Role-based accessNine roles as a least-privilege matrix — owner, admin, reception, coordinator, support coordinator, team leader, worker, finance, and family or nominee — each mirrored in the security rules.
Accounts come from the serverInvites are consumed server-side in one transaction. No client can create its own profile, assign its own role, or join an organisation it wasn't invited to.
Organisation isolationEvery record carries an organisation identifier and every rule checks it. Rules are deployed from a version-controlled repository, not pasted into a console.
Two-step sign-inTOTP, enforceable across every office role. Where it is required and not yet set up, nothing renders until it is.
Australian hostingSydney region, chosen at creation and unchangeable afterwards, with point-in-time recovery and scheduled exports in the same region.
Files, not linksPlans, documents, compliance checks and photos are fetched through the signed-in session and checked every time. There are no shareable download links.
Your own administratorYou own your workspace. Roles, rates, branding, security settings, forms and who sees what are yours to change, without asking anyone.
Take your data with youOne button downloads every record you hold, as it is stored. No support request, no notice period, and no need to be leaving to use it.