الحساب والإعدادات

إعدادات الأمان

أدر خيارات الأمان والمصادقة متعددة العوامل وضوابط الوصول.

مركز المساعدةاقرأ المقال

الحساب والإعدادات

تحكم فعلي بالوصول حسب الأدوار يُطبَّق على مستوى الخادم، وليس مجرد إخفاء للقوائم، مع قائمة صريحة بما هو غير متاح ذاتيًا بعد.
إعدادات الأمان

Careersome's access model combines role-based access control (RBAC) with subscription entitlements: to do something, your role must permit it and your organization's plan must include the underlying module. Access is enforced on the server (routes and APIs), not only hidden in the UI.

Access control (RBAC)

  • Admin, HR, Manager, and Employee map to different menus and different data scope
  • Admin is the only role with Organization settings
  • Managers see data for their direct reports when team features are enabled
  • Employees see their own personal data and tasks
  • Company isolation keeps every user scoped to their own organization (multi-tenant separation)

Account credentials

  • Users sign in with an email and password
  • Forgot password: users can request a password reset by email
  • Change password: signed-in users can change their own password from their account
  • Candidate pre-onboarding access uses a separate one-time-passcode (OTP) email flow; this is specific to the candidate portal and is not a login method for employee accounts

Transport and hosting

  • Traffic between the browser/API and Careersome is served over HTTPS/TLS
  • Careersome runs on managed cloud infrastructure with tenant data isolation

Your responsibilities

  • Assign the smallest appropriate role to each person
  • Review access when people change jobs and remove leavers promptly (this also frees seats)
  • Use a strong, unique password and protect your devices

Not currently self-serve in the product The following were checked in the codebase and are not exposed as configurable end-user security settings today: multi-factor / two-factor authentication (2FA) for employee login, single sign-on (SSO/SAML), configurable session timeout, and a user-facing security audit log. Do not tell users these exist. Enterprise agreements may add governance, data-processing, and deployment terms beyond the standard product; direct security-questionnaire and enterprise requests to [email protected] or your account executive.

<!-- VERIFY with product/security team: any 2FA, SSO, session-timeout, or audit-logging capabilities are NOT present in the application code reviewed. If these exist at the infrastructure or enterprise-contract level, product to confirm before we document them. -->

ما زلت بحاجة إلى مساعدة؟

لا يمكنك العثور على ما تبحث عنه؟ اتصل بفريق الدعم لدينا.