Employee Center API and Integrations Policy
No Raw Database Data Claim
For clarity, this document does not claim that Quintin N. Mahan owns raw facts, raw database rows, independent outside source records, CRS-owned operational records, customer-owned records, third-party-owned records, or customer relationships merely because such information is entered into, stored in, processed by, displayed through, backed up with, or exported from EC.
This document protects EC Protected Materials: the application, software, source code, schemas, database design, data model, relationships, indexes, workflows, dashboards, reports, queries, automations, integrations, APIs, access controls, credentials, hardware, infrastructure, legal records, certificate records, hashes, metadata systems, audit systems, methods, processes, techniques, trade secrets, documentation, and EC-created structural organization.
Version: 1.0
Effective Date: June 1, 2026
Platform: Employee Center / EC
Owner: Quintin N. Mahan
Legal Hub: /legal
Policy URL: /legal/api-integrations-policy
1. Purpose
This API and Integrations Policy explains how Employee Center (“EC”) APIs, webhooks, service accounts, connected systems, imports, exports, automations, and third-party integrations may be used.
EC is a private operational platform owned by Quintin N. Mahan. EC may connect to internal systems, external systems, customer systems, vendor systems, network devices, phone systems, email systems, SMS/modem systems, and other approved integrations.
This policy is intended to protect EC, EC credentials, EC API endpoints, EC service accounts, EC integration data, EC logs, EC automation records, EC evidence-preservation records, EC legal records, and the EC Protected Materials.
2. Scope
This policy applies to:
- EC APIs;
- EC webhooks;
- EC service accounts;
- EC API keys;
- EC OAuth connections;
- EC tokens;
- EC integration credentials;
- EC import jobs;
- EC export jobs;
- EC automation jobs;
- EC scheduled jobs;
- EC background workers;
- EC data collectors;
- EC email integrations;
- EC SMS/modem integrations;
- EC call-log integrations;
- EC network integrations;
- EC third-party integrations;
- EC-generated integration records.
This policy applies whether an integration is used by a user, administrator, service account, script, webhook, scheduled task, device, router, phone system, modem, automation engine, or third-party system.
3. Relationship to Other Policies
This policy works together with:
- Employee Center Terms and Conditions;
- Acceptable Use Policy;
- Privacy Notice;
- Cookie and Local Storage Notice;
- Data Security Policy;
- Data Retention and Backup Policy.
If this API and Integrations Policy conflicts with the Employee Center Terms and Conditions, the Terms and Conditions control unless Quintin N. Mahan signs a separate written agreement stating otherwise.
Nothing in this policy transfers ownership of EC, EC APIs, EC integrations, EC credentials, EC source code, EC integration records, EC logs, EC backups, or the EC Protected Materials.
4. Approved Integrations
EC may connect to approved systems, including:
- Zoho;
- Google Workspace;
- Google Voice;
- Gmail or email systems;
- calendar systems;
- UniFi;
- GL.iNet;
- Tailscale;
- SMS/modem systems;
- OBi / Poly / phone-related systems;
- caller ID systems;
- network collectors;
- payment, accounting, customer, and service systems;
- internal dashboards;
- Streamlit / DB Inspector tools;
- approved automation systems;
- approved customer-support systems;
- other systems approved by Quintin N. Mahan.
Approval may be limited by purpose, credential, scope, endpoint, role, network, device, company, or time period.
5. Authorized API and Integration Use
APIs and integrations may be used only for authorized EC-related purposes.
Authorized purposes may include:
- importing records;
- exporting authorized records;
- synchronizing data;
- receiving webhook events;
- sending webhook events;
- sending legal acceptance emails to Quintin;
- sending service or operational emails;
- ingesting call logs;
- ingesting network/device data;
- processing approved automations;
- supporting dashboards;
- supporting reports;
- supporting service workflows;
- supporting timecard workflows;
- supporting directory workflows;
- supporting legal records;
- supporting certificate generation;
- supporting backups;
- supporting evidence preservation and authorized transition support;
- troubleshooting;
- monitoring;
- security review.
6. Prohibited API and Integration Use
Users, companies, service accounts, scripts, or third parties may not use APIs or integrations to:
- bypass EC permissions;
- bypass Terms acceptance;
- bypass role restrictions;
- copy EC data without authorization;
- scrape EC records;
- bulk export records without authorization;
- clone EC;
- create a competing system;
- take EC credentials;
- disable EC integrations;
- disable EC logging;
- delete EC audit trails;
- delete acceptance records;
- delete certificate records;
- alter Terms records;
- alter legal evidence records;
- inject false data;
- send forged webhook events;
- overload EC with requests;
- abuse rate limits;
- impersonate another system;
- exfiltrate customer data;
- bypass owner/admin control;
- transfer EC data to a buyer, successor, or third party without authorization.
Unauthorized access or use is prohibited.
7. Credentials, Keys, Tokens, and Secrets
API keys, OAuth tokens, webhook secrets, service-account credentials, database credentials, email credentials, device credentials, and other integration secrets are confidential EC-controlled materials.
Users and companies may not:
- copy credentials;
- disclose credentials;
- share credentials;
- store credentials in insecure locations;
- hard-code credentials in unauthorized scripts;
- rotate credentials without authorization;
- revoke credentials without authorization;
- transfer credentials to another person, company, buyer, or successor;
- use credentials after access is revoked;
- use credentials to lock out Quintin N. Mahan;
- use credentials to seize or clone EC.
Credentials may be rotated, revoked, replaced, or disabled by Quintin N. Mahan for security, enforcement, preservation, or operational reasons.
8. Service Accounts
Service accounts may be used for EC-approved integrations, automations, background jobs, and system-to-system access.
Service accounts are not personal accounts.
Service accounts may be limited by:
- endpoint;
- role;
- permission;
- scope;
- IP address;
- token;
- integration;
- rate limit;
- schedule;
- environment;
- owner/admin approval.
Users may not use service accounts for personal access or to bypass user permissions.
9. Webhooks
EC may receive, process, store, verify, retry, and log webhook events.
Webhook records may include:
- source system;
- timestamp;
- event type;
- event payload;
- headers;
- signature verification status;
- processing status;
- retry status;
- error messages;
- linked EC records;
- IP address;
- audit metadata.
Users and systems may not send forged, misleading, replayed, malicious, excessive, or unauthorized webhook events.
10. Imports and Exports
EC may import and export data for authorized EC-related purposes.
Imports may include records from approved systems.
Exports may include authorized records, reports, backups, evidence packages, legal artifacts, or migration files.
Users may not use imports or exports to:
- corrupt EC;
- hide activity;
- overwrite records improperly;
- create false records;
- copy customer lists without authorization;
- bypass EC permissions;
- create unauthorized shadow systems;
- transfer EC data to unauthorized systems;
- transfer EC data to a buyer or successor without authorization.
11. Logging and Audit
EC may log API and integration activity.
Logs may include:
- API endpoint;
- method;
- request timestamp;
- response timestamp;
- status code;
- user identity;
- service-account identity;
- integration name;
- source system;
- IP address;
- user agent;
- headers where appropriate;
- payload metadata;
- processing results;
- errors;
- retry status;
- export details;
- import details;
- linked EC records;
- automation activity;
- webhook activity.
Logs may be retained for security, troubleshooting, reporting, evidence, legal defense, evidence preservation and authorized transition support, and enforcement.
12. Rate Limits and Abuse Protection
EC may apply rate limits, throttling, quotas, request-size limits, timeout limits, retry limits, or other abuse protections.
EC may block, delay, reject, disable, or restrict API or integration activity that appears abusive, excessive, unauthorized, suspicious, broken, misconfigured, or harmful.
13. Third-Party System Terms
Third-party systems may have their own terms, policies, security controls, rate limits, data practices, audit logs, and restrictions.
Users and companies are responsible for complying with applicable third-party terms when using connected systems.
EC’s use of third-party systems does not transfer ownership of EC, EC integrations, EC-created records, EC-maintained records, EC-derived records, EC logs, EC certificates, EC backups, or the EC Protected Materials.
14. Zoho Email Integration
EC may use a Zoho email integration to send legal, acceptance, certificate, operational, support, or system notices.
For EC legal acceptance notices and certificate emails, the required envelope is:
FROM: support@crsabq.com
TO: mahanquintin@gmail.com
Acceptance and certificate emails are evidence notices to Quintin N. Mahan only unless Quintin N. Mahan configures otherwise.
Users do not receive acceptance/certificate emails by default.
15. Google and Voice Integrations
EC may connect to Google Workspace, Google Voice, Gmail, calendar systems, or related services for authorized EC-related purposes.
Such integrations may support:
- call logs;
- directory records;
- email workflows;
- calendar workflows;
- audit review;
- service workflows;
- operational notifications;
- evidence preservation and authorized transition support;
- legal/evidence records.
Records imported from or linked with Google systems may become part of EC records and the EC Protected Materials to the maximum extent stated in the Terms.
16. Network and Device Integrations
EC may connect to network, router, firewall, UniFi, GL.iNet, Tailscale, phone, modem, caller ID, SMS, Raspberry Pi, or device-related systems.
Such integrations may support:
- network status;
- device status;
- call-log enrichment;
- SMS commands;
- modem activity;
- caller ID capture;
- service diagnostics;
- remote support;
- evidence preservation and authorized transition support;
- security review;
- reporting.
Users may not interfere with, spoof, disable, corrupt, overload, or misuse these integrations.
17. Automation Systems
EC may connect to automation systems, including approved scripts, scheduled jobs, Tasker, Shortcuts, SMS command systems, background workers, and webhook automations.
Automations may be logged and attributed to a user, service account, device, or system.
Users may not use automations to bypass approval, impersonate another user, create false records, delete records, export data without authorization, or interfere with EC operation.
18. Security Incidents
If an API, token, webhook, integration, or service account is suspected of misuse, compromise, leak, excessive activity, or unauthorized access, EC may:
- disable the integration;
- revoke tokens;
- rotate credentials;
- suspend service accounts;
- block endpoints;
- preserve logs;
- preserve payloads;
- preserve backups;
- restrict exports;
- notify appropriate parties where required;
- investigate and enforce EC policies.
19. Changes to Integrations
Quintin N. Mahan may add, remove, modify, restrict, disable, replace, or suspend EC APIs and integrations.
No user or company is entitled to continued access to any specific API, integration, webhook, export, service account, or automation unless a separate written agreement signed by Quintin N. Mahan states otherwise.
20. Changes to This Policy
Quintin N. Mahan may update this API and Integrations Policy by publishing a new active version in EC.
The current active version will be displayed through the Legal hub.
Older versions may remain stored in Postgres for audit, evidence, and historical review.
21. Contact / Owner
Employee Center is owned by Quintin N. Mahan.
Legal and policy documents are available from:
/legal
The current Terms and Conditions are available from:
/legal/terms-and-conditions
End of API and Integrations Policy.