WerkZ

Security & control

Easy to use does not mean loose access control.

WerkZ is designed around explicit permissions, tenant boundaries, traceable approvals, revocable integrations and recovery paths appropriate to the actual risk.

Capabilities

Permissions represent concrete actions. “Manager”, “office” or “field worker” are bundles, not hard-coded security models.

Tenant isolation

Customer organisations require server-side data boundaries; hiding UI elements is never sufficient access control.

Audit

Important changes and approvals can record actor, timestamp and context for later review.

Least privilege

Users and integrations should receive only the access required for their agreed task.

Revocable access

OAuth, scoped tokens and renewable credentials are preferred over unnecessary password sharing.

Recovery

Backup, restore, error handling and controlled correction flows are considered according to business impact.

Technical details

Security follows the data and the action.

Offline devices
Only data required for the current work should be available offline. Sessions, device loss, queued uploads and conflict handling need explicit behaviour.
Files & photos
Documents and photos should follow the same organisation and permission boundaries as the job or record they belong to.
Integrations & secrets
Secrets stay out of public client code and normal logs. Expired or revoked provider credentials are part of the failure path.
Messenger approvals
A messenger is never the database. It is a notification/approval channel; the core validates, de-duplicates and audits the actual action.
Simulation
Simulated data remains separate from real operational data, and analytics follows the same tenant and permission scope as daily operations.