Access controls
Firebase Authentication establishes identity; backend roles and ownership rules determine access.
- UID-based accounts
- Role-based team access
- Protected routes
- Inactive-account blocking
Authentication, authorization, consent and protected storage work together.
Firebase Authentication establishes identity; backend roles and ownership rules determine access.
Firestore is restricted, documents use protected storage paths and traffic uses encrypted transport.
OTP and secrets are never shown in staff records. Sensitive actions are designed for audit logging.