Standardise how every business unit specifies work
The problem at scale is not writing one specification. It is that forty of them are written forty different ways, and procurement has to price all of them.
Forty specifications, forty formats
The problem at scale is not writing one specification. It is that every business unit writes its own, in its own shape, and procurement has to price forty documents that cannot be compared with each other.
One structure across all of them makes a call-off comparable, an estimate checkable, and a rejected proposal explainable.
- SAML SSO and SCIM, so access follows joiner-mover-leaver.
- An audit log of every privileged action.
- A signed DPA and terms your legal team can redline.
What enterprise adds
The parts your security and procurement teams ask about first.
SSO and SCIM
SAML single sign-on and directory provisioning, so access follows the joiner-mover-leaver process you already run.
Role-based access
Per-project permissions with an audit log of every privileged action.
DPA and custom MSA
A signed Data Processing Agreement, and terms your legal team can redline.
Invoicing and PO
Purchase orders and invoicing, rather than a card on file.
Data residency
UK and EEA region pinning across the services that support it.
Private reviewer pool
Named reviewers under NDA, if your work cannot go to the open marketplace.
What your security questionnaire will ask, and where the answer is
All of it is written down before you ask.
- Data Processing Agreement — published, and signed on request.
- Sub-processor list, with locations and the notice period for changes.
- Encryption in transit and at rest, and who inside Moksy can reach what.
- Breach notification timeline, and the incident process behind it.
- Retention and deletion, including what survives an account closure and why.