Security and access control in GeoSewerTrack

Multi-step authentication, project approvals and granular permissions ensure that users can only access the areas and functions required for their tasks.

Security in GeoSewerTrack does not end at the login screen.

A customer instance can be used by several employees without every user automatically being allowed to access all projects, drawings and functions.

GeoSewerTrack therefore combines several levels of authentication and permission control.

Encrypted connection

Access to GeoSewerTrack takes place over an encrypted HTTPS connection.

This protects the data transmitted between the browser and the server while it is in transit.

When username and password are used for authentication, the password is also not stored in plain text in GeoSewerTrack.

Two-step login when using username and password

If a customer instance uses the traditional username-and-password login, an additional verification step is applied.

Knowing the password alone is therefore not sufficient to complete the login process.

Authentication takes place in multiple steps and provides additional protection for user accounts.

A user does not automatically see every project

A successful login to GeoSewerTrack does not automatically provide access to every project within the company.

Each employee must first be explicitly approved for a project.

Only after this assignment can the relevant project become visible and accessible to the user.

This allows different teams, locations or areas of responsibility to be separated within the same GST instance.

An employee therefore receives access only to the projects that are actually intended for them.

Permissions down to function level

Even after a user has been approved for a project, their permissions can be restricted further.

GeoSewerTrack supports differentiated permission control for different functional areas.

The following areas are particularly relevant:

1. List drawings

Controls permissions within drawing and project overviews.

2. Drawing details

Controls access to the detailed view of a drawing and the functions available there.

3. Create marking

Controls permissions for creating new markings within drawings.

4. Change markings

Controls permissions for editing existing markings.

Within these functional areas, permissions can be assigned individually, for example for:

  • reading,
  • adding,
  • editing, and
  • deleting.

This means that an employee does not have to be granted full access to an area as a package.

A user can, for example, be allowed to view information without being able to modify or delete it. Employees can also be granted permission to add new content while more extensive changes remain restricted.

Permissions matched to the task

The permission system therefore takes into account not only who a user is, but also what that user is actually allowed to do within GST.

Different responsibilities within a company can therefore be represented.

An employee working in the field may require different permissions from a member of the work preparation team or project management.

GeoSewerTrack makes it possible to reflect these differences within the same customer instance.

Staff – between user and administrator

In addition to regular users and administrators, Staff provides an additional user role.

Staff employees can receive extended administration or editing permissions without automatically receiving every administrator privilege.

The required permissions can be assigned individually and specifically to each Staff user.

A responsible employee can therefore take on additional tasks within GeoSewerTrack while particularly far-reaching administrative functions remain restricted.

The principle is simple:

Only as many permissions as are required for the respective task.

Separate customer instances

Each GeoSewerTrack customer instance is operated as a separate environment.

Customer data is not separated merely by different user accounts within one shared application. Separate databases are used for the individual customer instances.

This provides each customer environment with an additional technical separation from other GST instances.

Multiple security layers instead of a single access barrier

GeoSewerTrack’s security concept consists of several consecutive layers:

1. Protected and encrypted connection

Communication between users and GeoSewerTrack is protected using HTTPS.

2. Personal user account

Employees work with their own login credentials rather than shared standard accounts.

3. Additional verification

When the classic password login is used, the login process is protected by an additional verification step.

4. Approval for the respective project

A signed-in user can see a project only after access has been explicitly granted.

5. Individual function permissions

Within an approved area, it can also be defined which actions the user is actually allowed to perform.

6. Extended permissions only where required

Staff users can be given additional permissions selectively without automatically granting them full administrative control.

Control remains with the company

Which employees can access which projects and which actions they may perform can be defined according to the company’s division of responsibilities.

GeoSewerTrack can therefore be used both with a small number of users and with different levels of responsibility and access within a larger organisation.

Not every user has to see everything.

Not everyone who may see something has to be able to change it.

And not everyone who may change something has to be able to delete it.

GeoSewerTrack therefore relies on differentiated access permissions rather than a simple choice between “access granted” and “access denied”.