Skip to content

Wrkbase security: safe enough to let an AI agent act on your data

Wrkbase security is not a compliance badge. It is six real guarantees, each shown as what actually happens, not asserted in a paragraph.

Data-driven permissions

"Own vs. any" is enforced server-side, not just hidden in the UI

Roles and permissions are resolved from real records. Whether someone can edit their own task versus anyone's is checked on the server, every time, not assumed from what buttons happen to render.

  • Every record-level scope re-derived from real data
  • Hiding a button is never the actual security boundary
The AI agent re-checks everything

A plan is never trusted just because it was drafted correctly

Every action the agent takes re-runs the full permission check right before it happens, exactly as if a human had submitted it manually, so a permission revoked mid-plan actually blocks it.

  • Re-checked at execution, not just at planning
  • The same check a human action would hit, no shortcut
Immutable audit log

A record nothing can quietly edit or delete

Every action, human or agent, is written to an audit log that database-level triggers reject any UPDATE or DELETE against, after the fact, not just by policy.

  • Enforced by the database, not the application
  • Logins, changes, and agent actions, one trail
Encrypted in transit

Every connection encrypted and verified, end to end

From your browser to our servers and back, including the live updates that stream in as your team works: HTTPS, authenticated realtime connections, and CSRF protection on every request that changes data.

  • HTTPS on every connection, no exceptions
  • CSRF protection on every state-changing request
Realtime, without polling

Live updates push over the socket, no manual refresh

Task moves, attendance changes, mentions, and leave approvals fan out live over one authenticated socket connection, so the page in front of a visitor is never stale by a page reload.

  • No unauthenticated channel for data to leak through
  • No polling: updates push the moment they happen
Multi-tenant by design

Signing up creates an isolated workspace, not a shared table with a filter

Every organization's data is scoped to that organization at the query layer. Nothing is shared with, or visible to, any other team on the platform.

  • Isolation enforced at the query layer, not the UI
  • No cross-organization query exists to make
Accounts and access

Account security on every plan

The controls an owner checks before inviting the team, all included on Free.

Two-factor sign-in

Authenticator-app codes on any account, with 10 single-use recovery codes.

Lockout on repeated failures

Five wrong passwords or codes lock the account for 15 minutes.

Sessions you can see and end

Every signed-in device listed, revoke one or log out everywhere. Password resets end every session.

Sign in with Google

Google sign-in for existing accounts, plus bot protection on sign-in and sign-up.

Custom roles, 95 permissions

Boss, HR, Manager, and Employee by default. Create your own roles and choose exactly what each can see and do.

No acting above your rank

Nobody can edit, suspend, or grant a role more senior than their own, and the AI agent is held to the same rule.

One workspace, a different view for everyone

Every role sees exactly what's relevant to it, automatically, not just hidden behind a setting.

CapabilityBossHRManagerEmployee
Task & attendance visibility
Whole company
Whole company
Own team
Own work only
Leave approvals
Salary & payroll
Full access
Full access
Own payslip only
Own payslip only
AI agent
Chat moderation (delete any message)
Roles, permissions & org settings

Sees every team, holds every approval, and is the only role that manages other roles and company settings by default.

Not even Boss gets the audit log by default. That stays a deliberate, manually-granted step, never a blanket admin power.

What we won't claim

We're not going to list a certification we don't hold just because it's expected on a page like this. If you need a specific compliance framework or a security questionnaire filled out, ask. We'll tell you plainly whether we meet it today.

An agent architecture you can actually inspect, not just trust.

Free for teams up to 5, no credit card required.