Platform · Compliance & evidence
Be able to explain the week, months later.
Configurable operational rules, exceptions built for human review, corrections that supersede instead of erase, and an audit trail the application cannot rewrite.
The operational problem
Compliance work is usually archaeology.
The request arrives long after the fact: show that this shift happened, that this visit occurred, that these hours were reviewed and by whom. The evidence is scattered across a schedule, a timekeeping export, a messaging thread and somebody’s recollection. Assembling it takes days, and the result is a reconstruction — which is exactly the thing an auditor is entitled to be sceptical about.
Software often makes this worse by being too confident. Records get overwritten with corrected values, so the history of what was originally recorded disappears. Once that happens, the organization cannot demonstrate its own diligence even when it behaved perfectly.
How Phibian handles it
Keep the original. Explain the change. Prove the review.
Evidence is only worth having if it is intact. Phibian is built so that the record of what was first observed survives every correction, approval and reopening that follows.
Corrections supersede, never overwrite
An adjustment request creates a new record that supersedes the original. Both remain. The reason is required, and the approval is attributable.
Insert-only audit events
The application has no path to update or delete an audit event, and sensitive actions — such as revealing a client’s full name — write one as a matter of course.
Rules you configure, alerts you can trust
Workflow rules evaluate the live operational record and raise alerts through a defined lifecycle. One rule failing never stops unrelated rules from running.
Approvals that lock something real
Approving a timesheet period captures an immutable snapshot. If an underlying value changes afterwards, the week reopens for a fresh look rather than silently diverging.
Privacy defaults that survive contact with reality
Client identities appear as initials by default. Opening a full name is a distinct permission and is recorded, which keeps least-privilege practical instead of aspirational.
Degradation is labelled, not hidden
When a connected system is failing or returning implausible data, the state says so. Data from a degraded integration is never displayed as though it were healthy.
In the product
One model, two surfaces.
What the worker records is what the supervisor reviews. There is no second entry, and no reconciliation step between the two.
In Admin
Needs attention is the compliance surface in daily use: exceptions ranked by severity, each opening into the evidence that produced it.
- Alerts with an explicit lifecycle rather than a silent inbox
- Exceptions that carry their own uncertainty and context
- Correction requests reviewed side by side with originals
- Approval that locks a snapshot and reopens automatically when it must
For the Worker
Compliance is not something done to the worker off-screen. They can see what has been recorded about them, and they have a route to challenge it.
- A visible record of their own time and check-ins
- Ask for a correction, with the original preserved
- Attest when the phone cannot confirm a location
- Plain language about what is collected, and when
How it connects
Nothing here is a standalone product.
The value is not the capability on its own — it is what happens when this record is continuous with the rest of the operation.
Field activity supplies the evidence
Verification states, coverage and attestations arrive already attached to the events they describe.
Workforce supplies the accountability
Who approved, under which role and scope, is part of the same permission model everything else uses.
Attention turns evidence into action
Rules raise what deserves review today, so compliance becomes an ongoing operational habit rather than an annual scramble.
Security makes it defensible
Tenant isolation, default-deny permissions and the audit spine are what make the evidence credible to someone who did not watch it being collected.
Keep exploring
Security & trust
The controls underneath: isolation, access control, auditability and credential handling.
Explore Security & trustField & movement
Where the evidence comes from, and why its uncertainty is recorded with it.
Explore Field & movementHuman services
What defensible evidence looks like for community-based and regulated service organizations.
Explore Human services