Fieldiz security

Company data stays scoped. Sensitive actions stay accountable.

Fieldiz is designed around tenant isolation, role and record-scope authorization, secure provider credentials, and useful audit history.

No card required · Free plan available · Built for U.S. service businesses

Access decision Live

Permission and record scope both apply.

2 Security domains
0 Plaintext secrets
Company boundary Authorized
Action permission Manage jobs
Record scope Assigned only

Built for the real workday

Security foundations that match a multi-tenant field-service platform.

Give every teammate the context and next action they need without adding software clutter.

Focused access

Roles combine actions with assigned, team, or all-record visibility.

Audit history

Sensitive admin, permission, credential, and payment actions are logged.

Clear by default

Payments and credentials follow provider-safe patterns.

Raw card data never reaches Fieldiz servers. API keys and webhook secrets are protected after creation, and signed provider webhooks are verified and processed idempotently.

  • Separate Fieldiz platform administrators from company administrators
  • Stripe-hosted payment handling with verified webhook signatures
  • Predictable API errors, idempotent creates, and secrets hidden from logs

A practical Fieldiz guide

A closer look at Fieldiz platform security

Use this guide to evaluate the daily workflow, setup decisions, team access, integrations, and reporting that matter to company owners, administrators, security reviewers, and integration teams.

01

What Fieldiz platform security should solve

A useful Fieldiz platform security workflow starts with the people doing the work, not with a long settings list. For company owners, administrators, security reviewers, and integration teams, the important question is whether the system makes today’s next action easier to see and complete. Fieldiz is designed around tenant isolation, server-side authorization, roles, record scopes, administrator separation, secret protection, Stripe-safe card handling, signed webhooks, idempotency, and audit logs.

The records are connected through the same company boundary and domain API. That means a customer or lead does not lose context when the work becomes a job, an appointment changes, a document is issued, a payment arrives, or an automation runs. The result is clear boundaries and accountable sensitive actions across a multi-tenant platform.

When evaluating this workflow, follow one realistic record from beginning to end. Confirm what the first user sees, which fields are required, who owns the next step, what happens when information is incomplete, and how the team can recover from a mistake. Then check whether the same source, customer, service location, conversation, and status remain understandable after the record changes shape. This practical test reveals more than a feature checklist because it shows whether Fieldiz platform security actually reduces handoffs for company owners, administrators, security reviewers, and integration teams.

  • Keep the company, customer, service location, job, and activity history connected
  • Use American English, sentence-case labels, and specific actions that explain what happens next
  • Give office and field users focused views without hiding the operational trail from authorized managers
02

Set up the workflow around the company

Every Fieldiz company is a separate tenant with its own services, statuses, team, roles, forms, automations, integrations, document settings, numbering, tax rate, and notification preferences. That flexibility matters because company owners, administrators, security reviewers, and integration teams may follow similar stages while using different names, territories, responsibilities, and customer promises.

Fieldiz begins with sensible trade and role defaults, then lets the company adjust the parts that genuinely differ. Action permissions are combined with assigned, team, or all-record scopes. Sensitive platform administration remains separate from company administration. This keeps customization useful without turning company setup into a security shortcut or an unstructured collection of switches.

Configuration should also have a clear lifecycle. Services, roles, expense names, forms, and automations may need to be archived after they have history, while document numbering and other accounting-sensitive settings should become protected after use. Fieldiz favors readable defaults, explicit save actions, and activity records for important changes. The company can grow its setup without silently rewriting older jobs, documents, messages, or reports that depended on the previous configuration.

  • Start with trade-specific services instead of importing every industry’s catalog
  • Configure company details, logo, time zone, tax, numbering, roles, and communication preferences once
  • Preserve server-side tenant and permission checks even when a client sends a record or company identifier
03

Keep the office, field, and customer in sync

Field-service work changes during the day. A customer calls back, a technician finishes early, an urgent job arrives, a part delays a return visit, or an estimate becomes approved work. The system should make those changes visible without forcing the team to repeat the entire story in a group chat.

Fieldiz keeps schedules, map context, job statuses, communication, documents, expenses, and activity connected. Technicians can work from responsive and native-ready flows, while managers can review the wider pipeline and logs. Email and SMS events can follow company, role, and user preferences, with delivery state recorded so a failed or skipped message is diagnosable rather than mysterious.

Communication deserves the same care as scheduling and status. A new lead alert, appointment reminder, on-the-way message, estimate delivery, invoice notice, payment receipt, or internal failure alert may need a different recipient and channel. Company policy establishes what is allowed; role and user preferences refine who receives it. Consent and opt-out rules apply to customer SMS, verification protects account access, and safe logs help support teams diagnose delivery without revealing credentials or unrelated customer data.

  • Use one customer and service-location history across leads, jobs, appointments, documents, and payments
  • Show technicians the work and actions relevant to their assignment and permission scope
  • Record operational, delivery, integration, payment, and sensitive administrator events safely
04

Measure outcomes without separating them from the work

Reporting is more trustworthy when it comes from the same records used to operate the day. Fieldiz connects tenant isolation, server-side authorization, roles, record scopes, administrator separation, secret protection, Stripe-safe card handling, signed webhooks, idempotency, and audit logs, allowing authorized users to review counts, timing, value, costs, status, and source with the operational context still attached. The goal is not a dashboard full of numbers; it is a short list of decisions the owner or manager can act on.

Marketing reporting can combine Google Ads cost and selected GA4 conversion events with Fieldiz lead, booking, invoice, and collected-value data. Financial workflows can compare services, expenses, document totals, payments, and job context. Automation and delivery logs explain what ran and what failed. Together, those views help the company move toward clear boundaries and accountable sensitive actions across a multi-tenant platform.

A useful review should end with an action. An open-lead count should lead to the correct owner and response history. A busy schedule should lead to the jobs, technicians, service areas, and conflicts involved. A marketing number should lead to the connected account, selected conversion, campaign cost, source, and Fieldiz outcome. A margin concern should lead to services, expenses, invoice value, payments, and job history. Fieldiz is designed so authorized users can move from summary to evidence and then make the next operational change.

  • Review today’s appointments, open leads, overdue invoices, jobs to schedule, and recent activity
  • Connect source and campaign data to selected conversions, booked work, and reported revenue outcomes
  • Use stable IDs, explicit time zones, predictable errors, and retry-safe mutations across web and mobile clients

A connected implementation

Put Fieldiz platform security into practice

Start with the smallest useful workflow, confirm ownership and notifications, then expand connections and automation after the operating trail is clear.

  1. 1

    Configure the company

    Choose the trade, company details, services, statuses, roles, numbering, tax, branding, and notification defaults.

  2. 2

    Connect the intake

    Set up the relevant sources and workflows for tenant isolation, server-side authorization, roles, record scopes, administrator separation, secret protection, Stripe-safe card handling, signed webhooks, idempotency, and audit logs, then test the path with safe demo data before relying on live traffic.

  3. 3

    Assign clear ownership

    Use roles and record scopes so the person responsible can act while other company data stays appropriately limited.

  4. 4

    Run the daily workflow

    Keep the customer, service location, schedule, job, communication, document, expense, and activity trail connected.

  5. 5

    Review and improve

    Use operational, financial, marketing, automation, and delivery data to work toward clear boundaries and accountable sensitive actions across a multi-tenant platform.

Good to know

Questions, answered clearly.

Can one company access another company’s records?

No. Company-owned records are tenant-scoped and server-side authorization is required for every request.

Does Fieldiz store card numbers?

No. Stripe-hosted or embedded payment components handle raw card data.

Are API credentials visible after creation?

Secrets are not stored or returned in plaintext after creation.

Can we customize services, statuses, roles, and automations?

Yes. Fieldiz provides practical defaults and lets each company create, rename, reorder, or archive its own operational setup. Stable internal behavior remains in the domain API so web and mobile clients follow the same rules. Authorized company users can review the related configuration and activity without crossing another company’s tenant boundary.

Does Fieldiz support email and SMS notifications?

Yes. Transactional email is designed for a managed SMTP provider, and customer SMS uses Twilio with company sender registration, consent, opt-out behavior, usage handling, preferences, retries, and delivery logs. Authorized company users can review the related configuration and activity without crossing another company’s tenant boundary.

Can Fieldiz connect to Google, Facebook, Stripe, and websites?

Yes. The platform includes company-level integration patterns for Google marketing data, Facebook leads, Stripe Connect customer payments, hosted or embedded forms, and a versioned API. Provider keys still need to be configured before live traffic is enabled. Authorized company users can review the related configuration and activity without crossing another company’s tenant boundary.

Is Fieldiz available on mobile?

Fieldiz includes a responsive web application and a native Expo foundation for iOS and Android. Mobile contracts use the same versioned API and include cached reads plus safely retryable non-payment mutations for intermittent field connectivity. Authorized company users can review the related configuration and activity without crossing another company’s tenant boundary.

Can we try paid capabilities before adding a card?

Yes. Paid plans begin with a 14-day Pro trial and no credit card is required at sign-up. The company selects an available plan and adds billing before paid access continues after the trial. Authorized company users can review the related configuration and activity without crossing another company’s tenant boundary.

A calmer day starts here

Ready to put the workday in one place?

Try every Pro feature for 14 days. No credit card required.

Start free