Who can see your plan, and who can change it
Written to answer the questions a GC’s IT team asks, without making you request a document first.
Last updated 6 September 2026.
Signing in
Supabase Auth handles sign-in. Last Plan’s API verifies authentication tokens and checks permissions before granting access to protected project data.
Who can do what
Three permission roles, and they are the whole model: Admin runs the board and the project, Planner plans and statuses work — optionally limited to their own trades — and Viewer can only look. These are authorization roles; separately, for billing, Admin and Planner count as planning users and Viewer as a view-only user.
Those permissions are enforced in three independent layers that must agree:
- Postgres row-level security — the database itself refuses to return or change rows you are not entitled to. This holds even if something above it is wrong.
- API guards — the role is checked on every write, and the same refusal is returned in every environment.
- The interface — it hides what you cannot do, so nobody is offered a button that will fail.
The test suite fails if those three ever disagree, including under a simulated twenty-user storm on one board. Hiding a button is not a permission; it is a courtesy on top of one.
Your history cannot be quietly rewritten
- Commitments are append-only — PPC is computed from that history, never from a ticket’s current state.
- Closing a week freezes its numbers; a late catch-up never rewrites a closed week.
- The board versions itself automatically and keeps about 90 days of history — restore an earlier version in place, or open it as a separate copy.
- Deleted tickets go to a recycle bin, so a delete can be undone.
- Every ticket carries its own change history.
- Concurrent edits are versioned — the second editor is told, not silently overwritten.
Where your data lives
| Provider | What is there |
|---|---|
| Supabase (managed PostgreSQL) | Database and authentication: projects, boards, tickets, commitment history, versions, members |
| Render | Hosts the API — the application logic that serves requests; your planning data is stored in Supabase, not on Render. |
| Vercel | The web app — static files only |
| Resend | Email — sign-in links and project invitations |
Traffic is HTTPS end to end. Uploaded schedule files are parsed with hardened XML handling — external entities and entity-expansion attacks are blocked, uploads are size-capped, and spreadsheet formula injection is neutralised in both directions.
Getting your data out
Any board, any plan, any time: export it as an Excel workbook, or print it at wall size. Your planning data is yours and you do not need to ask us for a copy of it.
The boundaries, stated plainly
- No formal certification. There is no SOC 2 or ISO 27001 attestation. If you need one to proceed, say so early and we will tell you honestly where that sits.
- Single region. Your data is hosted in one region, with no multi-region failover.
- Change history is in the app, not a download. You can see who changed what and when, but there is no separate audit-log export.
Reporting something
If you find a security issue, email support@lastplan.io with enough detail to reproduce it. You will get a human reply, and we will tell you what we did about it.