Access control
Role and scope-based access should ensure users only see the customers, countries, projects and contractors they are authorised to manage.
Obtempera is being designed around controlled access, auditability, privacy and responsible handling of workforce and contractor information.
We will only publish certifications, uptime commitments or security standards once they are actually implemented, independently verified where appropriate, and supportable.
Role and scope-based access should ensure users only see the customers, countries, projects and contractors they are authorised to manage.
Changes, reviews, approvals, overrides and key compliance decisions are designed to retain clear history.
Collect and retain only the information needed to support configured compliance requirements and legitimate workflows.
Worker registration includes versioned privacy acknowledgement and context around customer, contractor, country and project.
Documents and compliance evidence are intended to be protected through controlled access and secure storage architecture.
Production deployment will include backup, recovery, monitoring and environment controls appropriate to the service.
Obtempera’s worker model is designed to retain the privacy notice version, acknowledgement context, customer, contractor, country and project information associated with registration.
Production data-protection documentation, retention schedules, hosting details and subprocessor information will be published as the service moves toward launch.