audittrailexportorganisation separation

Trust around assignment records

ProSafetyMatch records operationally what was agreed, changed, responded to and executed per engagement. Organisations with heavier requirements can align extra access, export and audit features.

Not every party sees the same information. For the parties involved per assignment, the recorded core context stays usable within role-bound access; each party can respond or add factual context where the workflow allows it.

Security Add-on covers identity and access capabilities such as SSO, 2FA policy, IP and session controls and advanced audit export. Trust Pack adds extra bundle and export routes, verification and procurement assets to the core dossier. Integrations Pack covers external-system connectors. Availability remains subject to plan, configuration and agreed scope.
ProSafetyMatch records operationally. It does not assess labour relationships and does not provide legal or compliance guarantees.

Practical for a first pilot

Starting small mainly requires clear scope, roles and handover

A scoped pilot does not require the whole organisation to move at once. Up front we limit which data is needed, who gets access, which confirmations and changes must remain traceable and in which form handover or export is needed.

Baseline for a limited pilot

  • Only the data needed to test one assignment line: assignment context, roles, changes, confirmations, reporting and handover.
  • Access and roles stay bounded per involved party or organisation role, in line with the agreed pilot scope.
  • Changes and confirmations remain traceable with timestamps in the same dossier line.
  • Basic dossier handover can use PDF, HTML or JSON where role and pack allow it.

Additional for broader rollout

  • SSO, session controls and additional access measures where organisation policy requires them.
  • Trust Pack routes for additional bundle, verify or export needs under the related permissions.
  • Integration agreements, tenant mapping and broader audit or export scope when the work goes beyond a first pilot.

What we can share during fit check or preparation

Depending on the question, we can review pilot scope, export forms, the DPA, subprocessor register, add-on boundaries and relevant trust documentation up front. That is meant to assess the first pilot in a controlled way, not to claim more than the product scope supports.

So for a first pilot: start small, role-bounded and traceable. Additional requirements for broader rollout can be assessed separately afterwards.

Access and assignment readiness (optional)

Access and assignment readiness (optional) records which access, documents or preparation are needed before someone starts. See Pricing for basic vs extended; in a pilot we align which layer fits.

Context: demonstrability & data

Where organisations ask for more demonstrable organisation of engagements, a dossier that records facts becomes more relevant. ProSafetyMatch supports that record-keeping as a dossier layer — without legal conclusions or an automatic compliance outcome.

The platform is designed around a minimal data model (minimum data model): no special categories of personal data are required for core functionality.

Metadata minimisation for reporting photos: ProSafetyMatch does not include camera metadata such as EXIF/GPS with reporting photos. Photos remain linked to the assignment record they were added to and are not used for location tracking.

Audit trail & timestamps

core

Confirmations are timestamped and retrievable. The dossier is exportable as a dossier layer.

Per assignment, changes, responses and confirmations are recorded with timestamps (ProjectAuditLog). Under Trust Pack, a hash chain and verify-chain endpoint can support role-bound dossier verification — not a legal conclusion, not personnel assessment and not a platform-wide tamper-evident claim. The general platform log (admin/ops) follows different retention and has no hash chain.

Exportable dossier

pdf standardJSON snapshot for organisation rolesCSV/bundle via Trust Pack

PDF is standard for operational handover. JSON snapshot is intended for organisation roles. CSV and bundle are intended for role-bound reconstruction and handover via Trust Pack.

Trust Pack JSON package and bundle include a dossier fingerprint (hash) and a verify-chain endpoint for signed-in users with project access under Trust Pack. This verifies the integrity of the dossier line, not the performance of an individual professional. PDF is a handover export, not a public verification link.

Organisation separation & access

Multi-organisation setup with separation per organisation and access control (in line with your configuration).

Integration security (pilot)

Integrations Packpilot scope

In integration scope we work with partner/organisation keys and controlled webhook/API communication — aligned per pilot.

This falls under Integrations Pack, not Security Add-on.

Trust Controls

Available via Security Add-on where activated

Security Add-onEnterprise focus

ProSafetyMatch keeps the data model minimal, with concrete access controls for organisations that want extra certainty.

  • SSO on request for pre-provisioned accounts: OIDC/SAML per organisation where configured (for example Okta or Microsoft Entra); no automatic user creation from the IdP response.
  • 2FA policy setting per organisation
  • IP allowlisting (access via office/VPN)
  • Session management (maximum session duration)

Audit en gecontroleerde toegang

Beheerexport en advanced audit export-scope op projectniveau

  • Filter by entity, action, actor and period (internal admin export)
  • JSON or CSV export via the admin interface for internal reconstruction and reviews
  • Dossier export with SIEM-ready mapping at project level (Trust Pack + dossier export + advanced audit export + organisation-side roles with project access — same threshold as export-pack): JSON mapping for pull-oriented consumption of export-pack data; ProSafetyMatch does not push live security monitoring into your environment.
  • External links for view-only or audit-only receipt acknowledgement, issued by authorised organisation roles with project access
  • Intended for internal reviews, reconstruction and client reviews within role boundaries

Security Control Matrix

Security Control Register

Per control: scope, dossier route and activation conditions.

Document Class

ProSafetyMatch Security Control Register

Scope: Product featuresStatus: Available by licenceAudience: Enterprise/Government
Control IDDomainControlScope / PackVerification routeActivation status
PSM-AT-01AuditAudit trail & timestampsCoreDossier events and PDF export show event rules and timestamps.Available in Core
PSM-ID-02IdentitySSO on request (OIDC/SAML where configured)Security Add-onLogin flow with SSO policy active, without local password path.Requires Security Add-on
PSM-ID-03Identity2FA policy per organisationSecurity Add-onPolicy active: magic-link login is blocked, user is directed to SSO (MFA at IdP level).Requires Security Add-on
PSM-NA-04Network AccessIP allowlistingSecurity Add-onAllowlist configuration active: magic-link request from unauthorised IP is blocked. Applies at authentication, not for existing sessions.Requires Security Add-on
PSM-SE-05SessionSession managementSecurity Add-onConfigured session max age is applied when creating a ProSafetyMatch session (OIDC/SAML flows). Supabase magic-link session respects the shorter of policy and Supabase default.Requires Security Add-on
PSM-AE-06Audit ExportAdvanced audit exportSecurity Add-onAdmin export with actor/period filter and JSON/CSV output file, where audit export is activated.Where audit export is activated
PSM-SI-07Audit exportSIEM-ready mapping endpointTrust Pack + Advanced audit exportEndpoint response at project level with Trust Pack + dossier export + advanced audit export active; organisation-side roles with project access only (same threshold as export-pack). Pull-oriented schema — not a live SOC feed.Requires Trust Pack + advanced audit export
PSM-IN-08IntegrationsIntegration authentication (keys/webhooks)Integrations PackSigned webhook/API key flow on active Integrations Pack.Requires Integrations Pack

Security/identity controls fall under Security Add-on. Integration connections fall under Integrations Pack. This keeps scope and contracting boundaries clear.

Security & Trust

Audit trail & export

Changes and confirmations are recorded with timestamps so you can retrieve per engagement what was agreed. Export is intended as a record layer for captured context, not as a legal statement.

Per assignment, changes, responses and confirmations are recorded with timestamps (ProjectAuditLog). Under Trust Pack, a hash chain and verify-chain endpoint can support role-bound dossier verification — not a legal conclusion, not personnel assessment and not a platform-wide tamper-evident claim. The general platform log (admin/ops) follows different retention and has no hash chain.

Access & separation

Access is role-based. In a multi-organisation context, the setup is intended to limit access to organisation data within configured tenant and role boundaries.

role-based accessorganisation separationexport (dossier)audittrail
ProSafetyMatch is the assignment record layer per assignment, on top of existing planning. It helps teams record assignment context carefully while keeping roles separated. Assessment and obligations remain with the involved parties and competent authorities.