Rota Generator

SECURITY AND PRIVACY

How organisation data is separated

Each organisation is treated as a separate tenant. Organisation-owned records are associated with that organisation and protected by server-side authorisation.

Membership checks

A signed-in user must belong to the active organisation and have the required permission for protected actions.

No cross-organisation browsing

Changing a URL or hidden form value should not grant access to another organisation's records because access is checked on the server.

Need another answer?

Return to the Help Center to search all guides or browse the related articles for this topic.

Back to Help Center