VisitsTracker

VisitsTrackerProduct › Control

Roles, fields and control

The settings that decide what the product asks, who sees the answers, how long they survive, and how they leave the building.

AdminSecurity

01 · Your questions

Typed fields, not a notes column

Text, number, date or a select with your own options, on stops, sites and visits.

  • A field's type and key are fixed once it exists, because values already captured were validated under them.
  • Making one required does not rewrite saved records: the next edit fills it in, and a visit cannot be marked done while it is blank.
  • A field can be marked as never reaching workers, neither the question nor the answer.
Custom fieldsVisits
Outcomeselect · order taken, follow-up, no decisionrequired
Order valuenumber · in £
Next visitdate
Internal marginnumber · hidden from workersprivate

02 · Who sees what

A manager sees their own people

And the same rule covers the map, the exports and the API, not just the screen.

  • Roles run owner, admin, manager, field and analyst.
  • Two-factor can be required as a workspace rule, with a default that does not strand field crews on shared phones.
  • Access grants give bounded, expiring visibility beyond the hierarchy, revocable in one click.
Access grantsexpiring
Grantee sees teamSouthern region90 days
Revocationone click
Require 2FA fromadmins and aboverule

03 · Retention

Deletion you can point at

You choose how long raw fixes live, with visits and hours living longer.

  • Deletion can be suspended for the workspace or one person while a matter is live.
  • The worker's own screen says when that applies to them.
  • Closing the account locks it, keeps exports for seven days, then deletes everything.
Retentionworkspace
Raw fixes24 months
Visits and hourslonger
Audit trailits own period
Legal holdsuspends deletionoff

04 · Out of the building

Read-only by default, signed on the way out

A REST API across visits, jobs, attendance, sites, zones, leave and expenses.

  • Keys are read-only unless you widen them, and one optional scope allows jobs and nothing else.
  • A key is shown once at mint time and never again.
  • Webhooks are HMAC-signed over the raw body, so you can verify rather than trust.
Developerkeys and webhooks
API keyread-onlydefault
jobs:writecreate and update jobs onlyoptional
attendance.punchwebhookHMAC-signed
zone.transitionwebhookHMAC-signed

Audit trail is append-only: approvals, permission changes, exports and deletions all leave a receipt.

Honest limits

What it does not do.

Worth knowing before you buy, not after

Two-factor is available and can be required by role. We hold no security certification to claim here, and we would rather say that than imply one.

Straight answers

Questions people ask.

Can a manager see the whole company?

Only if you give them that role. Scoping applies to the map, exports and API alike.

How long is data kept?

For the retention period you set, with raw fixes typically shorter than visits and hours. Deletion can be suspended while a dispute is open.

Are API keys read-only?

By default, yes. One optional scope permits creating and updating jobs, and nothing else.

Can I get everything out?

Yes, the whole workspace as CSVs, at any time, and for seven days after closing the account.

Try it on one van for a week.

Put it on one phone, run a normal week, and see what comes out the other end.