Every company is its own tenant
Data is scoped to the workspace it belongs to, on every read and every write. Switching between companies is an explicit switch, not a filter on a shared pile.
Short answers, and where to check them yourself once you're in.
Data is scoped to the workspace it belongs to, on every read and every write. Switching between companies is an explicit switch, not a filter on a shared pile.
A person sees a company's books because they were invited to that company, or because that company accepted their firm. Remove the membership, or end the engagement, and the access goes.
What someone is allowed to do and what the subscription includes are two different checks, and both have to pass. A client viewer can't reach the internal pages regardless of plan.
Every change is attributed and timestamped. History is kept for at least as long as your jurisdiction requires records to be kept — your plan can extend that window and cannot shorten it.
A posted entry in a closed period can't be edited. It can be reversed, in an open period, on the record.
Passwords live in Firebase Authentication, never in this application. A new password account confirms its address before any books are opened on it.
The sample business workspace has the same access model as a real one. Open it, change a role, close a period, and read the audit trail it leaves behind.