Server-authoritative permissions
The interface can hide unavailable actions for clarity, but only the API decides whether an action is allowed.
Security
ShiftChef is designed around minimum-necessary access, explicit invitations, controlled sessions, and an accountable record of important operational decisions.
Verified product principles
ShiftChef does not treat a hidden button as security. The product’s permission model stays authoritative at the server, with the mobile experience reflecting only the actions a person should use.
The interface can hide unavailable actions for clarity, but only the API decides whether an action is allowed.
Six access levels combine with all-locations or selected-location access so people see the part of the operation they need.
Invitation flows connect accounts, workspace membership, and staff records without asking people to pass around internal identifiers.
Email verification, password reset, and invitation acceptance use separate six-digit code flows inside the mobile product.
Secure token rotation and device-session controls help people understand and manage where they are signed in.
Important workspace changes, roster revisions, and cancellations keep reasons and history where the product supports them.
Designed for accountable operations
Important changes are easier to review when the actor, action, target, time, reason, and request reference stay together. This fictional card shows the shape of that record.
Change history
Fictional example for illustration only.
Privacy starts with the right scope
An account identifies the person signing in. Workspace membership defines access. A staff profile holds employment context inside that workspace. Keeping those ideas separate supports clearer decisions.
Personal sign-in, verification, password recovery, and device sessions.
Access role plus all-locations or selected-location scope inside one workspace.
Workplace-specific job details, scheduling context, and permitted operational records.
Private data should stay out of public screenshots and casual exports. Share CSV files only through approved channels, and configure native push delivery only with valid deployment credentials.
NEXT SERVICE
We’ll use your roles and workplace structure to make the security conversation concrete.