Sign-in for protected areas
Firebase Authentication verifies accounts and keeps session state for protected workflows that use this module.
Scope: only workflows that use this authentication.MapMyStaff uses specific controls to verify identity, govern certain access, recheck some requests on the server, and limit certain forms of abuse. These controls are not the same across every function.
The reference dossier is still awaiting approval. It is not a certification or a guarantee that every risk has been eliminated.
The dossier confirms specific controls. It does not say they are active everywhere or eliminate every risk.
Firebase Authentication verifies accounts and keeps session state for protected workflows that use this module.
Scope: only workflows that use this authentication.For certain access, the system can check the group associated with the account. The dossier documents administrator group 1 in particular.
Limit: this control also depends on the deployed Firestore rules and the information stored for the user.On certain Web functions, App Check and reCAPTCHA Enterprise can provide signals to limit abusive calls.
Limit: these tools do not replace server validation and are not used automatically everywhere.Depending on the function, the server can check fields, request type, an address, a route, or a rule before continuing.
Controls vary by function and version. MapMyStaff does not use one identical path for every action.
The trust dossier describes several specific technical contexts. It also states that the complete roles-and-permissions matrix by collection and endpoint still needs to be completed.
Firebase Authentication manages account identity and session state on protected workflows that use this module.
The documented access control can read the user document groupId, including administrator group 1.
App Check and reCAPTCHA Enterprise can provide application-protection or anti-abuse signals on configured functions.
Validation of fields, request types, routes, addresses, or rules depends on the module, endpoint, and version.
The Trust Centre is a starting point: it separates technical mechanisms, data categories, and legal texts so their scopes are not mixed together.
The technical resources explain the mechanisms and their limits.
Overview of documented security mechanisms and their limits.
View page → ArchitectureExplanation of the separation between the interface and server-side checks.
View page → AccessAccess principles; the complete table of all permissions still needs to be finalized.
View guide →The trust dossier lists the data categories observed in the documented version.
The legal dossier states that these pages remain controlled drafts that are not indexed until approval.
The policy still needs completion and approval before it is final.
View draft → Controlled draftThe website terms still need validation before final publication.
View draft → Controlled draftThe SaaS terms still need approval before they are final.
View draft →The dossier clearly identifies the items that must be completed before final approval.