Authenticated Program users
Normal internal users sign in through approved authentication and must be authorized for the target Turnover Program before they can work inside it.
Turnover is designed around authenticated Program access, customer-controlled administration, scoped permissions, bounded intelligent retrieval, controlled exports, and deliberate external-participant workflows. We describe the controls we actually use and do not claim certifications that have not been established.
Customer-owned operational, technical, form, file, and work information.
Authorized evidence only. No silent AI commit or export authority.
Assigned workflow or tokenized form path, not normal Program access.
Turnover separates account authentication, Program authorization, Local Admin responsibility, and feature-specific permissions so one access decision does not have to open every part of the system.
Normal internal users sign in through approved authentication and must be authorized for the target Turnover Program before they can work inside it.
Customer-designated Local Admins manage supported Program access, roles, Work Groups, page visibility, and other configuration controls for their organization.
Reviewer authority, Work Group and Persona scope, page access, export permissions, and other specialized controls remain separate from basic Program entry.
Leroy is Turnover's Program Aide. TurnBase is a structured, permission-aware and freshness-aware knowledge repository. Their current design keeps retrieval tied to authorized scope and source identity.
Use the smallest relevant evidence set the user is permitted to access.
Keep record, package, revision, scope, and freshness identity available where the source supports it.
An AI response does not silently create, verify, delete, export, approve, or overwrite authoritative Program data.
Turnover supports more than one limited outside-workflow pattern. The important rule is that an external participant receives the path needed for the assigned work, not normal access to unrelated Program data.
Where a company template allows external participation, Turnover can issue a high-entropy tokenized form link with expiration, revocation, replay protection, rate limits, server-side validation, and private submission storage.
The external participant completes the assigned form. The returned submission is synchronized back into the controlled form for internal review and any configured approval chain.
Where configured, approved contractors or specialists may use a limited contributor workspace for assigned submissions without receiving normal access to protected internal modules.
Some Turnover workflows can deliberately package a schema or authorized data set for use with an external AI. Those workflows are designed around explicit export, human review, and controlled import instead of giving an external model unrestricted live Program authority.
Authenticated users, permissions, authoritative records, and customer configuration remain inside Turnover.
Only the selected schema or authorized package is prepared for the outside task.
Proposed content comes back through a human-controlled workflow before it becomes live Program data.
Depending on Program configuration and feature use, Turnover uses SQL services, Firebase and Firestore services, Firebase Storage, Realtime Database, Turnover Login, and Turnover-controlled PHP service endpoints. Exact data paths vary by feature and deployment.
SQL and Firebase-family services serve different operational, configuration, working-state, and durable-history responsibilities inside the product.
Configured file, image, profile-photo, and private external-form workflows use controlled storage paths appropriate to the feature. Exact storage requirements can be reviewed for a deployment.
Turnover is served over HTTPS. Customers should also secure endpoints, browsers, credentials, and local networks used to access the service.
Customer retains ownership of Customer Data. Turnover processes it to provide, secure, support, and improve the service for that Customer and does not expose identifiable Customer operational content to other customers by default.
Operational records, technical content, files, forms, and other Customer-submitted content do not become Turnover intellectual property merely because Turnover stores or processes them.
Turnover Shared Knowledge may be offered as a paid add-on. Cross-customer contribution is off by default and requires separate affirmative administrator opt-in.
Hosting, authentication, database, storage, communications, payment, security, and configured model-processing providers may process information only as needed for their permitted service role.
Unless a different written agreement applies, the standard self-service policy provides a 30-day post-termination period to retrieve available Customer Data. After that window, active-system deletion may proceed, while protected backup remnants may age out for up to 90 days or remain longer where law, security, dispute preservation, or a written agreement requires it.
Authorized users work with Customer Data under the configured Program permissions.
Available Customer Data can be retrieved or requested after termination unless a different agreement applies.
Active-system deletion follows the retrieval window. Protected backup remnants may persist temporarily under the published policy.
Turnover can help document safety concerns, controlled forms, approvals, work history, and related information. It is not an emergency dispatch system, machine-control system, protective device, or safety instrumented system.
Do not use a Turnover notification, form, or AI response as a substitute for required life-safety, machine-safety, emergency, or protective systems.
Customers remain responsible for their procedures, permits, regulatory duties, training, approvals, and safe operation of facilities and equipment.
AI-assisted explanations, form drafts, and proposed structured data should be reviewed by qualified people before they are relied on for safety, engineering, quality, or compliance decisions.
Customers should protect credentials, use unique accounts, remove access when roles change, review administrator assignments, secure endpoints, and decide what information is appropriate for their configured Program.
Ask for the real architecture, permissions, AI boundary, retention, and data-flow answers for the Program you are considering. Security concerns can also be reported to contactus@turnoverllc.com.