Verified sign-in
WellSim accepts a verified identity-provider subject and verified email. It does not link a new identity merely because an email resembles an existing account.
Recent MFA
Owners and administrators must complete step-up verification for company-management actions. Help publishing by platform administrators also requires recent MFA. The assurance window lasts up to 15 minutes and is tied to the same signed-in account.
Tenant isolation
Every protected operation checks active membership on the server and PostgreSQL applies row-level security to workspace data. Request-supplied user IDs, roles and workspace choices are never treated as authority.
Safe operating habits
- Do not share invitation links publicly.
- Review the active workspace before saving or exporting.
- Use a distinct account for each person; do not share administrator credentials.
- Sign out on shared devices and report unexpected access promptly.