Security & compliance
Union data is sensitive, and Unionsuite is built for it. You get detailed roles, a full history of every change, access that's locked down at the source, and data kept in Canada.
Detailed permissions
47 granular capabilities you can scope by region and branch, not just four fixed roles.
Locked down at the source
Access rules live deep in the system, not just on the screen, so they can't be worked around.
Complete change history
Every change is logged and shows who made it, so nothing is a mystery.
Data kept in Canada
Member data is stored in Canada, not somewhere else.
No password to remember
You sign in with a one-time code we email you. There's no password to leak or reuse.
Your union's look
Your name, logo, colours, and wording show up throughout.
How access actually works
From sign-in to audit trail, the controls a procurement reviewer will ask about.
Sign in with no password
To sign in, you get a 6-digit one-time code we email you. No passwords to leak or reuse, and anyone not on the access list gets no access at all. “Trust this device” keeps officers signed in for 60 days.
Roles set the baseline
Four roles, each with its own reach: Administrator (everything), Regional VP (their region), Branch Executive (their branch), Member (none). The server enforces this reach on every list and export. No setting can widen someone’s region.
Access settings fine-tune it
47 access settings, set per role or per person. Each person can be set to Inherit, Grant, or Deny, and a live “Effective” column shows the final answer. Changes reach every signed-in user in about 30 seconds, with no need to sign in again.
Everything is attributed
Member edits land in each member’s history log. Grievance actions land in each case’s log. Imports keep their history, with a saved copy of the list made before each one. And changed role settings show who changed them and when.
Built like union data deserves
Access control has layers. Roles, access settings, reach, and the database itself each do their part.
47 access settings, not 4 fixed roles
Access goes far beyond job titles. Member profiles alone use 10 view settings and 8 edit settings, one per block, so a role can edit contact fields while never seeing salary.
- Salary, home address, and dates of birth each need their own view setting before the block even appears.
- Profiles outside your area show even less, an amber banner and only the blocks that role is allowed to see.
- The server never sends home addresses to branch executives, no matter what the screen settings say.
A clear, three-layer way to decide access
Every access check works the same way: the person’s own setting first, then the role’s custom setting, then the built-in default. First match wins, so the result is always easy to predict. Bulk changes are plain text, like SET someone@union.ca editSeniority = grant, each line checked with a colour-coded preview before anything applies. Safety rails are built in: you can’t delete the last admin, your own account, or your own access to the admin tools.
Each union fully walled off, by design
Each union runs its own separate setup: its own database, hosting, web address, and email address. With no shared database, another union’s setup cannot touch your data. The separation is structural, enforced by the architecture rather than policy. Your data is hosted in Canada, and the database blocks all direct access by default: a web browser reads and writes nothing on its own, every action going through approved server steps.
Sign-in with no password, with limits on attempts
The access list is the front door: one-time codes go only to emails on it, and repeated attempts are limited, so guessing won’t work. Trusted devices stay signed in for 60 days. Branch-executive access syncs automatically from the Branches module, so when someone leaves a branch role, their access follows.
A clean exit, in writing
If your union ever leaves, the written exit steps are “export first, revoke second, delete last”. You get a full copy of your database, every stored file, and plain spreadsheet files anyone can open, handed over and confirmed in writing. Then we delete it on an agreed date. Your data goes with you, in full.
Control you can demonstrate
Access settings
Every switch can be set per role or per person, in 13 feature groups, from editing grievances down to who can see a salary block.
For access changes to apply
Grants and denials reach every signed-in user in about half a minute, no rebuild, no signing in again, no ticket to IT.
One union, one setup
Your own database, web address, and email address. No shared infrastructure, and no risk from a neighbour.
Setting counts and timing as documented in the product manual.
Security and access, asked and answered
Where does our data live?
In Canada, in your union’s own separate setup, your own database, storage, web address, and email address. No other union shares any of it. The separation is structural, enforced by the architecture itself.
Can we create custom role types?
The four base roles are fixed, but their names are yours. Branch Executives can be Stewards, and Regional VPs can be District Reps. And all 47 access settings can be set per role and per person. In practice, that’s where the flexibility lives.
What happens when an officer leaves?
Remove them from the access list and their sign-in stops working, one-time codes only go to emails on the list. Branch-executive access syncs automatically from the Branches module. And the system won’t let you delete the last admin or your own account.
How complete is the history record?
Member edits are logged per member (who, when, before and after), grievance actions per case, and imports keep their history with a saved copy of the list made beforehand. Changed role settings record who last changed them. One limit to note: per-person access changes show the current state, not a full history.
What if we decide to leave?
The written exit steps put your export first. You get a full copy of your database, every stored file, and plain spreadsheet files anyone can open, handed over and confirmed in writing. Then access is shut off and the data deleted on a date we agree on.
Why sign in with no password?
Because passwords are the weakest link in any volunteer-run group. A 6-digit emailed code is nothing to phish at scale, and nothing to reuse from a hacked site. Limits on attempts stop guessing, and trusted devices keep day-to-day use easy.