Trust Center/Security policy
Identity and Access Management
Centralized accounts, roles, password rules, and how access is granted and revoked.
- Effective
- August 27, 2026
- Operator
- JRJ Group Holdings LLC D/B/A UNIFY
- Application
- GroFi · 40 Wall Street, 21FL, New York, NY 10005
1. Purpose
JRJ Group Holdings LLC D/B/A UNIFY uses a centralized identity and access management (IAM) system for GroFi. Staff, editors, and brokers authenticate against one user directory. Roles and approvals are stored on that record and enforced on the server.
2. System of record
GroFi’s users collection is the system of record for identity. It issues credentials, session cookies, password-reset tokens, and role flags (`admin`, `editor`, `broker`). There is no separate shadow directory for production application access.
3. Provisioning
- Staff (admin/editor) accounts are created by an existing admin.
- Brokers self-register. The handler sets role and pending approval server-side. Brokers remain unable to submit deals until an admin approves them and onboarding is complete.
- Role changes after create are admin-only fields.
4. Authentication
- Email and password, minimum eight characters
- Password-reset messages are built from the configured site origin, not the request Host header
- Reset links expire in one hour
- Sessions use first-party HTTP-only cookies with CSRF origin checks
- MFA is required as described in the Multi-Factor Authentication Policy
5. Deprovisioning
When a staff member leaves or a broker relationship ends, an admin disables or deletes the account in the same directory. Access reviews confirm that leftover accounts are removed. See Access Reviews and Audits.
6. Hosted consoles
Cloud consoles for hosting, database, email, and object storage are separate from GroFi login. Those consoles are still in scope for this IAM policy: they must use named accounts, MFA, and removal on termination.