Who can do what — and who did what — settled.
Users, roles and per-action permissions, live session control, an action center that chases work for you, and an audit trail that remembers everything.
An ERP is only as trustworthy as its controls. Administration is where they live: roles assembled from granular permissions that every single endpoint checks, sign-in hardened with MFA and lockouts, sessions you can see and end, and a before-and-after audit trail on every change. Add a built-in help center your own team maintains, and the platform explains itself.
- Roles built from per-action permissions — every API call checks one
- MFA with backup codes, automatic lockouts, IP allow-lists and single sign-on
- Live session dashboard with record locking, conflict logging and force-release
- Action center: notifications, work queues, SLA tracking and broadcasts
- Before/after audit trail on every change, plus a built-in help center
What’s included
The control plane for the whole platform — access, accountability and attention, managed from one place.
Users, roles and permissions
Access that matches your org chart, not a licensing tier.
- Per-action permission codes. Reading a vendor, writing a PO and approving one are different permissions checked by the API itself — “can see the screen” never silently means “can change the data”.
- Roles that bundle permissions. Define a role once — warehouse, purchasing, AP clerk — and every hire in that job gets exactly the same rights, ending permission-by-copying-a-colleague.
- Organization and branch scopes. Users are scoped to the organizations and branches they work in, so a branch manager manages a branch, not the company.
- Bulk user import wizard. Onboard a whole team from a file with a validation preview before commit — the typo is caught on screen, not discovered at first login.
- Everyday account operations. Unlock, reset password, deactivate and reassign roles in two clicks, so routine account hygiene never waits on a support ticket.
Sign-in that holds the door
Layered defenses in front of every account.
- Multi-factor authentication. Authenticator-app codes with eight one-time backup codes per user — a stolen password stops being a stolen account.
- Automatic lockout. Accounts lock after five failed attempts and every failure is logged, so a brute-force run trips an alarm instead of running all night.
- Single sign-on. Sign in through your existing identity provider, so offboarding in one place is offboarding everywhere.
- IP allow-lists. Restrict access to known networks per tenant — the ERP simply is not reachable from where your people are not.
- Bot defense on public surfaces. Challenge checks and honeypot logging on registration and login keep automated junk out of your user and lead queues.
Sessions and record locks
See who is in, and stop the two-editors problem for good.
- Live session visibility. Every active session with device, IP and last activity — “is that login really Dave?” gets answered with a row, not a guess.
- Revoke and terminate. Users end their own stray sessions; admins terminate anyone’s, convert one to read-only, or force-release with a reason on record.
- Record-level locking. Opening a PO for edit locks it; a second editor is told exactly who holds it and since when — no more last-save-wins overwrites.
- Conflict and stale-session handling. Lock collisions are logged, idle users get warned, and stale sessions are swept in batches, so abandoned locks never hold a record hostage overnight.
- Configurable lock rules. Lock behavior, idle timeouts and multi-session policy are set per screen and per tenant — strict where money moves, relaxed where it does not.
Notifications and the action center
The platform taps the right shoulder, instead of everyone polling screens.
- Event-driven notifications. PO approved, stock out, SLA at risk — events become in-app, email or push messages to the people who own them.
- Automation rules. Map any business event to a notification, a tracked action item, or both, targeted at a user, role or queue — routing lives in configuration, not in tribal knowledge.
- Work queues with SLAs. Department queues carry SLA hours, and breaches are tracked and escalated — the oldest item in the pile can no longer hide.
- Actions with a paper trail. Each action item carries comments, attachments, snooze, assignment and a full status history, so handoffs survive shift changes.
- Broadcasts and preferences. Role-targeted announcements for the things everyone must see, and per-user channel preferences so nobody drowns in the things they must not.
Audit trail and built-in help
Perfect memory, and a manual that lives where the work does.
- Before-and-after audit trail. Every create, update and delete stores the record’s full before and after — “who changed this price last Tuesday?” is a filter, not a forensic project.
- Activity log. Who did what, from which IP, on which screen, with duration and outcome — support can replay a user’s afternoon instead of interviewing them about it.
- History on the record. Each record’s drawer embeds its own change timeline, so you read a PO’s history where you read the PO.
- Built-in help center. Versioned help articles with a draft-and-publish workflow, written by your own team in your own vocabulary — the manual stops living in a shared drive.
- Field-level tooltips. Explanations attached to the fields themselves, so the answer to “what does this checkbox do?” is on the checkbox.
An audit trail that answers, not argues.
Two logs, on purpose. The audit trail records what changed in the data — every mutation with its full before and after. The activity log records what people did — screens, actions, IPs, durations, outcomes. Between them, any dispute about “who changed what, when” ends in a lookup instead of a meeting.
- Before and after, kept — every change stores the record as it was and as it became — recoverable, comparable, undeniable.
- Two questions, two logs — what changed in this record is the audit trail; what did this user do is the activity log — each tuned for its audience.
- History where you work — every record’s drawer carries its own change timeline, so context never requires leaving the screen.
Work that chases itself.
Without routing, an ERP is a set of screens people must remember to check. The action center inverts that: business events become notifications and tracked action items, routed by rules to a person, a role or a queue — with SLA clocks running and breaches escalated. The work finds its owner; the manager watches the queue, not the whole floor.
- Rules route the work — map any event to notify, create an action, or both — targeted at a user, role or queue, changeable without a developer.
- SLA clocks with consequences — queues carry SLA hours; due-today, breached and escalated items surface on the dashboard by themselves.
- Signal, not noise — per-user preferences by category, channel and minimum priority keep the bell meaningful.
What administrators ask us
How granular do permissions actually get?
Per action, not per screen. Reading vendors, writing purchase orders and managing users are separate permission codes, and every API endpoint checks the specific one it needs. Roles bundle those codes, and users can additionally be scoped to organizations and branches.
Can I see exactly what changed on a record?
Yes. Every mutation stores the record’s full before and after in the audit trail, filterable by module, record, action, user and date — and each record’s drawer embeds its own change timeline, so you rarely have to leave the screen you are on.
What happens when two people edit the same order?
The first editor holds a lock. The second is told who holds it and since when, and the collision is logged. Admins can force-release with a reason on record, idle holders get warned, and stale sessions are swept automatically — the last-save-wins overwrite simply cannot happen.
Can I end a session that shouldn’t exist?
Yes. Users can revoke their own sessions from any device; admins see every active session with device, IP and last activity, and can terminate it, convert it to read-only, or force-release its locks — all of it logged.
Will notifications turn into noise?
No — routing is deliberate. Automation rules decide which events notify whom, work queues absorb what teams share, and each user sets channel and minimum-priority preferences per category. The bell rings for things that are yours.
Do you support MFA and single sign-on?
Yes. Authenticator-app MFA with one-time backup codes, automatic lockout after repeated failures, single sign-on through your identity provider, and tenant-level IP allow-lists on top — layered, and each layer optional per your policy.
Run a tight ship, provably.
Fourteen days with the full platform — build your roles, turn on MFA, and watch the audit trail record it all.
14 days · every module · no card