Customer service and Company Workspace policies

Company Workspace policy 2026-09-13.1; Managed Support policy 2026-09-13.1. These policies apply to new orders that reference the applicable version. Existing signed agreements and applicable law take precedence.

Operational guidance revision: September 13, 2026, revision 12. Changes: company-scoped provider services, Gmail intake, Google security mail, owner CRM and financial records, company time zones, paginated history, centered editors, billing recipients and capacity execution evidence. Prior MFA, vault, pricing and narration guidance remains in effect. This guidance does not rewrite an accepted order. Read the previous published policy.

Products, licensing and payment

Managed IT Support and Company Workspace are separate products. Managed IT Support is delivered by TLS staff under an agreed service scope. Company Workspace is customer-administered software; customer administrators manage their own users and permitted settings while TLS retains platform and infrastructure administration.

Both product lines offer Standard, Professional and Enterprise plans per named user, with a minimum of ten Company Workspace users or five Managed IT users. Company Workspace list prices are $19, $39 and $69 per user/month. Managed IT Support list prices are $79, $129 and $199 per supported user/month. Monthly subscriptions bill in advance. One-, two- and three-year prepaid terms receive 8%, 12% and 15% discounts respectively. A longer commitment requires an accepted order; changing a plan does not silently replace an existing agreement. Taxes, vendor subscriptions, projects and out-of-scope services are additional as disclosed.

Additional seats are activated after confirmed payment. Self-service increases show an invoice estimate and require payment authorization; a failed or incomplete payment does not grant extra licenses. Current paid users and history are not deleted by a payment failure. Paid invoices and receipts are available through the company billing page and Stripe’s hosted billing portal when connected.

Renewal and nonrenewal

Renewal terms and charges are shown in the accepted order and checkout. For fixed terms, submit a nonrenewal notice at least 30 calendar days before the end date, unless the signed agreement or applicable law requires another rule. Renewal reminders are scheduled for 90, 30, 14 and 7 days before expiry. If a schedule begins late, the next applicable reminder is used instead of sending a backlog.

A notice is recorded in the company account. Requesting nonrenewal is not confirmation that a Stripe subscription has been cancelled; obtain cancellation confirmation through the hosted billing portal or TLS. Monthly plans may be cancelled for the next billing period under their accepted order. No company data is erased by submitting a notice. Export, retention and any eventual deletion follow the signed agreement and a separate authorized process.

Development and QA

Dev starts clean. Professional includes up to five test users; Enterprise includes up to ten. Standard has no included Dev. Test accounts use isolated data and provider credentials. QA is a paid replica of the approved production configuration at a recorded checkpoint, including its version, settings and permitted test fixtures. Credentials, passwords, MFA secrets, active sessions, payment data and unapproved personal information are not copied.

Choose clean Dev or a sanitized QA replica during provisioning. Configuration transfer operations expire after two hours and permit at most three attempts. This is an execution limit, not a promise that a complete environment will be built within two hours. Larger requests require a capacity review; the portal reports the recorded state. A request is not available until isolation, identity, routing and validation finish. Start changes in Dev, promote the same tested artifact to QA, and then promote that artifact to production. Production health checks remain necessary because its domains, secrets and live services differ.

Shared TLS Dev and QA use Production as the identity authority; independent customer federation requires separate implementation and acceptance. Production validates the account, role, environment grant and LastStop Verify state, then issues an encrypted, request-bound grant that can be redeemed once within 60 seconds. The environment synchronizes the approved profile and creates a separate session for no more than eight hours. Passwords, Verify private keys and Production cookies are never copied. Sign in again after central role or environment-access changes.

Configuration transfer and recovery

TLS must first allocate a separate company deployment with its own database, storage, keys and hosting audience. The current worker transfers supported portal settings, disabled connector definitions and anonymous user, group and delegation fixtures. These fixtures are a test model and do not activate real accounts or permissions. Hosting allocation, complete production cloning and independent customer sign-in are not automated by this worker.

The administrator confirms replacement of the supported settings on the selected test target. Each encrypted operation is scoped to that company and environment, retains an integrity reference and is verified against the target receipt. One active job is permitted per environment. Retry reuses the same operation; changed targets or expired jobs require review before a new capture. An encrypted before-image permits rollback of the current import’s configuration without deleting or replacing authentication, MFA, recovery or vault records.

Snapshots exclude structured personal identities, customer content, provider credentials, live access grants and payment data. Administrators must review free-text settings for sensitive content. Encrypted operations and before-images remain retained for recovery until authorized infrastructure cleanup under the applicable agreement; automatic artifact deletion is not implemented. A validated transfer is separate from DNS, identity, capacity and full workflow acceptance.

Production hosting invocation summaries record maintenance start, finish and task outcomes for a 14-day observation window. A manual action or completed handler does not establish customer message delivery. Independent monitoring and delivered-notice evidence remain required.

Access and security

All company accounts, including company owners, administrators, billing users and regular clients, must complete authenticator MFA before protected access. TLS staff retain their separate LastStop Verify requirements. Company authenticator secrets are encrypted; recovery codes are single-use and stored as hashes. Lost-factor recovery requires identity review by a verified TLS owner and revokes the affected user’s sessions. Domain ownership does not grant TLS owner access. Company data, secrets, license records and permissions stay scoped to the company. A custom-domain change requires ownership verification, a valid certificate and approved routing; it does not change the company identity or its access rights.

Company owners and administrators govern only their company. Role hierarchy, manual groups and time-limited delegated permissions cannot create TLS staff or platform-owner access. Dynamic identity-provider groups require a successful direct-membership read, explicit immutable identity links to existing company users and an administrator’s review before enabling inherited permissions.

Security is maintained through layered controls, testing, monitoring and incident response. No service can guarantee freedom from every breach or interruption. Healthcare or other regulated use requires a separate assessment and applicable signed agreements, including a business associate agreement where required. A renewal-notice policy alone does not establish HIPAA compliance.

Identity-group access and revocation

Microsoft Entra, Google Workspace, Okta and OneLogin direct-membership adapters may grant a permitted company role to an explicitly linked active company user. Matching email addresses, possession of a domain or a saved group ID do not grant access. Nested groups, external or guest identities and inactive or unavailable directory accounts are excluded. Company owner, company administrator and TLS platform roles are never inherited from these groups. Provider memberships, sign-in identities and base company roles are not modified.

An administrator reviews immutable identity links and explicitly enables synchronization. Each complete successful snapshot authorizes inherited access for at most one hour. Scheduled work checks eligible groups when the hosting scheduler invokes it; actual scheduled operation requires separate verification. Manual synchronization is available. Failed provider reads or database writes preserve the previous complete snapshot without extending its expiration. Expired grants cannot authorize requests even if no scheduler runs.

Pausing inherited access, pausing the group or pausing its directory credential source revokes the inherited grants. Identity-link changes pause access until reviewed again. Credential revision, source recreation and provider-tenant changes require review before current grants can resume. A late result cannot overwrite a pause or changed configuration. A successful removal sync revokes the removed member’s inherited role on the next request while preserving independent base-role access.

Company administrators retain the authorization, identity review, successful add/remove test and scheduled-operation evidence in their approved records system. Activity records identify configuration and synchronization results without storing provider secrets. Oversized or inconsistent snapshots fail rather than creating partial membership grants.

Read-only vendor licenses and application access

Authorized company roles may configure Microsoft 365, Google Workspace, Okta, OneLogin, Salesforce, Adobe, Atlassian, Slack and Zoom inventory adapters. Each company supplies its own approved credentials and must complete a successful provider sync. An available adapter is not evidence that a company account is connected. Credentials are encrypted and company-scoped; provider requests remain isolated in Dev and QA.

OAuth token exchanges may use POST. Subsequent inventory operations use provider GET endpoints and expose no purchase, assignment, cancellation or user-modification action. Some provider scopes, including certain API tokens, Slack admin and Adobe User Management, can authorize writes outside Connect. Use dedicated applications, minimum available privileges, credential rotation and controlled operator access.

Inventory scope is specific to each provider. Purchased capacity and provider utilization are distinct from application access, product-profile membership, account type or a periodically computed billable indicator. Unknown capacity stays unknown. Profiles can overlap, inactive users can retain profile references, and managed-account APIs can omit unmanaged users. The portal describes these limits and does not claim a complete effective-permissions graph or unreturned add-on licensing.

Synchronization commits a complete bounded snapshot. Failed pagination, inconsistent identity results, provider errors or a failed database transaction preserve the previous snapshot. Administrators must review its timestamp and any failure; cached results are not live proof of current entitlements.

Pause and Trash stop local synchronization. Restoration leaves the source paused; an authorized administrator chooses Resume, then explicitly runs Sync. Resume alone sends no provider request. Permanent deletion erases the selected company’s local encrypted connection and cached inventory, not its vendor subscriptions. Activity and historical service records follow their separate retention policy.

Knowledge and co-branding

Technology Last Stop global knowledge is maintained only by TLS platform owners. Company users may read published global guidance but cannot modify, archive, restore or replace it. Authorized company Knowledge managers and administrators may create and maintain only their own company-private articles; private content never becomes global merely by exporting or importing it.

Professional and Enterprise workspaces may add an authorized square company logo. Tenant branding is additive: the official TLS mark, Technology Last Stop platform identity, owner authority and backend controls remain visible and cannot be replaced from company settings. Uploaded logos are type, signature, dimension, size and company-scope checked. Standard workspaces continue with the TLS platform presentation.

Maintenance and incidents

Planned customer-impacting changes are normally announced at least 60 days ahead, with further reminders at 30 days, 7 days, 1 day and 1 hour. The change plan records the customer’s time zone, an overnight maintenance window, an estimated duration range, tested artifact, backup reference and rollback procedure. Urgent security fixes and unplanned outages may require faster action.

Incident trackers show operational, degraded or outage states with written updates. During an active incident, TLS acknowledges the problem and provides progress without promising an unverified restoration time. Support messages should include the incident reference, the affected service and safe next steps.

Custom addresses and separate browser tabs

The TLS environment addresses are dev.connect.techlaststop.com and qa.connect.techlaststop.com. A Company Workspace uses connect.companydomain.com, dev.connect.companydomain.com and qa.connect.companydomain.com after separate provisioning and verification. An address awaiting DNS or a certificate is not a ready environment; available links continue using the working address until activation.

Dev, QA and Company Workspace links open separate tabs. Each tab checks its own authorized session; opening or copying a URL never grants additional permission. Environment sign-in may return only to that environment’s registered HTTPS addresses. A new hostname does not change the company ID, ownership, roles or data scope.

Integration change review and healthcare use

Provider authorization, application credentials, verification and live acceptance are separate steps. Changes to payment credentials or their catalog require verification again. Displayed DNS instructions do not establish that a hostname is active; hosting must verify both routing and HTTPS before its address is activated.

Before enabling a new or materially changed integration, the responsible TLS or company administrator must review its purpose, read/write permissions, data categories, processing locations, vendor agreements, retention, incident contacts and removal procedure. Update the relevant setup article, access instructions and operational policy when that review changes how the service is used. A catalog entry or successful authorization check does not establish working synchronization.

Do not send electronic protected health information to an integration until the organization has assessed the applicable safeguards, authorized the use and completed required vendor and business associate agreements. Policies, branding and authentication alone do not establish HIPAA compliance.

Where the HIPAA Security Rule applies, required documentation must be retained for six years from creation or the date it was last in effect, whichever is later, made available to those implementing it and updated for operational or environmental changes. Keep dated approvals, earlier versions and applicable agreements in the organization’s approved records system; downloading this page does not itself configure that retention. See 45 CFR 164.316.

Company password vaults

Paid Company Workspaces provide a separate shared credential vault. Password view and manage permissions are enforced per company. Secret values are encrypted on the server, revealed on demand and excluded from audit detail. Authorized TLS platform administration remains possible; this is not a zero-knowledge service. Reveals and lifecycle changes are audited. Concurrent edits require the current revision. Trash is reversible and prevents reveal; eligible recycled records are purged after 60 days by lifecycle execution, subject to retention holds. Retention and authorized exit processing follow the signed agreement.

Narrated knowledge tutorials

Text setup instructions remain the maintained source for each tutorial. Narrated videos must identify their article revision, disclose AI-generated narration, include captions and a readable transcript, and be reviewed against the actual product before publication. Nora is the selected narrator name. TLS approved the Crisp standard female voice on September 13, 2026. Retain the exact provider voice identity and approved sample; rejected or unavailable voices are not substitutes. Voice approval is separate from reviewing each completed tutorial. A sample or a paid provider entitlement does not establish that a tutorial is complete. Prepared scripts are not evidence that a video has been produced. The narrator is a TLS guide persona and does not replace the company owner or a human support contact.

Record with synthetic demonstration accounts. Exclude customer information, passwords, API keys, recovery codes, payment details and protected health information. Keep company-private videos within the same company access boundary as their articles. A relevant interface, procedure or script change requires a tutorial review; outdated media must be updated or withdrawn. Media whose article or transcript no longer matches is withheld from the setup player. Playback remains viewer-controlled, with captions, chapter navigation and written instructions available alongside published video.

Account recycling and retained records

Deleted client users and internal staff have a 60-day recovery window. TLS platform owners can also recycle a company after verifying subscription cancellation and completing hosted-environment offboarding. Company deletion revokes portal access. Restore a company before its deadline into onboarding, then review access and services before activation. An authorized administrator may permanently delete a recycled record earlier after explicit confirmation.

Eligible expired records are processed automatically in bounded background batches. The hosting maintenance handler and a traffic-triggered fallback share a durable concurrency lease. Traffic checks run at most every 15 minutes; an idle application requires its hosting scheduler. TLS can inspect the latest result and run a due check in Account recovery and retained records. Failures preserve retry information. This is a cleanup process, not a guarantee of deletion at an exact second.

Company retention holds pause company purge. Required agreements, accounting records and historical service and audit records follow their separate approved retention schedules and legal holds. Retained company documents remain available only to TLS platform owners after the operational profile is removed. A 60-day recycle period does not shorten required regulatory documentation retention.

Permanent identity deletion removes local authentication factors, recovery material and identity links. Company purge removes its operational configuration, private knowledge revisions, shared vault and local connector credentials. Previously retained backups and records must be handled under the applicable agreement. Deleting a local record does not cancel a vendor subscription, remove an external identity or decommission a remote agent or hosting account; complete and verify those actions separately.

Company tools and helpdesk

New workspaces start with fresh company records. They share supported software capabilities and display controls without copying TLS private tickets, credentials, customer records or internal knowledge. Plan entitlements, company roles and actual provider readiness determine available actions. TLS owns and administers the backend; company roles cannot grant platform ownership.

A Company Workspace helpdesk is separate from TLS Managed IT support. Company support managers assign tickets to eligible company staff, record public replies or private internal notes and enter a resolution when closing work. Requesters can see their own tickets and public replies. Ticket changes require the current revision; recycled company tickets have a 60-day recovery window. Company helpdesk replies are stored in the workspace; external email delivery is not claimed by saving a reply.

View options opens within its page toolbar and closes when clicking outside or pressing Escape. Smaller screens wrap controls and allow normal page scrolling so content remains reachable. Search controls use one visible outline. Collection preferences remain independent in each browser tab, and opened sections still check permissions on every request.

Company identity and bulk administration

Microsoft Entra ID, Google Workspace, Okta, OneLogin and configured SAML sign-in require a provider connection and a specific approved immutable user link. The provider issuer and immutable subject identify the account. SAML requires a pinned signing certificate, signed response and assertion, request binding, the registered audience and a persistent NameID. TLS staff SSO uses a separately scoped platform provider. Email addresses and domain claims do not grant access by themselves. Personal Gmail addresses may be individually invited when the company explicitly permits them; public email domains never establish company ownership.

Changing a provider configuration invalidates its federated sessions. Revoking a user link revokes existing local sessions. Directory discovery does not automatically grant administrator access. CSV batches apply ordinary role, company, paid-seat and recovery rules to every row. Silent setup saves pending accounts without email; it does not bypass activation. Requested activation email and verified delivery remain distinct states. Bulk processing can be paused between batches and requires the browser tab to stay open.

LastStop Verify is mandatory for approved client accounts through the company authenticator flow. A stolen password alone is insufficient. TLS staff keep their existing registered approval devices. Authenticator codes reduce account-takeover risk but are not a phishing-resistant security guarantee.

Storage, capacity and infrastructure control

TLS administers the backend. Current company records use company-ID access boundaries in the deployed application database; object attachments use protected cloud storage. A fresh workspace receives no TLS private data. A separate physical database per company is a future provisioning capability, not the current storage arrangement.

The owner capacity console records database size observations, completed object-storage scans and per-company file metadata separately. A database reading counts physical database bytes; the file metadata meter does not. Dedicated component records can receive a scoped collector reading. Provider allocation must be entered with evidence before percentage capacity is meaningful. Default warning and critical thresholds are 75% and 90%; TLS can change them. Stale or missing readings remain unknown and cannot clear a capacity incident. Company users cannot access these infrastructure controls or their cost settings.

Background maintenance evaluates alerts, acknowledges escalation and records recovery. In-portal notifications and email queue entries are restricted to active TLS platform owners. Email acceptance by a provider is separate from confirmed inbox delivery. Uncertain delivery outcomes require review before retrying. An in-application scheduler is not an independent monitor of its own hosting outage. Raw usage observations are retained for 90 days; alert, change and delivery history follow their approved operational retention schedule.

Cost and margin indicators use the rates and budgets recorded by TLS; they exclude unentered operations, egress, backups, taxes and vendor fees. Budget changes do not purchase capacity. Expansion plans require a provider reference and verification evidence. A completed administrative record is not a claim that the application bought or migrated infrastructure. Recycled external component inventory has a 60-day recovery period, subject to retention holds; its removal does not delete a real database or bucket.

Before increasing paid storage allowances, TLS must verify capacity and cost, approve any provider purchase, test backup and restore, and record the resulting service terms. No unlimited physical storage, security, uptime or future mobile capability is implied by a plan name.

TLS environment access

TLS Development and QA use the production identity authority and mandatory verification. Test data is protected by the application’s TLS owner access check. Each environment holds a separate session; production passwords and customer data are not copied. Active environment sessions are periodically checked for continued authority access and fail closed when verification cannot be completed. Hosted access settings must be changed only after this application gate is deployed and accepted.

Selected services and new agreements

Customers can compare individual services at /configure and save a company-scoped configuration in Plans & billing. The secure foundation remains required. Dependencies, tier availability, a five-user Managed IT minimum and a ten-user Workspace minimum are enforced when quoting. Selecting the complete service set matches the published tier price. Removing a service changes the new quote; it does not alter an existing signed agreement.

Monthly requests can become quotes immediately; 12-, 24- and 36-month requests require TLS review. An authorized signer accepts the exact service selection and policy version before payment. An accepted quote alone grants no paid access. Stripe verification or an explicit TLS owner record of the cleared amount activates the selected services. Existing Stripe subscriptions require a reviewed change, so a second subscription or an unapproved seat charge cannot be created silently. Online payment remains unavailable until protected provider configuration and live acceptance are complete.

Draft and cancelled requests can be recycled and restored. Never-accepted, unbilled drafts become eligible for purge after 60 days; signed orders, payment references and active or superseded agreements are retained separately. Extra storage and vendor consumption require a disclosed accepted order. Internal utilization alarms never trigger an undisclosed customer charge.

SCIM provisioning and recovery

Authorized administrators can issue a company-scoped SCIM bearer token with a 90-day expiry. Rotation and disablement invalidate the previous token. SCIM supports paginated users and groups, supported equality filters, versioned updates, activation, suspension and local deletion. New accounts receive a basic company user role or a TLS staff viewer role. The token cannot assign platform ownership, administrator roles or paid entitlements. Existing accounts require an explicit immutable link before provisioning can adopt them.

SCIM deletion revokes access and begins the 60-day recovery period. Protected administrators use the portal lifecycle workflow. Portal restoration does not silently restore a revoked provider link; review the user and reconnect the authoritative identity before provisioning resumes. SCIM group membership is stored within its connection and does not automatically grant a role. Directory access rules and their acceptance remain separate. Customer provider assignment, field mappings, token rotation and real add/change/remove behavior must be accepted before describing a connection as operational.

TLS Dev and QA reuse the production identity authority without copying passwords. Automatic customer environment allocation, continuous identity mirroring and independent customer Dev/QA acceptance remain additional work. An unprovisioned environment must never be advertised as ready.

RMM release and remote access

Only verified signed packages may be offered for an accepted device and company. TLS retains release ownership, package history, scoped enrollment, revocation and remote-access policy. Native installer creation, operating-system permissions, provider licensing and real device acceptance are required before enabling downloads or claiming remote-control capability. A recorded remote-session request is not evidence of a working remote connection. Complete endpoint offboarding and verify agent removal before permanently purging its company.

Copies and questions

Your company account records the policy version, acceptance time and acting user for new orders. Keep the signed order and receipts with your own records. Download the setup PDF below or use your browser’s Print → Save as PDF for this policy.

Download setup and policy guide · Privacy Policy · Portal terms · Contact Technology Last Stop

Provider services and AI

Connections belong to one TLS or company scope. Paid product, tier, selected service dependencies and server permissions control access. A saved credential, read verification and a completed provider pass are separate states. Verification does not buy vendor licenses, grant portal roles or establish continuous availability. Dev and QA isolate external actions and do not copy production credentials.

Gmail intake stores reviewed message metadata and may convert a message for an approved active paid company user. Body text is copied only on conversion; attachments remain in the source mailbox. Conversion does not send an acknowledgment or automatically grant access. Microsoft and Google security notifications require verified sender configuration and approved recipients. Distribution-list membership and actual receipt must be accepted by the company.

OpenAI, Claude and Gemini drafting requires an explicit provider-usage acknowledgment for each request. Only the entered prompt is sent; private company records are not attached automatically. Outputs require human review. Prompt and response content are not stored in the connection run log. Provider retention and charges follow the authorized provider agreement; an uncertain request may still incur cost. Cursor reads existing agent status, and Copilot reads tenant subscription availability; neither enables unrestricted code execution or production Copilot API chat.

Provider connections can be paused, recycled for 60 days and restored pending verification. Local permanent removal does not delete the external vendor account. Credential rotation, consent revocation and external offboarding must be completed with the vendor. Connection run evidence is retained for 90 days; approved legal holds and required records follow their separate retention schedule.

Financial visibility and billing contacts

TLS owner financial and CRM records are restricted to verified platform owners. Recorded cash, expenses, refunds, savings and sales forecasts are distinct. Totals are grouped by currency and depend on complete source records; they are not a reconciled accounting statement. Provider-confirmed paid invoices are deduplicated. A vendor invoice inventory does not grant a LastStop paid entitlement.

Owner-entered financial drafts have a 60-day recycle period, subject to retention holds. Posted records retain an audit trail; manual corrections use a reasoned void and replacement. Provider receipt records are not silently rewritten. Company billing supports one primary and up to two additional approved billing contacts. Saved contact addresses do not create portal users. Card details are entered only through authorized hosted payment-provider controls.

Editing history and time zones

Supported creation and editing flows use centered dialogs with close, minimize and unsaved-change choices. A draft remains in its current tab until successfully saved; a browser crash can lose unsaved work. Knowledge and shared-password items support scoped recovery and permanent removal after the 60-day window through lifecycle execution, subject to retention holds. Audit and required accounting records follow their own schedule. Search and date filters apply to the full supported collection while page controls bound the number shown.

Company event times use the selected location-based IANA time zone, including daylight-saving changes. Stored event timestamps retain their original meaning. Calendar dates such as accounting dates and due dates are not shifted like timestamps. Changing a display time zone does not change an accepted notice deadline.