Security FAQ & Architecture
What security looks like from each seat, where each industry draws its data boundary, how a control matures, how a request flows from browser to record, and the questions we hear most. For the plain-language overview, start at the Security overview.
What Security Looks Like From Your Seat
You should retain authority over who accesses the company, what they can approve, and where information can move.
- Control which users have platform access across all businesses and locations
- Set approval thresholds for optional spending and sensitive actions
- Authorize and revoke integration connections
- View consolidated reporting without giving every user the same visibility
- Export business records and manage account termination
- Review administrative activity and security status
Employees need enough access to complete the work — not unrestricted access to the business.
- Manage schedules, assignments, and customer information for assigned locations
- View work history and completion records for direct reports
- Assign contractors limited access to job-relevant information
- Escalate issues that go beyond their approval rules
- Access reporting relevant to operational responsibility
Financial context should be visible only to the people authorized to use it.
- Access approved hours and wage summaries within authorized businesses
- View operational cost context for budgeting and reporting
- Export financial summaries in supported formats
- Access accounting integration data within configured boundaries
- Sensitive report access limited by role configuration
Every connection, permission, and administrative change should have an owner.
- Provision and deactivate user accounts
- Configure role assignments and permission templates
- Authorize and manage integration connections
- Review credential expiration and configuration changes
- Access audit history for administrative actions
- Manage data export and account configuration
Your account should show the work you need without exposing the rest of the company.
- Access assigned records, schedules, and required actions
- View customer information relevant to assigned work
- Complete job-specific forms and workflows
- Access through mobile browser with the same session protections
- Report lost devices or suspicious account activity
- Account removed promptly when engagement ends
Where The Forge Draws the Line by Industry
Regulated or specialized records are not automatically pulled into The Forge. Each industry has a documented boundary for what stays in a specialized system.
What matters in this industry
- Customer addresses and site-access information
- Job photos and inspection records
- Employee location during work hours
- Contractor vs. employee access levels
- Payment information for services
- Shared devices on job sites
- Temporary worker access for seasonal staff
How The Forge draws the boundary
- Field employees see only assigned jobs and required customer information
- Contractor accounts receive limited access without broad employee or financial visibility
- Customer addresses are visible for assigned work, not across the full customer database
- Shared-device access controlled through individual sign-in, not saved sessions
- Temporary accounts can be created and removed to match employment periods
Common Security Questions
Every control is one of four states
The matrix below also uses a fifth status, “Limited Availability,” for controls that are built but whose coverage is still expanding.
From browser to record, every hop has an owner
- Authorized UserCustomer
- Supported Web BrowserCustomer
- Encrypted Web Connection (HTTPS)HustleForge
- Identity and Session ControlsHustleForge
- Business, Location, and Role PermissionsHustleForge· Customer-configured
- Forge Application and Approved RecordsHustleForge
- Workflow, Automation, and Approval ControlsHustleForge· Human approval points
- Authorized IntegrationsThird-party provider· Read or approval-gated write
- Activity History, Monitoring, and RecoveryHustleForge
What each category covers
Security controls across the platform are grouped into 15 categories. The full inventory — every control, its status, limitations, and verification date — lives at the control inventory.
Secure Web Access
Do we need to install anything?
Identity and Sign-In
How do users sign in?
Roles and Permissions
Can employees see information outside their role?
Business and Location Separation
Can access differ by business or location?
Data Protection
How is our data protected?
Integration Security
How are integrations secured?
Automation and Approval Controls
Can automated actions require approval?
Audit History
Is activity recorded?
Platform Monitoring
How do you know when something breaks?
Availability and Recovery
What happens if something goes down?
Secure Development Practices
How is the platform built securely?
Secure Platform Updates
How are updates delivered?
Incident Response
What happens if there is a security incident?
Shared Responsibility
What are we responsible for?
Customer Data Rights
Can we export our data?
The Forge is in beta. Controls marked planned are not yet available. Contact contact@hustleforge.tech with questions about security requirements for your business.