Permissions
One permission per action
Assigning a ticket, approving hours or exporting the audit log are separate permissions. Roles bundle them; five come ready and you can create your own.
Security
Who can see what, how people sign in, where data is encrypted and how every change is recorded. Written for the security questionnaire you'll have to fill in.
Audit log
Chain verified · 02:00
Access
Access is granted by permission and by territory, so a dispatcher in Tijuana doesn't see Monterrey's tickets unless someone gives them that scope.
Permissions
Assigning a ticket, approving hours or exporting the audit log are separate permissions. Roles bundle them; five come ready and you can create your own.
Territories
A person can read their own records, their territory's or the whole organization's. Territories follow each client's own hierarchy of regions and zones.
Grants
Special access is given to one person, for one permission, with a written reason and an expiry date, so it doesn't quietly become permanent.
Ceiling
An administrator can only give access they have themselves. Access moves sideways or down, never up.
Duties
The person who plans the roster doesn't approve the hours, and the technician who fixed a defect can't sign off the fix.
Clients and vendors
A client sees its sites, tickets and equipment. A contractor sees the tickets assigned to it. Neither sees anyone else's.
Sign-in
Two-factor
Six-digit codes from an authenticator app, with single-use recovery codes. You choose which roles must use it.
Single sign-on
Staff and vendors can sign in through your own provider over SAML 2.0 or OpenID Connect, with its groups mapped to waydot roles.
Sessions
People see where they're signed in and can close any session. Changing a password signs out every other device.
Field app
After five minutes in the background, the app asks for a fingerprint or face. Transfers and expenses ask again every time.
Throttling
Five password attempts per minute, and five wrong codes end a two-factor challenge.
Deactivation
A deactivated account is refused on its next request, on every device, even with a valid token.
Data
Encrypted in transit and at rest, with the most sensitive fields encrypted a second time inside the database.
In transit
Every connection between the console, the field app and the platform.
At rest
Database volumes and file storage. Two-factor secrets, tax IDs, bank accounts and health data are also encrypted field by field.
Files
Photos, receipts and employee documents are served through links that expire, and every link issued is logged.
Logs
Passwords, tokens, national IDs and bank accounts are replaced before anything reaches the audit log.
Location
The GPS trail is recorded on shift only and deleted after the retention period you set. Technicians never see each other's positions.
Privacy law
Data export and erasure requests under Mexico's LFPDPPP, and GDPR or CCPA where they apply. Erasure anonymizes the person and keeps the operational record.
Audit log
Every workflow event, edit, sign-in and sensitive read goes through the same path.
The log entry is saved in the same database transaction as the change itself. One can't exist without the other.
change + log entry: one transaction


Each entry's hash covers its content and the previous entry's hash. Altering, reordering or deleting a row breaks the chain.
hash(n) = f(content(n), hash(n−1))


At 02:00 the whole chain is recalculated and the first row that no longer matches is reported.
nightly verification · 02:00


One year stays searchable in the console; older entries move to compressed archives. The application can't delete log rows.
1 year searchable · 7 years retained


Auditors filter by person, record, event or date. An export is itself logged before the data leaves.
exports are logged too


The log entry is saved in the same database transaction as the change itself. One can't exist without the other.
change + log entry: one transaction


Devices
Integrity
The app checks for root, emulators, tampered builds and mock location. You decide whether a finding warns, limits the session or blocks sign-in.
Evidence
Photos, signatures and receipts are stored encrypted inside the app, out of reach of the phone's gallery and file manager.
Lost phones
An administrator can wipe a lost device. On its next connection the app deletes its data and the session ends.
Commitments
Documents
The contracts and policies procurement usually asks for, published and versioned.
How we handle personal data on your behalf.
The providers that host and deliver the service.
Availability commitments and service credits.
What we collect and why, under Mexican law.
A 30-minute briefing with your dispatch, payroll and asset flows on screen.
Keep exploring
Platform
How each part of the operation works, step by step, and the rules that always apply.
Intelligence
What each model answers, where it appears, and what it will never do on its own.
The visibility gap
What running on WhatsApp and spreadsheets really costs, and what changes with one record.
Changelog
New capabilities and improvements across the console, field app and platform.