Security

The office, field, customer, and platform are separate trust zones.

JobCrewHQ treats identity, tenant context, public links, provider credentials, payments, and support access as explicit security boundaries.

Tenant isolation

Organization-scoped access contracts and database row-level security keep tenant data separated.

Identity controls

MFA, enforced enrollment, passwordless customer access, and enterprise SAML SSO support distinct user planes.

Role permissions

Preset and configurable roles gate office, field, financial, administrative, and platform actions.

Signed public links

Purpose-bound, expiring tokens protect quote, tracking, and customer-facing flows.

Provider credentials

Integration credentials stay server-side and encrypted rather than exposed to product pages.

Audit and compliance

Sensitive changes are audited, with retention, export, deletion, webhook, and security-gate evidence.

Security posture

Controls are part of the release gate, not a settings-page promise

Static authorization checks, integration tests, generated RLS policies, audit evidence, and production-readiness checks are maintained alongside product work.

Give every user the right surface—and only the right surface.

Start with the core workflow today, then add operational depth as your crew grows.