ScavoSecurity

Your team gets the room. You keep the keys.

Scavo is a private workspace, not a public tool. Access is granted per operator, scoped per workspace, and enforced on every request.

Permissions

Exactlywhateachrolecando.

This table mirrors the permission matrix the product enforces today. Roles are checked server side, so a hidden button is never the only thing standing between someone and an action.

PermissionOwnerAdminManagerOperatorViewer
Reply to conversationsAllowedAllowedAllowedAllowedNot allowed
Assign ownersAllowedAllowedAllowedAllowedNot allowed
View analyticsAllowedAllowedAllowedAllowedAllowed
Publish automationsAllowedAllowedAllowedNot allowedNot allowed
Invite membersAllowedAllowedAllowedNot allowedNot allowed
Manage membersAllowedAllowedNot allowedNot allowedNot allowed
Review approvalsAllowedAllowedNot allowedNot allowedNot allowed
Manage integrationsAllowedAllowedNot allowedNot allowedNot allowed
View audit logAllowedAllowedAllowedNot allowedNot allowed
Create workspacesAllowedNot allowedNot allowedNot allowedNot allowed

Roles

Fiveroles,noambiguity.

01

Platform owner

Full reach across every workspace. The only role that can create a new workspace from an approved request.

02

Workspace admin

Everything inside their own workspace: members, integrations, approvals, automations, and the audit log.

03

Manager

Runs the floor. Invites members, publishes automations, replies and assigns, and reads the audit log.

04

Operator

Works conversations. Replies, assigns owners, and sees analytics, with no access to settings or approvals.

05

Viewer

Read-only analytics. Useful for a client or a stakeholder who should see outcomes but never touch a thread.

Guarantees

Whatholdswhennobodyiswatching.

01

Approved registrations

An uninvited signup does not get a workspace. It creates a request that waits for an owner decision, and the account stays pending until then.

02

Session-derived scope

Tenant and role come from the server session on every protected request. A client cannot ask for another workspace's data by changing a parameter.

03

Audit trail

Workspace decisions, member changes, approvals, and lead tag edits are written to an audit log with the actor and the details.

04

Sending is an approval

Automatic DM sending without operator review is a high-risk approval that stays pending until you grant it.

05

Hashed credentials

Passwords are scrypt-hashed with a per-account salt. Sessions are database-backed, HTTP-only, and expire.

06

Attempt throttling

Five failed sign-ins locks the account for fifteen minutes.

Open your revenue room.

Scavo is a private workspace. Request access and the Scavolution team will approve your account and set the playbook up with you.

Request access