Workspace isolation
Operational records are organization-scoped. Server actions verify the authenticated user, membership, organization, role, and expected record version.
Security
Pebblyhill combines organization scoping, authenticated private-file access, role-aware commands, immutable audit history, and explicit controlled-record workflows. This page describes the current early-pilot approach, not a certification claim.
Operational records are organization-scoped. Server actions verify the authenticated user, membership, organization, role, and expected record version.
Controlled files use authenticated, organization-scoped reads rather than public download URLs. File access follows object and membership permissions.
Important workflow decisions use server-authoritative commands, idempotent command identifiers, receipts, and immutable audit events.
Firebase Authentication establishes identity. Workspace roles and team assignments govern administration, review, approval, and operational actions.
Retention, legal hold, and controlled-record locks prevent ordinary deletion where history must be preserved.
The early pilot runs as a managed cloud service. Environment secrets remain server-side and are not bundled into browser code.