Record of staff access grants across Xzopia systems. Maintained for access audit and offboarding. When someone leaves or changes role, work down their row and revoke/adjust each entry.
Granted: 08 June 2026 | Granted by: Simon Killen | Purpose: Engineer — TacticalRMM/ITFlow migration off NinjaOne
Status: Active
| System | URL | Access level | Notes |
|---|---|---|---|
| Wiki.js (KB) | kb.xzopiasecure.com | Read (all pages) | Full read across the KB incl. infrastructure docs |
| TacticalRMM | rmm.xzopiasecure.com | Technician role | View agents + remote access; 2FA enrolled on first login |
| ITFlow (PSA) | psa.xzopiasecure.com | Agent/Technician role | Work tickets, log time, view clients; not Administrator |
| Claude (AI) | claude.ai | Personal Pro account (Xzopia-funded, individual — not Team) | Granted 9 Jul 2026. For MCP connectors + Claude Code. Sign-in stephen@xzopia.com. |
| MCP connectors | mcp.xzopiasecure.com/* + CIPP | All fleet connectors EXCEPT Xero (incl. CIPP + M365 Admin) | Granted 9 Jul 2026. CIPP + M365 Admin (highest-privilege) intentional given seniority/CIPP-SAM involvement; Xero (finance) deliberately excluded. Underlying tool access still governs what he can do (two-layer). Setup: Claude Setup. |
Git repo (xzopia-deploy) |
github.com/Silentrunnerx/xzopia-deploy | Branch + PR only — NOT direct push to main |
Granted 9 Jul 2026. Claude Code on his own machine; feature branch → gh pr create → Simon reviews/merges. Precautionary during onboarding, explicitly revisitable (see CLAUDE.md two-committer model). |
Public resources (no account needed) shared with Stephen:
Offboarding checklist (when applicable):
main)Xzopia Limited (NI620366) | Access register started 08 Jun 2026