Workforce evidence is sensitive. Treat it that way.
Trakium uses organisation scope, revocable sessions, role-based access, protected screenshot links, and auditability as foundations—not enterprise add-ons.
Security controls connected to the evidence lifecycle.
The exact production architecture and responsibilities are documented in the deployment proposal.
Revocable sessions
Opaque session tokens are stored as hashes and can be revoked; browser cookies are HttpOnly and SameSite protected.
Role-based access
Organisation owners, administrators, managers, and members receive different access based on the work they need to perform.
Organisation scope
Workforce records are stored and queried with organisation context so one tenant is not treated as a naming convention.
Protected screenshot access
Screenshot objects are accessed through short-lived, scoped URLs rather than permanent public links.
Audit trail
Administrative actions and sensitive access can be recorded for organisation-level review.
Employee transparency
Employees can see their own record, supporting correction and a more transparent monitoring policy.
Software controls do not replace a responsible monitoring policy.
Before installing the agent, the customer remains responsible for defining a lawful and proportionate purpose, employee notice, access roles, retention, review standards, and an escalation path.
Minimum rollout checklist
- Document why each captured signal is necessary.
- Tell employees what is recorded and when.
- Restrict screenshot and organisation-wide access.
- Set a retention period appropriate to the purpose.
- Never treat one activity signal as an automatic disciplinary conclusion.
- Provide a process for correction, concern, and access requests.
Review security before the pilot.
We’ll walk through authentication, roles, data flow, screenshot access, deployment assumptions, and your organisation’s monitoring policy.