
How access stays shut.
Rules, not settings.
Require TOTP; until a Member enrols, no session opens.
Deactivating a Member ends their sessions at once.
Custody and activity are read-only in every role, the owner included.
Views and reports download. No one file carries the whole organization.
A Request Link opens nothing else.
Its own cookie and sign-in scope. Every failure looks the same.
Member sign-in
Request link
Two deliberate exceptions.
Neither edits history; everything else only appends.
- Undo an untouched import
- Erase an organization on request
What the product never does.
No writable assignee
Only recorded actions move custody.
Private storage, signed links
Request files open through signed links.
Read-only for everyone
No role changes or removes a recorded event.
Deactivation ends sessions
Access ends at once; the name stays.
Audit pack
- Register as of generation
- Custody events
- Activity