Identity and session security
Short-lived access, rotating refresh sessions, reuse detection, revocation, password-reset controls, rate limiting, secure cookies, and privileged step-up checks protect staff access.
FieldCRM
Staff login
Control environment
This catalogue describes how FieldCRM protects staff access, organisation boundaries, evidence, decisions, configuration, and external integrations.
Short-lived access, rotating refresh sessions, reuse detection, revocation, password-reset controls, rate limiting, secure cookies, and privileged step-up checks protect staff access.
Tenant, branch, assignment, role, permission, and object-level authorisation limit each request to the records and actions the authenticated staff member may use.
Context-bound uploads, file size and content validation, protected previews, private storage, and audit metadata preserve application evidence and restrict disclosure.
Authority limits, maker-checker separation, immutable workflow events, append-only audit history, recorded reasons, and fixed application snapshots prevent silent decision changes.
Separate administration, encrypted TOTP, short-lived step-up sessions, versioned drafts, different-person approval, immutable publication, and configuration diffs protect policy changes.
Signed and replay-limited webhooks, idempotent events, scoped synchronisation, validated provider data, secret-gated jobs, and read-only imported financial records constrain third-party boundaries.
Shared responsibility
Authorised users must still protect credentials, verify evidence, follow policy, report suspected compromise, and use customer information only for assigned duties.