exodus field

Security and data

Who can see what, stated exactly.

Field data is sensitive twice over: it is your crew's whereabouts and your client's property. Both are handled on a need-to-know basis.

Company isolation

Every record carries its company

Punches, sites, units, photos, receipts and settings are stamped with the company that owns them, and every read is filtered by that company on the server.

Enforced server-side, not in the app

The phone never decides what it is allowed to see. A token from one company cannot reach another company's data even if the request is crafted by hand.

What a tech can see

Their own hours only

A tech sees their punches, their jobs and their receipts. Crew members cannot see each other's hours or pay.

Admins see the company

Whoever holds the admin role sees all hours, approves timesheets and expenses, and edits punches. Every edit is written to an audit trail with who changed what.

Location data

Only while the clock runs

Location is read at the punch and sampled on a ten-minute cadence during a shift. Off the clock, nothing is collected.

Stored as distance and grade

What the record keeps is the fix, its accuracy and the distance to the job site — used to verify presence, not to trace a route around town.

Client-facing records

Read-only and revocable

Shared records are read-only links you can kill at any time. They expose one property and one week.

Scoped by construction

Pay rates, other properties, other clients and other techs' timesheets are not part of the shared record.

Retention and export

Your history stays yours

Records and photos are kept for the life of the account so last year's turn is still provable this year.

Export on demand

Any property's week prints to a clean sheet, and account data can be exported on request.

Deletion on request

Ask and an account and its data are removed. Records already shared with a client are revoked at the same time.