Skip to main content
Scooteefield / office

Security

Access follows the tenant, the role, and the workforce scope.

Scootee handles location, expense, attendance, payroll, and employee-request data. The security model is designed to keep those workflows inside the organization boundary and expose only the records a user is authorized to manage.

Organization boundaries

Operational and workforce records carry tenant context, and access rules are designed around the authenticated organization.

Role and workforce scope

Portal authority remains separate from employee job identity and can be limited by organization, branch, department, permission template, and override.

Authenticated clients

Web and native mobile workflows use authenticated sessions and tenant-aware APIs rather than public operational endpoints.

Sensitive records and storage

Location, workforce, request, receipt, and document access require product-specific policies and customer release verification.

Privacy-aware deployment

Location controls begin with a defined work purpose.

Scootee is designed around explicit field work sessions. Each customer remains responsible for employee notice, lawful basis, device policy, retention, geographic requirements, and the configuration used in production.

Review evidence

  • Tenant access and cross-tenant negative tests
  • Portal permissions and branch or department scopes
  • Mobile authentication, release configuration, and device permissions
  • Receipt and private-document storage policies
  • Approval, correction, request, and activity history

Procurement note

Do not infer certifications from architecture.

Ask the Scootee team for the current security documentation, subprocessors, retention behavior, deployment evidence, and any independent attestations that are actually available at the time of purchase.

Request security information