Security and trust

Workforce access designed around clear boundaries.

Protect sign-in, decide what every role can do, and keep company and branch context attached to daily operations.

MFA support Permission policies Company and branch scope
WorkforceSuite role permission configuration
Mobile security
WorkforceSuite mobile security and multi-factor authentication screen
Permission-driven Access follows assigned responsibilities
Identity and session protection

Layered controls from sign-in to sensitive action.

The platform combines token validation, protected browser storage, multi-factor challenges, and revocable refresh credentials.

01

Validated sign-in

Signed access tokens are checked for issuer, audience, lifetime, and signing key before protected API access is accepted.

02

Protected browser session

Portal tokens use HTTP-only, SameSite strict cookies and are marked secure in production to reduce exposure to browser scripts and cross-site requests.

03

MFA when it matters

Multi-factor challenges can protect login and support separate verification before sensitive actions. Used challenges are consumed and cannot be replayed.

04

Revocable continuity

Refresh credentials rotate when used and can be revoked for the current session or across the account when access must end.

Access boundaries

Give people the access their work requires—not a generic portal.

Authorization policies connect assigned permissions to protected actions, while company and branch context keep operational records inside the intended scope.

Explore role-aware features
OrganizationCompany context

Business records are queried and operated within the selected company context.

LocationBranch scope

Operators can work across all branches or within assigned branches according to their access.

ResponsibilityRoles and permissions

Menus, dashboards, records, and API actions follow the permissions assigned to each role.

Operational accountability

Preserve context around important administrative changes.

Audit records support selected administrative and recovery workflows with who, where, what changed, outcome, timestamp, IP address, and user-agent context.

Recorded context
Actor
User and account
Scope
Company and branch
Change
Action and entity
Result
Outcome and error context
Source
Time, IP, and user agent
Shared responsibility

Secure configuration is part of a successful rollout.

  • Assign the least access each role needs and review it as responsibilities change.
  • Keep user, branch, device, and employment status records current.
  • Review access, exceptions, and recovery activity as part of regular operations.
Security review

Bring your access and deployment questions to the demo.

We will walk through the implemented controls and confirm the configuration, hosting, data-handling, and rollout requirements that apply to your organization.