Back to product

Controlled access

Tenant Security and Permissions

CatOps is built as a multi-tenant system with server-side authorization patterns. The same app can support admins, operators, clients, and platform owners while protecting tenant boundaries and sensitive financial data.

What is included

The working parts behind this feature.

  • Tenant-scoped APIs, data access, navigation, and feature entitlements
  • Admin, operator, client, master admin, sub-role, grant, and deny permission patterns
  • Feature bundles for warehouse, co-packer, brewery, distillery, and winery operations
  • Audit logs for sensitive activity, financial changes, approvals, and system events
  • Cost and margin hiding for users without the correct permissions

Workflow

How it moves through CatOps.

01

Define roles

Set up admins, operators, clients, and sub-roles around what each person should do.

02

Scope features

Enable the right inventory, production, compliance, planning, and finance modules by tenant.

03

Protect data

Enforce tenant and permission checks at the server and API layer.

04

Audit changes

Preserve a record when sensitive records, permissions, or financial data changes.

Why it matters

Designed for multi-tenant SaaS from the start

Lets clients see what they need without exposing internal operations

Supports operational users without making everyone an admin