Security

Your records, your rules, on the record

Every read and write is checked on the server against the company, the role, the record's access list and the field. Nothing is enforced only in the browser.

Company isolation

Each company is its own tenant. Row-level policies in the database scope every query; the app cannot ask for another company's rows.

Roles and groups

Workspace admins, members, external members. Groups for teams and departments. Substitutes inherit a colleague's rights for a period.

Access lists and fields

A named access list per record decides who can read, edit, delete or share it. Field-level security hides or locks individual fields by role.

Versions and history

Every edit makes a version. Check-out gives one person the pen. The event log records who did what, exportable as CSV.

Retention

Rules per class archive or delete records after a period, with a bin and a restore. Archived records stay available to admins.

Keys and links

API keys act with the rights of the member who created them. Shared forms, pages and QR actions act as their creator, never more. Links can expire, be limited to named people, or be turned off at once.

Questions about your setup?

Create a company and look around Settings › Permissions — everything above is configured there.