Best Practice | Global API Application Security Validation
  • 30 Sep 2025
  • 1 Minute to read
  • Dark
    Light

Best Practice | Global API Application Security Validation

  • Dark
    Light

Article summary

Introduction:

To ensure the highest level of data compliance, CMiC has implemented application-level security across all endpoints, effective Patch 22. This ensures that API responses respect company, job, project, payroll, and employee relevant security rules, protecting sensitive information from unauthorized access.

Recommendations:

  • Verify that your API calls are aligned with your assigned permissions by checking the application security setup for the API service account under CMiC System User Maintenance.

  • Report any unexpected access errors to your Account Manager or CMiC Support.