Separate company data
Jobs, employees, hours, schedules, materials, documents, events, and billing records carry a company boundary. Database row rules restrict access to authorized company members.
Security
CMD Ops checks the signed-in user, company membership, role, work view, feature access, and requested record before returning company data.
Jobs, employees, hours, schedules, materials, documents, events, and billing records carry a company boundary. Database row rules restrict access to authorized company members.
Owners, administrators, managers, field leads, employees, and viewers have different permissions. Office and field screens are checked separately from paid-feature access.
Registration, sign-in, recovery, and persistent sessions use managed authentication. App routes require a valid signed-in session before company data loads.
File paths include the company boundary. A signed-in user must be allowed to see the linked company or job record before opening a protected file.
Live employee location requires the paid capability and employee consent. The client is designed to collect only during an open shift, pause during lunch, and stop after clock-out. Paid activation waits for the matching server-side boundary and retention deletion to pass acceptance.
The browser does not decide who owns a record. Database functions and row policies re-check company membership, role, and feature access.
Platform administration is limited to approved administrators. Company-status and paid-feature changes create audit records.
No online system can promise zero risk. CMD Ops uses layered access controls, keeps the application private from search indexing, and reviews security findings as the product changes.
Report a concern
Report a suspected security problem to hello@retehost.com. Include the affected screen, approximate time, and what you observed. Do not send passwords, recovery codes, API keys, or unnecessary customer information.