Skip to main content

Authentication

  • Sign-in uses current security standards, with sessions established securely and validation applied on both the client and the server
  • Available sign-in methods are configured per deployment
  • Protected pages redirect you to sign in rather than exposing anything to an unauthenticated visitor

Role-based access

Teams and organisations both use roles, so people only get the access their position requires. An organisation owner and a team reserve do not see or control the same things, and permissions covering money are separated from permissions covering rosters. See Team Structure & Roles and Organisation Roles & Permissions.

Audit logs

Sensitive actions are recorded — roster and ownership changes, permission changes, and movements of money. Organisation and team leadership can review this history, which means a disputed change can be traced rather than argued about.

Protecting your own account

  • Use a strong, unique password
  • Complete any verification a deployment requires before withdrawing funds
  • Review your organisation’s activity log if a change appears that you did not expect