Skip to content
Platform Controls & Security · Platform Capability

Enterprise controls without enterprise weight.

Role-based access control, configurable approval workflows, immutable audit trail, and compliance-ready records — the platform controls that let growing businesses operate with the rigor of enterprise-scale operations, without the enterprise complexity or cost.

role permissions matrix — modules × permission levels × user roles
audit trail with filtered results

What Platform Controls handles.

Access, approvals, audit, and authentication — the controls every action on the platform passes through.

Role-based access control (RBAC) at module, function, and data level
Configurable approval workflows for high-impact actions
Immutable audit trail on every action with user attribution and timestamp
Multi-factor authentication (MFA) for user access
Session management with configurable timeout policies
Data segregation across warehouses, business units, or entities
Data export controls with permission-based restrictions
IP allowlisting for enterprise deployments
Password policies (complexity, expiry, rotation)
Compliance-ready record retention and archival

How platform controls run.

These are the control operations that run behind everything else — user setup, approval enforcement, and audit trail retrieval when someone asks.

Workflow 1

User Setup and Role Assignment

5 steps
01Admin creates a new user02Assigns to a role (Sales, Warehouse, Finance, Management)03Role determines modules, actions, and data access04Custom roles for specific responsibility patterns05Productive within minutes, restricted to only what they need

Admin creates a new user, assigns to a role (Sales, Warehouse, Finance, Management, etc.). Role determines what modules, actions, and data the user can access. Custom roles can be created for specific responsibility patterns. New user is productive within minutes, restricted to only what they need.

Workflow 2

Approval Workflow Enforcement

5 steps
01High-impact action requested02Routes through the configured approval chain03Approver sees full context, acts from mobile or desktop04Rejected requests return with a reason05Complete audit trail preserved

High-impact actions (stock adjustment beyond threshold, customer credit override, vendor payment above amount) route through configured approval chains. Approvers see full context and can act from mobile or desktop. Rejected requests return with reason. Complete audit trail preserved.

Workflow 3

Audit Trail for Compliance

5 steps
01Every action captured with user, timestamp, and IP02Change details recorded03Records immutable after creation04One query returns complete history05Root cause analysis is straightforward

Every action captured with user attribution, timestamp, IP address, and change details. Audit trail is immutable — records cannot be modified after creation. When auditors ask, one query returns complete history. When incidents occur, root cause analysis is straightforward.

Who uses Platform Controls.

Admins configure it, management and compliance review it, and every other user operates inside it whether they notice or not.

Role
Usage
What they do with it
Admin
Primary
Primary users. User management, role configuration, permission setup, security monitoring.
Management
Secondary
Approval workflow configuration, audit trail review for exceptions, compliance oversight.
Compliance / Audit
Secondary
Audit trail extraction, compliance reporting, security incident investigation.
All users (indirectly)
Secondary
Every user operates within the permission structure — invisible when working correctly, immediately visible when acting outside authorization.

Common questions about platform controls.

Very granular. Access can be restricted at module level (Sales, Procurement, Warehouse), function level (view vs edit vs delete), and data level (specific warehouses, customer groups, product categories).

Every action creates an audit record with user, timestamp, IP address, and change details. Records are immutable — cannot be modified after creation. Retention configurable per compliance requirements.

Yes. Approval chains configurable by amount, category, or user role. Multi-level approvals supported. Approvers can act from mobile or desktop.

Configurable. Recommended for administrative accounts and high-privilege users. Supported: TOTP (Google Authenticator, Authy), SMS-based OTP, email-based OTP.

The audit trail, access controls, and record retention support customer compliance with data protection regulations. Currently designed with DPDP Act requirements in mind for Indian operations; extensible to GDPR and other frameworks.

Ready to see it in action?

Enterprise controls, growth-paced.

A 30-minute discovery call showing how platform controls give you compliance-ready operations. If it's a fit, we'll follow up with a tailored proposal.

Have questions first? Email hello@stockrect.com