EcoIQ
EcoIQ Platform Module

EcoIQ Security, Privacy & Compliance Centre

Protect industrial evidence, personal data, approvals and AI workflows.

EcoIQ Security, Privacy & Compliance Centre provides the governance layer for role-based access, data protection, consent, audit logs, evidence permissions, supplier/funder access, data retention, public reporting controls and AI agent safety. It helps EcoIQ become enterprise-ready for governments, investors, industrial companies, suppliers, Microsoft ecosystem partners and development institutions.

Core purpose: Make EcoIQ secure, permissioned, auditable and compliant-by-design.

Connected EcoIQ Modules

Data Room & Evidence Vault

Enforces the permission levels documented in Data Room Permissions.

API & Integration Layer

Enforces the API keys, scopes and rate limits documented in API Security.

AI Agent Operations Console

Supplies the agent outputs governed by AI Agent Safety & Governance.

Governance & Expert Review Board

Approves the human review decisions this centre tracks.

Public Trust & Impact Portal

Enforces the Public Reporting Controls before publication.

Command Centre

Surfaces security and compliance alerts across the project pipeline.

Mobile / iPad Inspection Mode

Captures the photos and personal data governed by Privacy / PII Protection.

Supplier & Funding Marketplace

Operates within the supplier and funder access scopes defined here.

Institutional Finance Engine

Its financial models are protected under Data Room Permissions.

Sales CRM & Partner Pipeline

Its contact and outreach data falls under Privacy / PII Protection.

Customer Success & Renewal Engine

Its account data is governed by Role-Based Access Control.

Product Analytics & KPI Engine

Its usage data is subject to the same privacy and retention rules.

Microsoft Ecosystem Core Stack

Provides the identity, governance and monitoring building blocks this centre documents.

SharePoint

Enforces evidence pack permissions.

Teams

Delivers access review and approval notifications.

Microsoft Fabric

Stores governed metadata and audit telemetry.

Power BI

Renders security and compliance dashboards.

Dynamics 365

Applies access scopes to customer and partner records.

Presidio-style privacy tooling

Detects PII across documents, images and notes.

Responsible AI tools

Support explainability and governance of AI agent outputs.

Security Domains

Domain 1

Role-Based Access Control

Roles

AdminProject ownerInspectorEngineerFinancial reviewerEnvironmental reviewerSafety reviewerMaqasid/Mizan reviewerIslamic finance reviewerSupplierFunderInvestorGovernment reviewerCommunity viewerAuditorAPI integration user

Permissions should control

View projectUpload evidenceEdit Asset PassportRun AI diagnosisView financial modelView supplier quotesView MRV evidenceApprove public summaryExport reportShare Data Room packAccess APIView audit logs
Domain 2

Data Room Permissions

Permission levels

Private internalExpert review onlyInvestor due diligenceSupplier RFQ packGovernment / akimat reviewSponsor / CSR packPublic summary only

Rules

Suppliers should not see investor-only documentsInvestors should not see private personal data unless approvedPublic viewers should only see approved summariesCommunity data must be anonymised where neededSensitive industrial data must stay restricted
Domain 3

Privacy / PII Protection

Protect

Personal namesPhone numbersEmailsAddressesExact household locationsFaces in photosVoice notesSignaturesPersonal documentsSensitive community data

Capabilities

Detect PII in documentsFlag faces or personal details in imagesRedact sensitive fieldsRequire consent before publicationMark public-safe summariesTrack privacy risk
Domain 4

Consent Management

Track consent for

Household photosCommunity storiesSponsor visibilityPublic impact storiesBefore/after imagesLocation sharingData sharing with suppliersData sharing with investorsPublic reporting

Consent statuses

Consent requiredConsent requestedConsent grantedConsent deniedConsent expiredPublic sharing approvedInternal only
Domain 5

Audit Logs

Track

File uploadedFile viewedFile downloadedEvidence sharedData Room pack createdData Room pack sharedPublic summary approvedSupplier invitedFunder invitedAI task startedAI output generatedExpert review approvedMRV claim verifiedPermission changedAPI key createdAPI access used

Every audit record should include

UserRoleTimestampActionProjectAssetDocument/evidencePrevious valueNew valueIP/session conceptReason or note where relevant
Domain 6

Data Retention & Deletion

Track

Document ageRetention periodExpiry dateDeletion requestArchive statusLegal holdConsent expiryPublic summary review date

Rules

Expired consent should block public displayOutdated evidence should be flaggedDeletion requests should be trackedAudit logs should preserve compliance history where legally appropriateSensitive documents should have retention policies
Domain 7

API Security

Controls

API keysOAuth conceptScoped tokensRate limitingWebhook signingIntegration logsSupplier/funder access scopesRead-only vs write accessRevoked tokensSuspicious activity alerts
Domain 8

AI Agent Safety & Governance

Track

Model usedData sensitivity levelEvidence usedPrompt/instruction summaryOutput statusHallucination riskUnsupported claim flagHuman approval requiredPII detectedNo Harm Gate statusPublic reporting block

Rules

High-impact decisions require human approvalVisual findings are hypotheses until verifiedPublic summaries require approvalIslamic finance/Maqasid wording requires review where relevantSensitive data should use approved enterprise routing
Domain 9

Public Reporting Controls

Before publishing, check

Public summary approvedMRV evidence availableConsent recordedSensitive data redactedSponsor name approvedExact location safe to showMaqasid/Mizan wording reviewedClaims labelled estimated vs verifiedHuman approval recorded
Domain 10

Compliance Readiness

Show readiness for

Enterprise procurementInvestor due diligenceGovernment reviewSupplier access governancePrivacy reviewAudit reviewResponsible AI reviewData room due diligenceMicrosoft ecosystem governance concepts

Do not claim formal certification unless actually obtained. Phrase as "compliance-ready controls" or "designed to support".

Dashboard Cards

Active usersRoles configuredRestricted documentsPublic-safe documentsConsent recordsExpired consentsPII alertsOpen privacy risksAudit log eventsData Room packs sharedAPI keys activeRevoked access tokensPublic summaries awaiting approvalNo Harm Gate security alertsAI outputs needing reviewSuspicious access alerts

Security Table Fields

ItemProjectAssetData typeSensitivity levelPermission levelOwnerAccess statusConsent statusPII riskRetention statusLast accessedLast reviewedNext action

Sensitivity Levels

PublicInternalConfidentialRestrictedHighly sensitive

Data Types

Asset evidencePersonal dataFinancial modelSupplier quoteInvestor memoMRV proofExpert reviewLegal/compliance documentAI agent logPublic summaryAPI record

Example Scenarios

Project

Village Clean Heating Pilot

Risk: Household photos and location data may contain personal information.

Controls

  • Consent required
  • Exact address hidden
  • Public summary only
  • Before/after photos approved before publication
  • Sponsor name shown only if approved

Status: Public reporting blocked until consent is recorded.

Project

Factory Energy Efficiency Memo

Risk: Financial model and production data are commercially sensitive.

Controls

  • Investor due diligence permission only
  • Supplier cannot view financial model
  • Public portal shows only aggregated impact
  • Audit log tracks access

Status: Restricted.

Project

Supplier RFQ Pack

Risk: Supplier needs technical specs but should not see investor documents.

Controls

  • Supplier pack permission level
  • Quote upload only
  • No access to finance memo
  • No public sharing

Status: Ready for approved supplier outreach.

Project

AI Agent Photo Diagnosis

Risk: AI visual finding may be interpreted as confirmed engineering fact.

Controls

  • Label as AI hypothesis
  • Requires engineer verification
  • Cannot be used in public report until reviewed

Status: Needs verification.

Microsoft Security Integration

  • Microsoft Entra ID concept for identity and access
  • Microsoft Purview-style data governance concept
  • SharePoint permissions for evidence packs
  • Teams approvals for human review
  • Microsoft Fabric for governed metadata
  • Power BI for security dashboards
  • Power Automate for access review workflows
  • Presidio-style PII detection
  • Responsible AI Toolbox for explainability and governance
  • Azure Monitor / Application Insights concept for logs
  • Key Vault concept for secrets and API keys

Use careful wording: "designed to integrate with" or "can use", not "certified by Microsoft".

Amanah Autopilot for Compliance

Amanah Autopilot can run overnight and:

  • Detect expired consents
  • Flag PII in new documents
  • Identify public summaries missing approval
  • Detect Data Room packs shared too widely
  • Find AI outputs needing human review
  • Flag stale evidence
  • Prepare access review list
  • Generate compliance morning briefing

Morning briefing example: "Overnight, EcoIQ found 3 documents with possible PII, 2 public summaries missing consent, 1 supplier pack shared too broadly and 4 AI outputs requiring human review."

No Harm Gate for Security & Privacy

Before data is shared, published or used externally, check:

  • Is the user authorised?
  • Is the document permissioned correctly?
  • Does the file contain personal data?
  • Is consent recorded?
  • Is the evidence public-safe?
  • Are exact locations safe to show?
  • Is supplier/funder access limited?
  • Is the AI output approved?
  • Is the impact claim MRV-backed?
  • Is the audit trail complete?

Safety and Governance

  • EcoIQ security controls are platform governance features and do not replace formal legal, compliance, cybersecurity or data protection review.
  • Do not claim certification unless obtained.
  • Sensitive data must be permissioned, audited and protected.
  • Public reporting requires consent, MRV evidence and human approval.
  • AI outputs require review before high-impact use.
  • Maqasid/Mizan is ethical decision-support, not a fatwa.