee Tasks
- Incident and Quality Issue Management
- Collaborative Resolution of Multiple Problems
- List of business areas
- Required qualifications
- Plan template / strategy
- Decision
- Configuration Package
- Record template
- Change management process in a project
- Task list
- Requirements
- Team Member
- Right to Manage Qualifications
- Obligation
- Competencies and Skills
- Problems, tickets and their management
- Meeting
- Package definition
- Phrases and terms in QMS
- Data Area
- Risk
- Task
- Business event
- Task, project & quality management
- Records and protocols
- Directives and Policies
- Events
- Risk Pattern
- Information
- Project definition
- Activity log
- eventinstances
- Personal calendar
- Objects of decision making
- Event activation buttons
- Objects affected by the problem
- Variant decision-making
- Recorded activities
- Self-Reminders
- Assignment of a New Task According to Methodology
- Objects related to the task pattern
- Effect of the task on the right to modify the atta
- Level of Competence
- Manager approval with the task report
- Region / project / methodology
- Manage your marks
- Task patterns saves work and improve quality
- Quality Management System (QMS)
- Task planning both in project and daily business
- Project Team
- Events and meetings
- Events and meetings
- List of event instances
- moduleclientoptions
- Processed objects
- Mark patterns
- Notification events
Interprocess management
Human Resources
- roles
- Staffer / Worker Management
- Human resources
- Employee access to the contract files
- Personalistics - User Permissions and roles
- Candidates Management
- Manage department / division data
- Job Position
- Employee dashboard with personal data
- An overview of your staff
- Responsible HR Manager
- Synchronizing staff and system users
- Management of the staffer contracts
- Safety of the HR module
Asset Management
- Products, assets and sales
- Tendering and purchasing
- Analytical model
- Product Supplier
- Product Categories
- Product or Product Property
- Manage projects by goals
- Create offer for premium or B2B clients
- Offers summaries
- Create and recalculate offer using price lists
- Offer and Price Access Rights
- Creating and processing orders
- System order status query
- Order Reports
- Pricing
- Pricing – volume discounts
- Products and Goods
- Product status and change
- Product Units
- Quality criteria
- Why are the Quality criteria usefull
- DFEMA - FMEA of the product design
- HARA for product
Customer Relationship - CRM
- Contacts and directories module (
- System Permissions and CRM Module Settings
- Customer Order Overview
- Address books
- Address book list and management
- Privacy policy
- Send bulk messages in compliance with GDPR
- Bulk email footer
- Unsubscribe and set preferences
for bulk mail - How to correctly forget a person's details
- Bulk Emails
- Contracts
- Partner in a contract
- Message patterns
- Group of contacts from address books for better management
- Directory or people and companies
- Contact per person or company
- Quickly available contacts
Finance management
System modules
System management
- moduleclientoptions
- Electronic sign even on mobile device
- formattedtexts
- System Configuration
- Processes in use
- Client
- Member Management for churches, non-profit organisations
- Configure gateways for external messages
- Corporate email and communication processing
- Email messages
- Rules for external messages
- Secure business communication
- Send SMS directly from CRM
- Call directly from CRM
- Documents and files
- Additional functions with files
- Copying and moving files between objects
- Picture presentation
- Public link to the document
- Recent Files
- Dashboard
- Object location on the board
- Client items
- Revisions and comments
- Securing posts and internal discussions
- Translations
- Record Relationships
- Relation types
- System Groups and Teams for rights settings
- User Processes
- System module
- System User
- User administration
- User Administration
- Connecting users to VOIP PBX
- Trusted User Device
- Secure Key Wallet - Safe storage for digital keys
- Data vault for Company secret & Classified data storage
Framework
- frmobjectextension
- introhelp
- introhelp_mobile
- introhelp_aplikace
- versioninfo
- releases
- AyMINE modules and basic types
- cliplink
- introhelp_settings
- introhelp_deleting
- introhelp_dragdrop
- list_filtering
- Short AyMINE framework introduction
- AyMINE Access control and security
- AyMINE Modules
- Object locks
- System rights
- AyMINE Gestures and Keyboard Shortcuts
- AyMINE icons are language for fast orientation
- list
- introhelp_generalinfo
- introhelp_objectdetail
- introhelp_objectlist
- introhelp_privateobjectnotes
- AyMINE User Rights Control
- introhelp_dashboard
Secret Management
Protecting credentials, login data, and other secrets within an organization requires end-to-end encryption tools
Security of Secret Protection
Organizations need to store various credentials, codes, and passwords. On one hand, they need to ensure maximum protection for them; on the other hand, their availability must not depend on a specific employee and must be accessible when needed.
Examples of Corporate Secrets
- Credentials for company email accounts such as
info@...,sales@..., etc. - Access credentials for managing all services and social profiles, e.g.:
- Facebook account administrator
- Access to the company Google account
- Management of an external email server
- Access to the corporate CMS for web management, LMS with internal courses, etc.
- Dedicated system administrator accounts for SharePoint, AyMINE, etc.
- Corporate server access credentials and certificates
The Necessity of End-to-End Encryption
All sensitive information within a company should be protected by end-to-end encryption. Sensitive information must never be placed on network drives or local employee drives without additional protection.
Cloud or internal services that lack built-in end-to-end encryption are also not secure storage options. These include SharePoint, Teams, and all DMS systems. (Services often offer an additional encryption option for a separate fee, but it is not a standard feature.)
What is End-to-End Encryption
End-to-End Encryption
End-to-end encryption encrypts data on your device, and it remains encrypted until it reaches another end-to-end encrypted destination capable of decrypting it. At no point between the endpoints can the data be accessed.
Fake End-to-End Encryption
Many services promise end-to-end encryption, but the mechanism does not actually protect the data at all times.
Examples of fake encryption:
- There is a "backdoor" in the encryption mechanism, allowing the operator to decrypt it. Suspicions that Meta exploits this are repeatedly discussed.
- A service claims end-to-end encryption, but means that transmission between your device and the server is encrypted, and then the data is encrypted on the server. This is how protection is provided by most cloud storage providers.
Risks Without End-to-End Encryption
Risks on Network Drives or DMS Without Encryption
If data is protected only by credentials, you have no control over who actually has access to it. Access rights can be changed temporarily to gain access to the data and then restored to their original state. Even if the change is logged, no one will ever notice without additional review. Access right changes occur regularly, making it easy for an extra change to get lost among them. And even if someone notices, it is easy to claim it was a mistake. How can that be disproved?
Network and server administrators have broad permissions in companies, but that certainly does not mean they should have access to all services. Furthermore, their accounts are the primary targets of external attacks. Therefore, a system administrator account should never have access to secrets unless strictly necessary.
Network drives can be compromised by a hacker. If credentials to other systems are stored on them, they can easily be exploited. You might not even know that the data has already been compromised.
Network drives are backed up and archived. Archives pose another risk because they are moved under the management of other administrators and can be attacked independently of the backed-up storage. Thus, each backup increases data risks.
Risks of Storing Secrets on Local Drives
Local hard drives on computers are even riskier than network drives. Network administrators (via remote management) and service technicians can gain access to these drives. Most computers end up in the hands of administrators—both internal and external—at least occasionally.
Deleting data when decommissioning a computer is not completely safe either. Although procedures and tools exist, control over how thoroughly the deletion was performed is usually minimal.
The security of local drives is generally even lower than that of network drives, partly because OS systems like Windows lack built-in isolation to prevent programs from accessing data outside their own directories.
Access Control to Secrets
A secret management tool ensures both the security of secrets and the control of access to them.
Basic Rules of Protection
- Security is fully in the hands of the person responsible for the data. It must not depend on anyone else, such as an administrator or service provider.
- You always have a full overview of who has access to the data. Ideally, you also have a complete history of who had access and when.
- You can revoke access at any time.
Protection of Secrets in AyMINE and AySafe
For protecting secrets, AyMINE uses data vaults, which handle both encryption and access management. Access to a secret must be explicitly granted by its administrator. Furthermore, the administrator can only grant access to someone who has global permission enabled. Thus, an administrator cannot grant access to just anyone.
An administrator cannot do this by mistake. Unlocking a vault requires personal interaction, so the risk of error is minimal. (For details, see the description of data vaults.) Special vaults are used for storing secrets and are not used for anything else. Therefore, no one can accidentally gain access to credentials while being granted access to other classified or sensitive data.
Availability of Credentials
Interlinking with Records
AyMINE allows credentials to be linked to a variety of other records, such as:
- Work procedures and business continuity plans
- Orders and clients
- Assets, e.g., information about servers and external services.
Credentials are thus very easy to find—they are attached to the records to which they pertain. However, this link does not reduce their protection in any way. An employee who has access to the main record does not automatically gain access to the credentials or other sensitive information. If they do not have access, they cannot even discover that credentials are attached.
Accessing Data
You can access secrets either directly from the main workspace (via the Secrets menu item) or from the detail view of the record to which the secret is attached. To gain access, you must always unlock your access wallet beforehand; otherwise, access cannot be granted.
Secrets can only be worked with on trusted devices. Without confirmation that the device is available and verified, secrets are never accessible.