Role-based access control
Securing sensitive estate data requires strict governance. ECO operates as a role-based access control healthcare software solution, enforcing defined user permissions natively across the platform.
The right people see the right data. Nobody else.
Developed for the NHS by the NHS
Securing sensitive estate data requires strict governance. ECO operates as a role-based access control healthcare software solution, enforcing defined user permissions natively across the platform.
Each client organisation's data is isolated at the data layer. ECO scopes every record to its tenant, so users only ever see the data belonging to the organisations they're authorised for.
Passwords alone are insufficient for protecting critical infrastructure records. ECO enforces multi-factor authentication across the entire user base to mitigate credential-based security risks.
All users must authenticate via Time-Based One-Time Passwords (TOTP) during the login process.
Managing workforce turnover and contractor offboarding requires immediate administrative control. In compliance with NHS Vendor Security Point 5.4 user deactivation standards, ECO provides a definitive mechanism to terminate user access instantly.
System administrators can revoke access in a single action, preventing orphaned accounts from remaining active post-contract.
Deactivating a profile revokes access immediately- the user is locked out on their next request and can no longer read, modify, or export any estate data.
Structured HSG264/HSG227 assessments with tracked follow-up actions.
Learn moreModel and manage complex multi-site estates, mapped to every assessment.
Learn moreTamper-evident activity logs, ready to survive a DTAC review.
Learn moreProfessional PDF reports generated from live data — no manual assembly.
Learn moreSecure, encrypted storage linked to the estate and audit-logged.
Learn moreBook a short platform walkthrough and we'll show you how ECO keeps your asbestos register live, auditable, and inspection-ready.