Compliance That Enforces Itself

An operational control layer, not a compliance checklist. Soft-blocks prevent non-compliant operations automatically. Training gates prevent unqualified deployment. Audit packs generate on demand for any auditor.

Multi-Jurisdiction Document Verification

Two-tier compliance: Company-Level requirements (global) and Jurisdiction-Level requirements (state/regional). Documents are categorized as Business License, Insurance, W-9, or state-specific security licenses. Platform owners review with in-app preview (PDF/image), then approve or reject with feedback notes.

A company can be fully operational in Florida but soft-blocked in Texas until their Texas-specific license is verified and approved.

Soft-Block Enforcement Model

Non-compliant tenants retain full dashboard access for viewing, but operational 'write' actions are blocked. They cannot dispatch guards, assign shifts, or generate invoices until documentation is verified. Enforcement is jurisdiction-granular, not binary.

30-day grace period for new tenants. After grace period, soft-block activates automatically for jurisdictions with unverified documents.

Automated Expiration Monitoring

An edge function (check-compliance-expirations) runs on schedule and sends automated notifications at 90, 60, 30, 14, and 7 days before document expiry. Compliance scores calculate dynamically as a percentage of approved documents across all required categories.

Amber warnings at 30 days. Red warnings at 7 days. Expired documents trigger immediate soft-block for the affected jurisdiction.

Training Gating Rules

Training is not just tracked; it is enforced at the system level. Gating rules block employees from scheduling, dispatch, and deployment until required training packs are completed. Rules are configurable by license level, position, or specific site. Managers cannot override them.

Academy LMS bundles courses with required/optional designations and passing thresholds. Platform owners manage master templates; tenants customize for their organization.

Six Layers of Audit Coverage

Every action, access event, financial transaction, and administrative change is captured with full actor attribution and tenant context.

Platform Audit Logs

All cross-tenant administrative actions logged via centralized RPC, capturing event_type, actor_id, target details, tenant_id, severity classification (info/warning/error/critical). Retained for 7 years.

Tenant Audit Logs

Tenant-scoped administrative actions tracked independently within each organization. Full actor attribution with timestamps.

API Usage Logs

Every API request logged with endpoint, method, IP address, response time, status code, and API key used. Retained for 2 years. Supports usage-based billing.

Billing Audit Logs

All financial actions tracked, including invoice creation, payment processing, refunds, and billing configuration changes. Full attribution.

Gate Access Logs

Every badge scan event with timestamp, gate location, and direction (entry/exit). Supports real-time headcount, historical access review, and emergency muster.

Context Switch Audit

Every platform owner context switch into a tenant recorded with entry time, exit time, actions performed, and deep-clean cache purge verification.

Log Retention Policy

Formal retention schedules enforced at the infrastructure level.

Audit Logs7 Years
API Usage Logs2 Years
Auth Logs90 Days

Per-Employee Compliance Tracking

Every certification, training requirement, document acknowledgment, and license status is tracked individually and enforced automatically.

  • Certification expiration tracking with proactive alerts at 90/60/30/14/7 day intervals
  • Required training completion verification, where gating blocks deployment until done
  • Document acknowledgment tracking with individual timestamps and attribution
  • License status monitoring per employee with license-level position validation
  • Per-employee compliance dashboard showing all gaps at a glance
  • Training gating prevents scheduling and dispatch of uncertified personnel

Audit Pack Generator

Generate structured compliance packages on demand, ready for client review, government audit, or insurance verification.

  • Filter by date range, site, employee, department, or compliance category
  • Bundles incidents, training records, SLA breaches, gate access logs, and audit trail data
  • JSON manifest for automated processing by client compliance systems
  • CSV and PDF export formats for human review and stakeholder distribution
  • SLA compliance reports with breach counts, recovery tracking, and trend analysis