Security and Data Protection
Understand tenant separation, permissions, API controls and practical account security in WorkPulse.
Security and Data Protection
WorkPulse combines company separation, user permissions and controlled integration access. Security also depends on how each customer manages accounts, devices and exported data.
Workspace separation
Operational records are stored and queried in the selected tenant context. Always confirm the company shown in the account area before adding people, changing policy or reviewing reports.
Roles and least privilege
Give each user the smallest role that supports their job. Review administrative, wage, capture and subscription permissions when responsibilities change, and remove access promptly when a person leaves.
Account and device safety
- Use a unique password and do not share login credentials.
- Sign out on shared devices and review login activity when something looks unfamiliar.
- Keep desktop and mobile clients updated.
- Treat screenshots, camera images, reports and downloaded files as company data.
API and webhook controls
Customer API access requires an enabled entitlement, authentication and tenant client security. Browser integrations use approved origins; private integrations can use a client key. Webhook secrets must be stored securely and rotated if exposed.
Reporting a concern
If you believe an account, client key or webhook secret has been exposed, stop using the credential and contact support@workpulse.solutions with the company name and a clear description. Do not email passwords or secret keys.
This guide describes controls available in the product. Contractual, regulatory or industry-specific requirements should be reviewed for each customer's use case.
Was this article helpful?