Security

Security is part of the operating model, not an afterthought.

Devv PropOS is being built with tenant boundaries, role-aware access, server-side workflows, and auditability as core product requirements.

Tenant boundaries

PropOS records are scoped to organizations. Access rules are designed so authenticated users only work inside the agency context they belong to.

Server-side mutations

Business writes are handled through server-side workflows that validate input and scope organization, branch, ownership, and audit fields before data changes are made.

Role-aware access

The product supports principal, administrator, branch manager, and agent operating roles. These roles are used to shape visibility and management actions.

Audit posture

Important operational and security-sensitive actions are intended to leave an audit trail so agencies can understand what changed and who was accountable.