Skip to content

Give staff access, not the keys

Written for a salon owner rather than a security team: what keeps your records separate, who can see what, and the things Salvoro does not do.

30 days free · No card required

The short answer

How is one salon's data kept separate from another's?

Salvoro runs many salons on one system, so every record carries a stamp saying which business it belongs to. That stamp is applied automatically in one place, on every read and write, rather than typed into each screen where somebody could forget it. A request that does not say whose data it wants fails instead of guessing. Branch rules narrow it further.

Your records are not mixed with anyone else's

Every record in Salvoro — customers, bills, staff, stock — carries a stamp saying which business it belongs to. What matters is where that stamp gets applied: in one place that every request has to pass through, rather than in each screen, where one missed line would be enough. So the worst a mistake can do is show you your own records. A request that does not say whose data it wants does not fall back to showing everything; it fails and returns nothing.

  • Every record is stamped with the business it belongs to
  • The stamp is applied once, centrally, on every read and every write
  • A request that does not name a business fails rather than guessing

Who can see which branch

An owner sees every branch and switches between them. A branch manager sees only the branches you gave them. Everybody else sees only their own. The part worth understanding is where that decision is made: which branch you get is read from your account, not from the web address or anything the browser sends. Someone who edits a link to name a branch they were never given is answered with their own anyway, because the request is checked against the account rather than believed.

  • Owner sees every branch; a manager sees the ones you gave them; staff see their own
  • Your branch is read from your account, not from the link
  • A branch manager cannot rename a branch or open the company settings pages

How multi-branch access is set up

What each person can open

There are 65 separate permissions, and you tick them one person at a time. There are no shared roles, so nobody quietly inherits access because of a job title — a designation such as “Senior Stylist” is a label on the profile and grants nothing by itself. A new joiner starts with nothing ticked, which is the way round that matters: access is something you hand out on purpose, not something you have to remember to take away.

  • 65 permissions, ticked per person — no shared roles to inherit from
  • A new staff member starts with nothing ticked
  • A job title is a label, not an access level
  • An optional PIN can lock the dashboard and the reports pages

How staff permissions work day to day

Signing in, and what protects it

Signing in takes one step, not two. You use either your password or a six-digit code sent to the email address on your account — and the code is an alternative to the password rather than an extra check on top of it, so a correct code on its own signs you in. Your password is stored scrambled in a way that cannot be reversed, so nobody at Salvoro can read it or tell it to you. Sessions renew using a single-use key; if an old key is ever presented again, that is treated as a stolen session and everything from that sign-in is cancelled at once.

  • One step: your password, or an emailed code — either one alone signs you in
  • Codes go to email only, last fifteen minutes and allow five tries
  • Passwords are stored scrambled (bcrypt) and are never recoverable
  • A reused session key cancels every session from that sign-in
  • Repeated attempts are slowed down per account and per internet connection

A record of who changed what

When a bill, appointment, customer, staff member, stock item, membership, commission or tip is changed, Salvoro writes a line saying who did it, at which branch, when, and — for an edit — what it looked like before and after. Nothing inside the product can alter or delete those lines. Two caveats belong here rather than in small print: it covers the things that move money and records rather than literally every action, and if writing a line ever fails, the sale still goes through and the failure is logged instead. It is a dependable record, not a sealed one.

  • Who did it, at which branch, when, and the before and after of an edit
  • Nothing in the product can change or remove a line
  • Covers changes to money and records, not literally every action

What Salvoro does not do

Every item here is a real gap stated at full strength, because the ones that matter to you are the ones a sales page would round off. Customer names, phone numbers and visit history sit in the database as ordinary text: your password is scrambled and the connection is encrypted, but those records themselves are not. Salvoro holds no security certificate of any kind. And nothing is backed up automatically — a copy is taken by hand before the database structure changes, but there is no schedule and no way for you to restore one yourself. How your data is handled as a matter of policy is the privacy policy's job rather than this page's.

  • Customer records are not individually encrypted where they are stored
  • No ISO 27001, SOC 2 or PCI certificate, and none in progress
  • No second sign-in step, no authenticator app, no single sign-on
  • No automatic backup and no self-service restore
  • No published service level agreement

Common questions

The connection is encrypted and passwords are scrambled in a way that cannot be reversed. The customer records themselves are not: names, numbers and visit history sit in the database as ordinary text. Saying otherwise would be a false security claim, and it is better known before a trial than after.
No. Signing in takes one step: your password, or a six-digit code emailed to the address on your account. The code is an alternative to the password rather than a second check after it, so a correct code on its own signs you in. There is no authenticator app, hardware key or single sign-on.
No, and none is in progress. There is no ISO 27001, SOC 2 or PCI DSS certificate. If your buying process requires one, that rules Salvoro out — which is better to know now than after a trial has been set up, data imported and staff trained on something that cannot be signed off.
Not on a schedule. A copy is taken by hand before the database structure changes, so a recent one usually exists, but nothing runs automatically and you cannot restore one yourself — recovery is a manual request. The record of changes at least tells you who deleted what before anything is restored.
Yes, across bills, appointments, customers, staff, stock, memberships, commission and tips. Each line names the person, the branch, the time and, for an edit, the before and after. Nothing in the product can alter or delete those lines, though they cover money and record changes rather than every action.

See it with your own salon’s data

30 days free, no card required, and a guided setup that takes four steps.