Skip to content
Access and permissions

A supervisor can run the app
and see nothing in the office.

Web access and app access are set separately, as explicit lists of what a person can reach rather than a role template they inherit. On top sit specific controls on the sensitive things: hourly rates, other people's timesheets, and whether a site role sees prices at all.

web and app set separately granted per person rates hidden by flag site quotes priceless copy
How it is built

Separate surfaces first,
then permissions inside them.

The first control is not a permission at all. Staff, clients and subcontractors are served entirely different surfaces, and the access layer returns anyone to their own if they reach for a page that is not theirs.

Surface separation
Staff use the web portal and the field app. Clients use the client portal. Subcontractors use the subcontractor portal, served by their own controllers with their own template. A URL from one surface, sent or guessed, returns the user to their own dashboard.
Web page permissions
An explicit tree of the menus and sections a person can open, ticked per person. This is more precise than a role template and it is how the construction deployment is run.
App permissions
A separate list, set independently of web access. A supervisor can have the full field app and almost no back office at all.
Sensitive flags
Specific switches on the things that cause trouble: whether a person can see hourly rates, whether they can see other people's timesheets, and whether they can manage anyone else's access.
Priceless documents
On onsite quotes, site-level roles are served a document with no prices on it at all, so a supervisor can raise and progress a quote without ever seeing what it costs you or what you make on it.
Record-level scoping
Clients see their own projects. Subcontractors see their own orders and invoices, constrained by the identifier held against their login, which cannot be changed from the browser.
Leavers
Deactivation is immediate and blocks login, with the reason written to the login log. Every login, failed login and blocked attempt is recorded with the IP address.
What we are not claiming

The limits, stated
before you ask.

This page describes how access is configured. It is not a statement of security posture, and we are not going to publish one that reads better than it is.

No multi-factor
authentication

Not yet

Mobile login requires a PIN as well as a password, which is a second factor of a kind. It is not an authenticator app or an SMS code, and we will not call it MFA.

Stated plainlyGap

No self-service
password reset

Not yet

Passwords are set and changed by an administrator on the user record. There is no reset flow in the web login today.

Stated plainlyGap

Roles are labels,
not bundles

By design

Permissions are granted per person, using the role as a starting point. If you expect to edit one role and change every site manager at once, that is a configuration item to raise at implementation.

Stated plainlyDesign

No per-folder
document rights

Not live

Project document visibility is controlled at page level, and at project level for clients. Folder-level permissioning is not a live feature and we will not describe it as one.

Stated plainlyGap
On certifications

We are not claiming ISO 27001, Cyber Essentials or any other certification on this website, because the company does not hold them. If a certification is a procurement requirement for you, raise it early and we will tell you where we actually are. A supplier who lists standards they have not been audited against is telling you something about how they will answer harder questions later.