Help · Security and access

Who can do what, and the record of it.

Ten roles, seventeen permissions, enforced on the server. Two-factor sign-in for everyone who wants it and everyone an owner says must. Every change to your data carries who made it, what it was before, and why. The security page lists the controls in full, including the ones not yet in place.

Roles

Additive from viewer upward.

A viewer reads. An analyst also imports. A functional manager also assigns exceptions and decides approvals. An administrator manages the organisation's settings; the owner can do everything, including invite the next owner. The automated agents hold a narrower set than the people who trigger them — an agent can never do something the person who ran it could not.

Beyond roles, an owner can grant or withhold each module per person under Module access, so a payroll module is visible to the people who run payroll and nobody else.

Signing in

Passwords, codes, passkeys, single sign-on.

Passwords are twelve characters or more and are never stored as such. A second factor is a time-based code from an authenticator app, with single-use recovery codes, or a passkey — the fingerprint or face your device already uses. An owner can require a second factor across the organisation; a member without one is reminded on every page, not locked out of the page where they enrol. Organisations with an identity provider can sign in through it; the provider's roles are mapped to ours once and then followed.

Sessions last eight hours and end sooner when idle. Three wrong passwords lock the account until an administrator unlocks it, and every sign-in, failure and unlock is logged with the address it came from.

The audit trail

Actor, before, after, reason.

Every state change — an import, a decision, an execution, a setting — writes a row with who did it, the record before and after, and the reason where one was given. Administrator actions taken from the platform console write a row your organisation can see. Audit rows are kept for seven years; sign-in events, which contain addresses, for one.

Your data

Yours, exportable, and read by a model only in bounded pieces.

Every figure on every screen can be downloaded with the rows that produced it. Where a language model is used — the Copilot, and the agents that write recommendations in prose — it is handed a bounded context of aggregates and never the database, and your organisation sets a monthly ceiling on that spend. Most of the product never calls a model at all.

Get started

Bring one month of data. Leave with your own control tower.

A demo runs on your material master, your purchase orders and your stock — not on ours. Thirty minutes, and you see your own exceptions rather than a scripted one.

Ask a question

Book a demo

Thirty minutes, on your own data. Six fields — the rest only helps us prepare.

Not binding. Tell us the size and we will say which one fits.

The demo connects to it, so this shapes the whole session.

Add context, and the demo runs on your problem rather than a scripted one

We reply within one working day.