Access and permissions

A supervisor can run the app
and see nothing in the office.

Web access and app access are set separately, as explicit lists of what a person can reach rather than a role template. On top sit controls on rates, timesheets and whether site sees prices.

How it is built

Separate surfaces first,
then permissions inside them.

The first control is not a permission at all. Staff, clients and subcontractors are served entirely different surfaces, and the access layer returns anyone to their own if they reach for a page that is not theirs.

01Signing in
Single sign-on with Microsoft 365 and Google Workspace, with MFA available on top of it. Mobile login additionally takes a PIN as well as the password, which is what lets a shared site tablet be used by several people who each sign as themselves rather than staying logged in as whoever set it up.
02Surface separation
Staff use the web portal and the field app. Clients use the client portal. Subcontractors use the subcontractor portal, served by their own controllers with their own template. A URL from one surface, sent or guessed, returns the user to their own dashboard.
03Web page permissions
An explicit tree of the menus and sections a person can open, ticked per person. This is more precise than a role template and it is how the construction deployment is run.
04App permissions
A separate list, set independently of web access. A supervisor can have the full field app and almost no back office at all.
05Sensitive flags
Specific switches on the things that cause trouble: whether a person can see hourly rates, whether they can see other people's timesheets, and whether they can manage anyone else's access.
06Priceless documents
On onsite quotes, site-level roles are served a document with no prices on it at all, so a supervisor can raise and progress a quote without ever seeing what it costs you or what you make on it.
07Record-level scoping
Clients see their own projects. Subcontractors see their own orders and invoices, constrained by the identifier held against their login, which cannot be changed from the browser.
08Leavers
Deactivation is immediate and blocks login, with the reason written to the login log. Every login, failed login and blocked attempt is recorded with the IP address.
Security posture

Access is granted per person,
page by page.

Single sign-on with Microsoft 365 and Google Workspace, with MFA on top.
Every individual carries an explicit access tree rather than inheriting a role template.

Per person,
not per role

By design

Permissions are granted to the individual, using the role as a starting point. One deployment runs thirteen menu groups across 87 pages, each granted explicitly, which is finer control than most systems in this market allow.

Access controlLive

Single sign-on
and MFA

Standard

Sign in with your Microsoft 365 or Google Workspace account, with multi-factor authentication on top. Mobile login takes a PIN as well, which is what makes a shared site tablet usable by several people who each sign as themselves.

Login securityLive

An audit trail
behind every entry

Standard

Records carry the person, the time, the device and the IP address, appended rather than overwritten, so who did what is answerable months later.

AccountabilityLive
On certifications

Unibuild holds Cyber Essentials Plus and is ICO registered. ISO 27001 certification is in progress. If a certification is a procurement requirement for you, raise it early and we will set out exactly where it stands.