Across every block
Who can see what, decided once.
A task, a doc, a table and a channel all answer the same question the same way.
The screen
Teams
The directory, the roles, the reviews.
WorkPlannerAITalkTeamsDocsTablesGoalsSettings
NONorthwind OpsSample workspace
Directory
Roles
Operations
OOnboarding lead
OOperations lead
FFinance
Teams›MembersSearch or jump toMD
Invite people
SOsam@northwindops.exampleAdd an email
LevelEmployeeSend invites
What you get
Everything below ships today.
- The workspace ladderEvery person holds one workspace level: Company Admin, then C-Level, VP, Director, Manager, Team Lead, HR, Employee or Agent. The level decides the settings pages and the people data; it never decides one object at a time.
- Additive grantsA Space, a Folder, a List, a Board or a Doc can be shared directly. A grant adds reach and never takes it away, so sharing a folder does not require handing over the Space around it.
- Member can writeContributing and managing are separate. A member of a Space or a List can create and edit the work in it without being able to rename, move or delete the container.
- Security activity logSign-ins, password changes, sign-out-everywhere and the sessions holding your account, on your own account page. An org-wide audit view sits behind the manager gate.
- Sign-in hardeningBrute force lockout, hashed reset tokens, a password policy, idle session expiry, a real sign-out that invalidates the token, and two step verification at login.
- What we do not claimNo certification, no SSO or directory provisioning, and no choice of storage region. When any of those ship they will be named on the security page with their evidence, and not before.
How a permission is actually decided.
- Start from the person's workspace level
- Add every grant they hold on the object, and on the containers above it
- Take the strongest of those, because a grant only ever adds
- Assigning someone a task grants them the task, so work is never invisible to the person doing it
Questions
Straight answers.
What certifications do you hold?
None. We hold no third party security certification today. When one exists it will be named on the security page with its report, and not before.
Can I require multi factor authentication?
Yes. Two step verification at login is enforced for the workspace, and sign-in hardening (lockout, password policy, idle expiry, real sign-out) is on for every account.
Do you support single sign-on or directory provisioning?
Not yet. There is no identity provider connection and no automatic provisioning, so a person is invited and removed by an admin.
Can I choose where the data is stored?
No. There is one deployment and you do not get to pick its region. Say so in your security review rather than finding out later.