How data are kept separate
How the platform keeps one organisation's data away from another's, keeps each employee's record private from colleagues, and enforces roles in the database.
Every person and every record on the platform belongs to one organisation. When someone opens a screen, the database checks who they are and what their role allows before it returns anything. Menus show only what a person's organisation and role allow, and the same checks run behind every screen, so a person who types the address of a screen they should not see still gets nothing from it.
Between organisations
If someone opens a join link with an email that already belongs to an active employee at another organisation, the platform refuses it, so one person cannot end up on two organisations' rosters that way.
Admins can only invite people on their own roster. An invitation aimed at someone outside it gets the same reply as one aimed at nobody, so the response never reveals whether a person belongs to another company.
The sign-in pages behave the same way. They show one identical message whatever email is typed, so they cannot be used to find out who works where or which companies use the platform.
Between colleagues
Employees can read their own record and nobody else's. What they see of colleagues comes from a deliberately narrow directory: name, job title, department, location, photo and time at the company, with contact buttons where an email or phone number is on file. Pay, home address and full date of birth are never part of it. The birthdays card shows the day and month only.
On the calendar, colleagues in the same department appear as their name, the word "Away" and the dates. The type of leave and the reason are never sent to anyone else's screen; the database returns name and dates only. On the employee calendar, only you see your own sickness entries.
Inbox tasks belong to the person they were set for. A request to tick off someone else's task is refused.
What employees can change about themselves
From their own account, employees can change a set list of personal fields, such as preferred name, personal email, phone number, home address and notification preferences. A change to anything else, such as salary, job title, department or organisation, is refused by the database. Admins can still edit every field.
When an employee uploads their own life assurance beneficiary form, the platform checks that the form belongs to one of their own memberships before saving it.
Roles, enforced in the database
The admin portal only opens for people whose record gives them an admin or line manager role, and for Alltoogether's own staff. A line manager sees only a Leave page for their own team, and the database function behind it limits them to that team's requests.
Which modules your organisation has is also held in the database. Only Alltoogether can switch a module on or off, and the database refuses the change from anyone else.
Wellbeing data
The employer's wellbeing screens read only from figures already combined across five or more people, and the database will not hold a figure for fewer. They never read individual answers. This is enforced in the database and checked by automated tests. Mood and anxiety questions are kept off the employer's screens entirely. What your employer can see covers this in full.
Questions
No. Every record belongs to one organisation, and the database checks the organisation and role of whoever is asking before returning anything.
No. Colleagues see directory details only. Pay, home address and full date of birth are visible to your organisation's admins, not to other employees.
Security and privacy
How the platform keeps each organisation's data apart, who can see what, and how sign-in and files are protected.
What your employer can see
Exactly what an employer sees of wellbeing answers, employee records, Total Reward statements, birthdays, the calendar and the support chat, and what stays private.