VisitsTracker › Product › Control
Roles, fields and control
The settings that decide what the product asks, who sees the answers, how long they survive, and how they leave the building.
AdminSecurity
01 · Your questions
Typed fields, not a notes column
Text, number, date or a select with your own options, on stops, sites and visits.
- A field's type and key are fixed once it exists, because values already captured were validated under them.
- Making one required does not rewrite saved records: the next edit fills it in, and a visit cannot be marked done while it is blank.
- A field can be marked as never reaching workers, neither the question nor the answer.
02 · Who sees what
A manager sees their own people
And the same rule covers the map, the exports and the API, not just the screen.
- Roles run owner, admin, manager, field and analyst.
- Two-factor can be required as a workspace rule, with a default that does not strand field crews on shared phones.
- Access grants give bounded, expiring visibility beyond the hierarchy, revocable in one click.
03 · Retention
Deletion you can point at
You choose how long raw fixes live, with visits and hours living longer.
- Deletion can be suspended for the workspace or one person while a matter is live.
- The worker's own screen says when that applies to them.
- Closing the account locks it, keeps exports for seven days, then deletes everything.
04 · Out of the building
Read-only by default, signed on the way out
A REST API across visits, jobs, attendance, sites, zones, leave and expenses.
- Keys are read-only unless you widen them, and one optional scope allows jobs and nothing else.
- A key is shown once at mint time and never again.
- Webhooks are HMAC-signed over the raw body, so you can verify rather than trust.
Audit trail is append-only: approvals, permission changes, exports and deletions all leave a receipt.
Honest limits
What it does not do.
Worth knowing before you buy, not after
Two-factor is available and can be required by role. We hold no security certification to claim here, and we would rather say that than imply one.
Straight answers
Questions people ask.
Can a manager see the whole company?
Only if you give them that role. Scoping applies to the map, exports and API alike.
How long is data kept?
For the retention period you set, with raw fixes typically shorter than visits and hours. Deletion can be suspended while a dispute is open.
Are API keys read-only?
By default, yes. One optional scope permits creating and updating jobs, and nothing else.
Can I get everything out?
Yes, the whole workspace as CSVs, at any time, and for seven days after closing the account.
Keep going
The rest of the product.
Try it on one van for a week.
Put it on one phone, run a normal week, and see what comes out the other end.