Skip to content
MapMyStaff
Trust Centre

Before entrusting customer, scheduling, and pricing data to software, see what is controlled.

MapMyStaff uses specific controls to verify identity, govern certain access, recheck some requests on the server, and limit certain forms of abuse. These controls are not the same across every function.

The reference dossier is still awaiting approval. It is not a certification or a guarantee that every risk has been eliminated.

DOCUMENTEDWhat has been confirmed in the technical documents.
SCOPEEach control applies only to the functions that use it.
TO CONFIRMSome data-protection and management items still need to be completed.
01What is already confirmed

See what is already confirmed — and where the limit is.

The dossier confirms specific controls. It does not say they are active everywhere or eliminate every risk.

Sign-in for protected areas

Firebase Authentication verifies accounts and keeps session state for protected workflows that use this module.

Scope: only workflows that use this authentication.

Administrator access by group

For certain access, the system can check the group associated with the account. The dossier documents administrator group 1 in particular.

Limit: this control also depends on the deployed Firestore rules and the information stored for the user.

Protection for certain forms

On certain Web functions, App Check and reCAPTCHA Enterprise can provide signals to limit abusive calls.

Limit: these tools do not replace server validation and are not used automatically everywhere.
02Server-side checks

Some requests can be rechecked on the server.

Depending on the function, the server can check fields, request type, an address, a route, or a rule before continuing.

Key point: Reading principle: the interface does not replace the server-side validations defined for the relevant workflow.
01
The request is sentThe function receives the information expected for the action.
02
The planned checks applyThe server can check the elements required for that function.
03
The function continues according to its rulesWhat happens next depends on the documented behaviour of the function and its version.

Controls vary by function and version. MapMyStaff does not use one identical path for every action.

03Controls by function

Controls change depending on the function being used.

The trust dossier describes several specific technical contexts. It also states that the complete roles-and-permissions matrix by collection and endpoint still needs to be completed.

PROTECTED

Signed-in account

Firebase Authentication manages account identity and session state on protected workflows that use this module.

ADMIN

Administrator access

The documented access control can read the user document groupId, including administrator group 1.

WEB

Web form

App Check and reCAPTCHA Enterprise can provide application-protection or anti-abuse signals on configured functions.

SERVER

Server function

Validation of fields, request types, routes, addresses, or rules depends on the module, endpoint, and version.

05What still needs to be finalized

What still needs to be finalized.

The dossier clearly identifies the items that must be completed before final approval.

Name and contact details of the person responsible for privacy.
Data retention and destruction rules, by category.
List of providers and the places where data is processed.
Complete table showing who can access which data and functions.
Process to follow in an incident, the register, and the people to notify.
Privacy impact assessment when required for certain projects or communications outside Quebec.