Access is decided once, and recorded

Workdome holds the three kinds of data a company most needs to control — its pipeline, its people and its books. The access model is the same for all three.

Separation

Tenant isolation

Every tenant's data is isolated at the database level rather than by a filter the application is trusted to apply.

Default deny

A role sees what it has been granted and nothing else. New pages are not visible until somebody decides they should be.

Roles and permissions

Built-in roles to start from, custom roles when those do not fit, and a settings page showing exactly who can open what.

Per-record access

Scoped by record as well as by page, so a manager sees their own team rather than the organisation.

Personal data

HR is where the most sensitive records live, so it carries controls the rest of the system does not need.

PII access log

Who opened which personal record, and when — available to review rather than merely retained.

Export is its own permission

Reading a record and exporting rows of personal data are different decisions, so they are different permissions.

Disciplinary records

Held with restricted access rather than in a shared drive.

Audited changes

Changes to records are audited, so a disputed value has a history.

How people and systems get in

SSO

Configure single sign-on so joining and leaving are handled by your identity provider.

Personal access tokens

Scoped tokens for integrations, issued and revoked per user rather than shared.

Microsoft Teams

A connected Teams app, so day-to-day approvals happen where people already are.

Operated by Daiviksoft

Workdome is built and run by Daiviksoft Technologies.

See it on your own data

A demo runs on a tenant of your own, not a shared sandbox, so you can import a sample of your records and see how they behave before deciding anything.