DocsSettings & Security

Workspace Configuration, Roles & Security Controls

Configure multi-tier permissions, company VAT registration, data encryption, and audit security.

6 min readUpdated 2026-09-25

1. Company Profile & Tax Configuration

Workspace administrators can customize their business identity from Settings → Company Details. Here you can configure your trading name, company registration number, registered VAT/sales tax rate, and official logo.

All outgoing client communications — including automated PDF invoices, dispatch confirmation emails, and customer SMS alerts — will adopt your branded theme and tax credentials.

If your company operates across multiple tax jurisdictions, you can set override tax codes under Settings → Invoicing.

2. Role-Based Access Control (RBAC)

Pro TeamX enforces strict role-based authorization to protect sensitive business and payroll information. There are four primary permission tiers: Admin, Manager, Dispatcher, and Field Worker.

Field workers are restricted to their own assigned shifts, client geofence locations, and digital checklists, with no access to company financial records or payroll rates.

Action Steps:

  1. Go to Settings → Roles & Permissions
  2. Select the role tier to inspect permissions or create a custom role preset
  3. Toggle sensitive permissions such as "Export Client Data" or "Override GPS Clock" and click Save Changes

3. Two-Factor Authentication & Session Security

To safeguard dispatcher and administrator accounts, Pro TeamX supports mandatory Two-Factor Authentication (2FA) via authenticator apps (TOTP) such as Google Authenticator or 1Password.

Administrators can enforce session duration limits, automatic logouts on inactive browser tabs, and inspect active mobile device sessions under Settings → Security.

We recommend enforcing 2FA across all users with Dispatcher and Admin privileges to comply with data privacy standards.

4. Audit Trails & Compliance Exports

Every operational event — from shift cancellations to bank detail modifications and client deletions — is recorded in an immutable audit ledger.

Security officers and account owners can filter audit events by timestamp, actor, IP address, or affected entity, and export compliance reports in CSV or JSON format.