Workzo

Workzo security

Security starts with a simple question: who should see this?

Authenticated access, scoped data policies, explicit membership, and revocable sharing keep the answer clear.

An honest account of controls implemented in the current product—not a claim of certification or compliance status.

The control ledger

Six boundaries that work together.

01

Authenticated accounts

Private workspace and support routes require an authenticated Workzo session.

02

Row-level policies

Database policies scope records through user ownership, profile identity, or explicit membership checks.

03

Dataroom membership

Dataroom content is limited to members, with admin checks for management actions.

04

Document ownership

Document and folder policies verify the current user's relationship to the requested resource.

05

Private connections

Integration connection records are scoped to the profile that created them.

06

Support separation

Customers see their own conversations while internal support notes remain staff-only.

When work leaves the workspace

Sharing should be deliberate—and reversible.

01

Direct Workzo sharing

Grant another Workzo account preview or download access through its Share ID.

02

Public links

Create a read-only public link when access without a Workzo account is intentional.

03

Immediate revocation

Regenerating or disabling a public link prevents the previous token from being used again.