Verified invitations
Invite a teammate through a time-limited, one-time flow with masked account information.
Team and Permissions
Invite employees, use fixed roles mapped to permission keys, assign records and tasks, manage member status, and review authorized activity without relying on interface-only checks.
Invite a teammate through a time-limited, one-time flow with masked account information.
Roles map to server-enforced permission keys so access does not depend on a hidden button.
Make lead and task ownership visible in the workflow.
Authorized admins can manage invitations and supported member status changes.
Review protected administrative events and record history according to permission.
Current boundary
Custom roles are Planned. The current product provides one workspace per company; arbitrary workspace structures are not available.
Not today. The MVP uses fixed roles mapped to permission keys; custom roles are Planned.
No. The architecture requires server-side permission checks, with database tenant controls as defense in depth.
The product is designed with company-level tenant isolation, app-layer scoping, and database row-level security. The Security page states verified controls and test status without making a certification claim.
Authorized admins can suspend, reactivate, or remove member access. Removal revokes the affected user’s company sessions.