Manager
Overall visibility, management, configuration and approval of significant actions according to assigned permissions.
Overall management · approvalGE2studio is designed to give the right information to the right person, retain a record of useful actions and keep people at the centre of sensitive decisions.
Trust starts with a simple rule: everyone sees what their role requires, and no more.
Overall visibility, management, configuration and approval of significant actions according to assigned permissions.
Overall management · approvalAccess focused on their classes, participants, availability and the information needed for the session, without overall finances, member cohorts or individual departure risks by default.
Their classes · useful informationAccess to their profile, bookings, credits and personal information.
Their own data onlyCapabilities are limited to operational needs. Responsibilities and access levels are defined with the studio.
Important operations are designed to be attributable, timestamped and reviewable.
Proportionate collection, structured data, consistency checks and retention rules to formalise.
A recommendation can inform a decision. It does not execute a sensitive action on its own.
Explain a recommendation. Show its assumptions. Leave the final decision to the responsible person.
This matrix describes the level expected for the pilot. It is neither a certification nor, by itself, a contractual guarantee.
Separation of Manager, Coach and Member roles, access limited to operational need, intended traceability and human confirmation of sensitive actions structure the product.
Two-factor authentication for sensitive profiles, session revocation, default-deny access, strict studio separation, encryption in transit, input validation, audit logging, recovery and incident procedures must be tested.
Hosting provider, location, subprocessors, backups, retention, support, incident notification and responsibilities are specified in the documents applicable to the deployment.
The applicable framework is checked according to the studio's country: GDPR, the revised Swiss Federal Act on Data Protection or relevant local regulations. Minimisation and aggregation remain required.
Separated secrets, validated inputs, abuse prevention and signed automated calls with replay protection must be technically verified.
Instructions given to AI and scenarios use the minimum necessary data. No training on a studio's data without explicit agreement and provider documentation.
Hosting, backup, retention, subprocessors and incident-management arrangements will be specified in the contractual documentation applicable to the deployment.
No security certification is claimed on this page.
Review the documented responsibilities, controls and limitations before deployment.
Discuss security