Access is decided once, and recorded
Workdome holds the three kinds of data a company most needs to control — its pipeline, its people and its books. The access model is the same for all three.
Separation
Tenant isolation
Every tenant's data is isolated at the database level rather than by a filter the application is trusted to apply.
Default deny
A role sees what it has been granted and nothing else. New pages are not visible until somebody decides they should be.
Roles and permissions
Built-in roles to start from, custom roles when those do not fit, and a settings page showing exactly who can open what.
Per-record access
Scoped by record as well as by page, so a manager sees their own team rather than the organisation.
Personal data
HR is where the most sensitive records live, so it carries controls the rest of the system does not need.
PII access log
Who opened which personal record, and when — available to review rather than merely retained.
Export is its own permission
Reading a record and exporting rows of personal data are different decisions, so they are different permissions.
Disciplinary records
Held with restricted access rather than in a shared drive.
Audited changes
Changes to records are audited, so a disputed value has a history.
How people and systems get in
SSO
Configure single sign-on so joining and leaving are handled by your identity provider.
Personal access tokens
Scoped tokens for integrations, issued and revoked per user rather than shared.
Microsoft Teams
A connected Teams app, so day-to-day approvals happen where people already are.
Operated by Daiviksoft
Workdome is built and run by Daiviksoft Technologies.
See it on your own data
A demo runs on a tenant of your own, not a shared sandbox, so you can import a sample of your records and see how they behave before deciding anything.