Security

Access that follows responsibility.

ShiftChef is designed around minimum-necessary access, explicit invitations, controlled sessions, and an accountable record of important operational decisions.

Verified product principles

A clear boundary between convenience and control.

ShiftChef does not treat a hidden button as security. The product’s permission model stays authoritative at the server, with the mobile experience reflecting only the actions a person should use.

Server-authoritative permissions

The interface can hide unavailable actions for clarity, but only the API decides whether an action is allowed.

Role and workplace scope

Six access levels combine with all-locations or selected-location access so people see the part of the operation they need.

Explicit invitations

Invitation flows connect accounts, workspace membership, and staff records without asking people to pass around internal identifiers.

Purpose-specific verification

Email verification, password reset, and invitation acceptance use separate six-digit code flows inside the mobile product.

Controlled sessions

Secure token rotation and device-session controls help people understand and manage where they are signed in.

Accountable changes

Important workspace changes, roster revisions, and cancellations keep reasons and history where the product supports them.

Designed for accountable operations

Keep the reason beside the decision.

Important changes are easier to review when the actor, action, target, time, reason, and request reference stay together. This fictional card shows the shape of that record.

  • Revision reasons stay with controlled schedule changes.
  • Cancellation paths ask for an explanation.
  • CSV exports should travel only through approved channels.

Change history

Friday Dinner Service

Recorded
Action
Roster revision shared
Actor
Jordan Lee · Manager
Reason
Terrace section reopened
Request reference
SC-DEMO-1042
Recorded
Friday · 16:20 local time

Fictional example for illustration only.

Privacy starts with the right scope

Three records. One intentional boundary.

An account identifies the person signing in. Workspace membership defines access. A staff profile holds employment context inside that workspace. Keeping those ideas separate supports clearer decisions.

01

Account

Personal sign-in, verification, password recovery, and device sessions.

02

Membership

Access role plus all-locations or selected-location scope inside one workspace.

03

Staff profile

Workplace-specific job details, scheduling context, and permitted operational records.

Operational care still matters.

Private data should stay out of public screenshots and casual exports. Share CSV files only through approved channels, and configure native push delivery only with valid deployment credentials.

NEXT SERVICE

Map access to the way responsibility already works.

We’ll use your roles and workplace structure to make the security conversation concrete.