Every action signed in. Every session yours to end.
Each workspace is sealed off from every other, every administrative action requires a valid sign-in, and you can see and revoke each device your account is signed in on.
What the platform enforces
Each of these is applied by the application itself rather than left to procedure — the distinction that decides whether a control survives a busy week.
Workspace isolation
Every administrative request is scoped to the signed-in business. One workspace can never reach another’s records.
Sign-in on every action
Creating, editing, deleting and status changes all require a valid session. Unauthenticated requests are refused outright.
Automatic lockout
Five consecutive failed sign-ins lock the account for fifteen minutes. A successful sign-in clears the count.
Silent password reset
A reset request never reveals whether an email is registered, so the form cannot be used to discover accounts.
Time-limited reset links
Reset links expire an hour after they are issued. Expired links are refused with a prompt to request a new one.
Short-lived credentials
Access credentials last minutes, not weeks, and are refreshed against a longer-lived session that rotates as it is used.
Session list and revoke
See every device your account is signed in on, with its last-active time, and end any of them individually.
Suspension stops everything
A suspended workspace blocks public access, sign-in, booking, support submissions and outbound email in one action.
Platform-only controls
Listing, creating and suspending workspaces is restricted to the platform operator, and the platform’s own workspace cannot be suspended.
What this does not do
Worth knowing before you buy rather than during a trial. This is how the platform works today.
No per-user permission tiers
Any user signed in to a workspace can perform every administrative action in it — manage services, update bookings, change branding and settings. Where separation of duties matters, run a separate workspace per team or brand; each is fully isolated, and each carries its own subscription.
The log covers access, not content
Sign-in and session events are recorded with device and address. Content changes — a service edit, a booking status update, a settings change — are not currently written to that log, so treat it as a security record rather than a full change history.
Separation by workspace
Multi-brand operators
Each brand gets its own workspace, domain, catalogue and staff. Nobody working on one can see another.
Resellers
Every client sits in an isolated workspace. Their staff sign in to theirs; you keep the platform view.
Multi-location businesses
Give each location its own workspace when branch data genuinely should not be shared between managers.
Single businesses
One workspace, one team, everyone trusted with the same access — which is how most small operators work anyway.
Frequently asked questions
Can one business see another business’s data?
Can I give team members different permission levels?
What happens if someone guesses at a password?
Can I see where my account is signed in?
Is there an activity log?
What happens to a workspace that is suspended?
Ready to see how it works for your business?
Book a personalized demo and we'll show you Servio in action.