Security and access control
Permission is checked on the server, on every request
Not once at sign-in, and never in the browser. Each of these is working today and covered by tests — nothing on this page is a plan.
What it does
What this does today
Each of these is working and covered by tests.
Roles and permissions
One role per person for their place in the business, plus job roles layered on top. Every action is checked against them on the server.
A ceiling nobody can exceed
Nobody can grant access they do not hold themselves. The check runs inside the same database transaction as the change.
Access recalculated every request
Membership, role, branch scope and entitlement are re-read on every call. Nothing about permission is stored in the session token.
Tenant isolation
One organization can never read another’s data. It is enforced in the database itself, not only in application code.
Audit
Who did what, and when — written in the same transaction as the change rather than alongside it.
Validated on the server
Every input is checked again on the server, whatever the browser already validated. The frontend is a convenience, never a control.
The rest
Everything else the platform covers
Available and planned, kept visibly apart.
Get started
The foundation is ready. Set yours up today.
Organization, branches, people, roles and permissions all work now. The applications join them as they ship.