Workspace isolation
Every workspace is a separate operating context. Queries, records, permissions and audit logs never cross workspace boundaries.
- Scope enforced end-to-end, not only in the UI
- Switching workspaces re-scopes every query
- No cross-workspace exposure by design
Role safety
Roles are configured per workspace. Least-privilege defaults keep sensitive modules and actions reachable only by the roles that need them.
- Admin, editor, viewer defaults
- Custom roles scoped to modules or actions
- Membership managed per workspace
Auditability
State changes write to an append-only log. Every entry carries actor, action and timestamp — no silent edits, no rewritten history.
- Append-only per workspace
- Actor and timestamp on every change
- Retained for operational review
Data ownership
The data you enter belongs to your organization. You can export it, and closing an account removes it on the schedule described in our policies.
- Export from every module
- Deletion honored on request
- No re-sale, no ad targeting