Hi @EdwardDe2 I pass the sessionID and the customer ID in the URL, then do a lookup in Workfront to validate the session, get its user, and validate the user is part of the customer record (and often, that they are a sysadmin) . Or pass the userID and sessionID and validate the userID belongs to the...