Skip to content
CleverHiveCleverHive Technologies
Available today

Security and access control

Permission is checked on the server, on every request

Not once at sign-in, and never in the browser. Each of these is working today and covered by tests — nothing on this page is a plan.

What it does

What this does today

Each of these is working and covered by tests.

Roles and permissions

One role per person for their place in the business, plus job roles layered on top. Every action is checked against them on the server.

What someone may do is decided once and honoured everywhere, rather than configured again inside each application.

A ceiling nobody can exceed

Nobody can grant access they do not hold themselves. The check runs inside the same database transaction as the change.

An administrator cannot quietly build a role more powerful than their own, and the rule cannot be skipped by a screen that forgot it.

Access recalculated every request

Membership, role, branch scope and entitlement are re-read on every call. Nothing about permission is stored in the session token.

Revoking someone takes effect on their next click, not their next sign-in.

Tenant isolation

One organization can never read another’s data. It is enforced in the database itself, not only in application code.

A bug in a screen cannot leak another business’s records, because the database would refuse the query.

Audit

Who did what, and when — written in the same transaction as the change rather than alongside it.

A change that rolled back leaves no entry, so the trail cannot disagree with reality.

Validated on the server

Every input is checked again on the server, whatever the browser already validated. The frontend is a convenience, never a control.

Get started

The foundation is ready. Set yours up today.

Organization, branches, people, roles and permissions all work now. The applications join them as they ship.