Data ownership

Data location follows the workflow, with ownership stated explicitly.

Understand which Workspace records use the application database, which approved CRM workflow uses company Google Drive, and what each storage model means.

Structured application records

Company membership, permissions, workflow status, tasks, leave, overtime, expenses, announcements, salary configuration, quotation indexes, inventory records, and similar application data need structured relationships and company scope.

These records use the application database so server actions, permissions, validation, and tenant policies can operate consistently.

Company-owned Google Sheet for CRM leads

The approved CRM model requires the company or user to connect Google before creating or importing leads. Manual and imported lead rows are written to a private Google Sheet in that connected account's Drive.

Workspace provides the pipeline workflow around the sheet. The connected account retains direct control of the underlying Drive file and its Google sharing settings.

Ownership does not remove security responsibilities

A company-owned file still requires controlled OAuth access, correct sharing permissions, backup decisions, and a plan for revoked access or account changes.

  • Workspace must verify company authorization before reading or writing connected data.
  • The Google account owner controls Drive sharing and can revoke the integration.
  • Private operational data is not added to the public sitemap, structured data, or llms discovery file.
  • Data export, retention, and deletion expectations should be reviewed against the applicable company policy and privacy terms.