Skip to main content
The ForgeThe Forgeby HustleForge
Reference Material

Security FAQ & Architecture

What security looks like from each seat, where each industry draws its data boundary, how a control matures, how a request flows from browser to record, and the questions we hear most. For the plain-language overview, start at the Security overview.

Security by Role

What Security Looks Like From Your Seat

Owner or Executive

You should retain authority over who accesses the company, what they can approve, and where information can move.

  • Control which users have platform access across all businesses and locations
  • Set approval thresholds for optional spending and sensitive actions
  • Authorize and revoke integration connections
  • View consolidated reporting without giving every user the same visibility
  • Export business records and manage account termination
  • Review administrative activity and security status
Operations Manager

Employees need enough access to complete the work — not unrestricted access to the business.

  • Manage schedules, assignments, and customer information for assigned locations
  • View work history and completion records for direct reports
  • Assign contractors limited access to job-relevant information
  • Escalate issues that go beyond their approval rules
  • Access reporting relevant to operational responsibility
Finance or Payroll

Financial context should be visible only to the people authorized to use it.

  • Access approved hours and wage summaries within authorized businesses
  • View operational cost context for budgeting and reporting
  • Export financial summaries in supported formats
  • Access accounting integration data within configured boundaries
  • Sensitive report access limited by role configuration
Technical Administrator

Every connection, permission, and administrative change should have an owner.

  • Provision and deactivate user accounts
  • Configure role assignments and permission templates
  • Authorize and manage integration connections
  • Review credential expiration and configuration changes
  • Access audit history for administrative actions
  • Manage data export and account configuration
Employee or Contractor

Your account should show the work you need without exposing the rest of the company.

  • Access assigned records, schedules, and required actions
  • View customer information relevant to assigned work
  • Complete job-specific forms and workflows
  • Access through mobile browser with the same session protections
  • Report lost devices or suspicious account activity
  • Account removed promptly when engagement ends
Industry Boundaries

Where The Forge Draws the Line by Industry

Regulated or specialized records are not automatically pulled into The Forge. Each industry has a documented boundary for what stays in a specialized system.

What matters in this industry

  • Customer addresses and site-access information
  • Job photos and inspection records
  • Employee location during work hours
  • Contractor vs. employee access levels
  • Payment information for services
  • Shared devices on job sites
  • Temporary worker access for seasonal staff

How The Forge draws the boundary

  • Field employees see only assigned jobs and required customer information
  • Contractor accounts receive limited access without broad employee or financial visibility
  • Customer addresses are visible for assigned work, not across the full customer database
  • Shared-device access controlled through individual sign-in, not saved sessions
  • Temporary accounts can be created and removed to match employment periods
Security FAQ

Common Security Questions

How a control matures

Every control is one of four states

ScopedConfiguredActiveIndependently checked
Scoped
On the roadmap. Not yet built — no control exists to rely on today.
Configured
Built and available. Your business turns it on and sets the policy.
Active
Built and enabled by default in production today.
Independently checked
Active, then independently re-checked — with a recorded date and method.

The matrix below also uses a fifth status, “Limited Availability,” for controls that are built but whose coverage is still expanding.

How a request flows

From browser to record, every hop has an owner

  1. Authorized User
    Customer
  2. Supported Web Browser
    Customer
  3. Encrypted Web Connection (HTTPS)
    HustleForge
  4. Identity and Session Controls
    HustleForge
  5. Business, Location, and Role Permissions
    HustleForge· Customer-configured
  6. Forge Application and Approved Records
    HustleForge
  7. Workflow, Automation, and Approval Controls
    HustleForge· Human approval points
  8. Authorized Integrations
    Third-party provider· Read or approval-gated write
  9. Activity History, Monitoring, and Recovery
    HustleForge
Customer responsibilityHustleForge responsibilityThird-party provider responsibility
Control Categories

What each category covers

Security controls across the platform are grouped into 15 categories. The full inventory — every control, its status, limitations, and verification date — lives at the control inventory.

6 controls

Secure Web Access

Do we need to install anything?

5 controls

Identity and Sign-In

How do users sign in?

3 controls

Roles and Permissions

Can employees see information outside their role?

4 controls

Business and Location Separation

Can access differ by business or location?

4 controls

Data Protection

How is our data protected?

3 controls

Integration Security

How are integrations secured?

3 controls

Automation and Approval Controls

Can automated actions require approval?

3 controls

Audit History

Is activity recorded?

4 controls

Platform Monitoring

How do you know when something breaks?

4 controls

Availability and Recovery

What happens if something goes down?

4 controls

Secure Development Practices

How is the platform built securely?

2 controls

Secure Platform Updates

How are updates delivered?

2 controls

Incident Response

What happens if there is a security incident?

2 controls

Shared Responsibility

What are we responsible for?

3 controls

Customer Data Rights

Can we export our data?

The Forge is in beta. Controls marked planned are not yet available. Contact contact@hustleforge.tech with questions about security requirements for your business.