Jarvix AI / Production Hardening

Security Center

Security Center

AreaRiskRequirement
Customer Portalcustomer_data_scopeCustomers only see their own appointments, invoices, payment methods, and profile.
Payrollsensitive_financialOnly owner/manager/payroll roles should access payroll.
Financial Centersensitive_financialOnly owner/manager/accounting roles should access financial reports.
Workforce Documentssensitive_documentsHR documents must be protected by role.
Pricing Settingsbusiness_rulesOnly owner/manager roles can change pricing rules.
Payment Methodspayment_securityOnly tokenized last4 data is shown; raw card data must never be stored.
Admin Settingstenant_securityOnly owner/admin roles can update company settings.