Security
Every read and write is checked on the server against the company, the role, the record's access list and the field. Nothing is enforced only in the browser.
Each company is its own tenant. Row-level policies in the database scope every query; the app cannot ask for another company's rows.
Workspace admins, members, external members. Groups for teams and departments. Substitutes inherit a colleague's rights for a period.
A named access list per record decides who can read, edit, delete or share it. Field-level security hides or locks individual fields by role.
Every edit makes a version. Check-out gives one person the pen. The event log records who did what, exportable as CSV.
Rules per class archive or delete records after a period, with a bin and a restore. Archived records stay available to admins.
API keys act with the rights of the member who created them. Shared forms, pages and QR actions act as their creator, never more. Links can expire, be limited to named people, or be turned off at once.
Create a company and look around Settings › Permissions — everything above is configured there.