No multi-factor
authentication
Not yetMobile login requires a PIN as well as a password, which is a second factor of a kind. It is not an authenticator app or an SMS code, and we will not call it MFA.
Web access and app access are set separately, as explicit lists of what a person can reach rather than a role template they inherit. On top sit specific controls on the sensitive things: hourly rates, other people's timesheets, and whether a site role sees prices at all.
The first control is not a permission at all. Staff, clients and subcontractors are served entirely different surfaces, and the access layer returns anyone to their own if they reach for a page that is not theirs.
This page describes how access is configured. It is not a statement of security posture, and we are not going to publish one that reads better than it is.
Mobile login requires a PIN as well as a password, which is a second factor of a kind. It is not an authenticator app or an SMS code, and we will not call it MFA.
Passwords are set and changed by an administrator on the user record. There is no reset flow in the web login today.
Permissions are granted per person, using the role as a starting point. If you expect to edit one role and change every site manager at once, that is a configuration item to raise at implementation.
Project document visibility is controlled at page level, and at project level for clients. Folder-level permissioning is not a live feature and we will not describe it as one.
We are not claiming ISO 27001, Cyber Essentials or any other certification on this website, because the company does not hold them. If a certification is a procurement requirement for you, raise it early and we will tell you where we actually are. A supplier who lists standards they have not been audited against is telling you something about how they will answer harder questions later.