Skip to main content

Security

Set access.
Review activity.

As your team grows, see who joins, which permissions they hold, and which actions are recorded. Review authentication, roles, and session management against your organization’s requirements.

CoplaceProduct team · Administration

Members

The people in your team and their workspace roles.

MemberRole
MW
Maya Wilsonmaya@example.com
Owner
RP
Robin Parkrobin@example.com
Admin
AC
Alex Chenalex@example.com
Member
JL
Jamie Leejamie@example.com
Member

4 example members

Find members, compare sample permissions in Roles, or open an access record. This example does not change real permissions.

Decide on access. Follow what happens next.

Review security through four practical questions: who joins, how they sign in, whether the session is valid, and which actions are recorded.

Members and roles

See which workspace a member belongs to and the role they hold. Assign administrator permissions according to their responsibilities, and manage channel membership separately.

Explore workspace administration

Multi-factor authentication

Complete the additional verification enabled for your account during sign-in. Confirm the verification method and account or role policies during deployment planning.

Session management

Authorized administrators can review active sessions and end a session with termination permission. Viewing and termination permissions are checked separately.

Audit records

Review a sign-in or administrative event alongside its actor, time, and action. Event details give your team a shared record when discussing a change.

Ghost Mode

Make the terms of a temporary conversation clear.

Some conversations call for a temporary session. Deployment policy determines when Ghost Mode starts and when its content is cleaned up.

Participant consent
When everyone’s consent is required, the session waits for every participant to agree. Explore the waiting and approved states in the example.
End of session
Review how expiry and leaving policies govern temporary message-history cleanup.
Security review
Temporary content, access permissions, and connection encryption are separate review topics. Define your requirements for each.
Explore Ghost Mode
CoplaceTeam workspaceSample workspace
Ghost ModeThe first-week plan
Participants review the terms and give their own consent.

Data and deployment

Review the data path, from messages to backups.

Review where the application, file storage, calling infrastructure, and backups run. Define access and operating responsibilities for each service.

Connections
You connect to the Coplace cloud over HTTPS. Review connection security separately from the encryption model for messages, files, and calls. Define domains, certificates, and network boundaries for your own deployment.
Data location
Confirm where the workspace, files, and related services will run as part of the chosen deployment. Requirements for cloud deployment and your own servers may differ.
Operations
Document who owns updates, access administration, backups, and incident response.

Agree on responsibilities from the start.

Use these topics as a starting point for your review. Your deployment model and agreement define the final scope.

TopicIn the productWith your organization
Identity and accessSign-in, multi-factor authentication, roles, and permission checksAccount owners, administrator permissions, and access for departing employees
RecordsAccess and administration events for authorized reviewReview practices, retention requirements, and incident follow-up
InfrastructureApplication and data services in the chosen deploymentNetwork, certificates, backups, updates, and support scope

Questions about security

How do consent and deletion work in Ghost Mode?

The conditions for starting Ghost Mode and cleaning up content at the end of a session depend on deployment policy. When everyone’s consent is required, the session waits until all required approvals are complete. Review the scope of temporary messages, files, and previews for your deployment. Temporary content does not imply a separate encryption model.

Is encryption in transit the same as end-to-end encryption?

No. HTTPS protects the connection between a device and the service. End-to-end encryption concerns who holds the keys to the content. Review the encryption scope of messages, files, and calls separately when evaluating Coplace; HTTPS is not an end-to-end encryption guarantee.

Does Coplace support multi-factor authentication?

Coplace supports multi-factor authentication using an authenticator app. Confirm which account and workspace policies apply to your users in your deployment. An email sign-in code and multi-factor authentication are separate steps.

How are retention and backup requirements defined?

Share your requirements for messages, files, logs, and backups during deployment planning. Retention periods, deletion, backup access, and restore responsibilities need to be agreed for the chosen deployment and contract.

Can we deploy Coplace on our own servers?

You can discuss a Coplace deployment on your own infrastructure with our team. We define the technical scope and ownership of network access, data services, updates, monitoring, and backups together.

Bring your questions to our technical team.

Share your users, data requirements, and deployment preference. Let’s agree on the scope of your evaluation.