Roles, scope and approvals decided on the server
Seventeen seeded roles, sixty-plus permissions and seven data-scope levels. Screens, reports and AI tools all read from the same scope rule, so nothing drifts.
Approvals
Discounts, quotations and broker onboarding route to the right approver. Pending approvals count in the sidebar and on the dashboard.
Audit and auth
JWT with rotating refresh tokens, account lockout, full audit log, and dashboards that send only the figures a role may see.
Also included
- Roles and permissions
- Organizations, companies, branches, departments and teams. A role can never grant more than its creator holds.
- Data scope
- Own, team, branch, company or organization reach per entity. A lease or receivable inherits reach from the unit it hangs off.
- Webhook & Ingestion Security
- HMAC-SHA256 signature verification (X-Hub-Signature-256), timing-safe comparisons to stop side-channel attacks, replay protection, and AES-256-GCM encryption for stored endpoint credentials at rest.
- Column masking
- IDs and bank accounts come back as bullet-masked digits unless the caller holds the sensitive-view permission. Applied in the response envelope, not per route.
- Broker isolation
- Broker users are filtered by company before role scope is considered. A protection conflict never reveals which broker holds the lead.
More of the platform


