A page you can forward to your funder.
Structural facts about how COMPASS handles client data, and a plain list of the things we do not claim. Short on purpose. A long security page usually means somebody is padding.
Who can see what
Access in COMPASS is granted capability by capability rather than by job title. There are more than 200 of them, and an organization sets its own combinations without asking us.
Nothing quietly disappears
Case notes and time entries are attested records. Somebody signed them, a funder may audit them, and payroll may depend on them. COMPASS treats them that way.
| Edits create versions | Session logs, case notes and time entries are versioned. An edit writes a new version and preserves the original rather than overwriting it. |
| Deletions leave a marker | A deleted record leaves a tombstone. You can tell that something was removed, and when, rather than finding a gap. |
| Editing a signed record clears the signature | Change a signed timesheet and the signature comes off. It has to be signed again. A signature in COMPASS always refers to what is actually in the record. |
| Separation of duties | A form cannot be cosigned by the person who started it. Enforced by the system rather than by policy. |
| Audit trail | Significant actions are logged with the user, the timestamp and the detail. Exportable, and the retention period is yours to configure. |
What we do not collect
What we are not claiming
Most security pages are a wall of badges. Here is the other list, because a vendor who tells you the limits before you ask is easier to check than one who does not.
Or put the question to a person instead of reading three more pages. hello@illumipath.io