# Everyone sees only their work.

> Access control — part of the Intigra business platform.

Add your team, hand each person their own login, and decide exactly what they can open, add, edit or delete. Every check is enforced again on the server, so nobody can slip past what you allowed.

## Everyone sees only their part.

*The idea in one line*

Your salesperson opens the app and sees enquiries and quotations. Your store keeper opens the same app and sees stock for the godowns he handles. Your accountant sees the figures, not the prices you would rather keep private. One firm, one app, but each person walks into the room they belong in and no further. You decide who gets which keys, and you can take them back the moment something changes.

- Give each person a role like Admin, Sales, Store keeper or Accounts
- Every screen, button and figure is shown only to the people you allowed
- A person never even sees the parts of the app they cannot use
- Change someone's access and the whole app respects it the moment you save

## Shared logins where everyone sees everything, or a scoped login for each person.

Most small firms start with one login that the whole office shares. It feels simple, until you realise nobody can tell who did what, and everybody can see everything.

### One shared login for the whole office

- Everyone signs in as the same person, so you can never tell who added or changed a record
- The newest junior sees the same prices, margins and order values as you do
- A salesperson can open stock, accounts and reports that are none of their concern
- When someone leaves, the only fix is changing the password for everybody at once
- Nothing stops a person from deleting a record they were never meant to touch
- If two firms run on the same software, you are never quite sure your data stays yours

### A scoped login for each person, with Intigra

- Each person signs in as themselves, so every record carries who really did it
- Sensitive figures like prices and order value are hidden from anyone you have not allowed
- A person only ever sees the areas you ticked, and the rest of the app stays out of sight
- Remove one person and they are signed out at once, with everyone else untouched
- View, add, edit and delete are separate rights, so reading never means being able to change
- Your firm's records live in their own sealed space, apart from every other firm on the software

## Permission down to the single action, and data kept to its rightful owner.

Two things decide what a person can do: which actions you ticked for them, and which records belong to them. Both are decided by you, and both are checked again on the server before anything is saved.

### Tick exactly what each person may do

For every part of the app you tick what a person is allowed to do. Looking at a list, adding a record, changing it and deleting it are four separate choices, so you can let someone read without ever letting them touch.

- Separate ticks for view, add, edit and delete on every area
- Enquiry and quotation rights, including sending offers and logging follow-ups
- Customer, contact person, product and supplier record rights
- Procurement, delivery and arrival rights, each held on its own
- Hide sensitive figures like prices, commissions and order value
- Untick anything later and the change applies the moment you save

### Each firm's data stays sealed off

Your business sits in its own private space. Another firm using the same software can never see a single one of your customers, enquiries or figures, and your own people only ever reach the records you handed to them.

- Your firm's records live in their own space, apart from every other firm
- Inventory can be limited godown by godown to the right store keeper
- Approvals follow your reporting line, so a manager sees only their juniors' work
- Separate rights for a junior's own records versus everyone's records
- Backdated changes need their own permission, kept apart from normal edits

### Built so it cannot be tricked

Hiding a button on the screen is never the whole story. Every request is verified again on the server, so a person cannot reach a record or run an action just because they found a way around the screen.

- Every request is re-checked on the server, never trusted from the screen alone
- You can only hand out rights that you hold yourself
- Removing a right also removes everything that depended on it
- Customer and product references are revalidated before anything is saved

## The full list, so nothing is left to guesswork.

These are the controls you actually get. Hand out exactly the keys you mean to, and take them back just as easily.

### Adding and managing users

- **Add a user with name and role** — Open the Add User form, fill in first name, last name and role, then pick their permissions before the account is created.
- **Set how many users they can manage** — Decide how many people each user is allowed to add and manage themselves, so you can let a manager run their own small team.
- **One-time temporary credentials** — When you create a user the app generates a temporary Company ID, username and password, with a Copy Credentials shortcut to share them.
- **Password shown only once** — The temporary password appears only on the confirmation screen, so it is never left lying around inside the app afterwards.
- **User completes their own profile** — On first sign-in the new user is asked to fill in their personal details and change the temporary password to one only they know.
- **Edit profile, permissions and details any time** — Open any user later to change their name, role, what they can do, and personal details like email, address, Aadhaar, PAN and notes.
- **Add-user button locks at your limit** — Once you reach the number of users you are allowed, the Add User button is disabled until you remove someone to free a slot.

### Removing and archiving

- **Delete a user with a typed confirmation** — Removing a user asks you to type their username exactly to confirm, so an account is never deleted by an accidental click.
- **Deleted users are signed out at once** — The moment you delete a user they are logged out everywhere and can no longer sign in, even if they still have the app open.
- **Nothing is truly lost** — A deleted user is kept read-only rather than wiped, so their past work and details remain on record for you to look back at.
- **View Deleted Users** — Open the Archived Users list to see everyone who has left, each entry showing their name, username, role and exit date.
- **Inspect an archived user** — Open any archived user to review the profile, permissions and personal details they had when they were removed.

### What each permission controls

- **Separate view, add, edit and delete ticks** — For every area of the app, looking at a list, adding a record, changing it and deleting it are four separate ticks, so you can let someone read without ever letting them touch.
- **Rights for every part of the business** — Enquiries, quotations, customers, contact persons, products, suppliers, procurement, deliveries and arrivals each carry their own permissions that you hand out one area at a time.
- **Hide sensitive figures** — Overview controls like Order Value decide whether revenue, prices and similar private numbers are shown to a particular person while they still use the rest of the screen.
- **Backdated entries kept on a separate leash** — Permission to make a backdated entry is held apart from a normal add or edit, so changing the date on a record is a deliberate right you grant on its own.
- **Own records versus everyone's records** — A junior can be limited to the records they created while a manager sees their whole reporting line, and approvals follow that same line so a manager only acts on their juniors' work.
- **Hand out only the rights you hold** — You can never grant a permission you do not have yourself, and removing a right also removes anything that depended on it, so access can never quietly exceed your own.
- **Inventory limited godown by godown** — Stock rights can be tied to specific godowns, so a store keeper only sees and handles the locations that are genuinely his to manage.

### Dashboard, reports and AI permissions

- **Open Dashboard is the master switch** — This single permission unlocks the dashboard page; without it, none of the overview figures or detailed reports appear at all.
- **Each detailed report on its own switch** — Sales, customer, product, supply chain, procurement and HR reports each have their own permission, so you grant only the ones a person should read.
- **Reports stay hidden until both switches are on** — A report block appears only when the person holds Open Dashboard and that report's own permission together, never just one of the two.
- **Fine-tune which figures show** — Overview controls like Order Value decide whether revenue and similar sensitive numbers are shown inside a tab to that particular person.
- **View AI Inbox is the master AI gate** — Once AI is switched on, this permission opens the AI Inbox as read-only; without it a person can neither approve, ignore nor re-run anything the AI has prepared.
- **Approve, ignore and re-run AI documents** — Separate rights let a person turn a staged enquiry, sales order or supplier quotation into the real thing, drop an email the AI is processing, or re-run the AI on one.
- **Manage AI settings and browser clipping** — A firm-wide right covers the listening inbox, fallback product and AI controls, while a separate right decides who may push pages in through the browser extension.

### Sessions and personal security

- **Review every device that is signed in** — The Security tab lists each active session with its browser, operating system, IP address and start time, and tags the one you are using right now as Current.
- **Two devices at most, one PC and one phone** — A person can be signed in on one computer and one phone at a time; signing in on a second of either kind signs the first of that kind out, while the other stays connected.
- **Revoke a session or sign out this device** — Revoke any session you do not recognise to cut it off at once, or use Logout From Current Device to sign out only the device in your hand while your other one stays connected.
- **Reset a forgotten password yourself** — From the sign-in page you request an 8-digit code by email, which lasts five minutes and allows three tries, then choose a new 8 to 16 character password; resetting signs you out everywhere.
- **Recover a forgotten Company ID or username** — Ask for your sign-in details by email and they are sent to you, finding accounts across more than one firm, while the screen never reveals whether an email has an account.
- **Change your password and email** — From Update Security Data you change your own password or the email address the app uses to reach you, each behind its own confirmation modal.
- **Connect your own sending mailboxes** — Add personal Google or SMTP mailboxes to send from, re-verify one whose authorisation has lapsed, or remove one once it has no mail still waiting to go out.

> The access you set here decides what every person sees across enquiries, customers, inventory, HR and reports — one switch, and the whole app respects it.

## Related modules

- [Team, HR & expenses](https://intigra.app/modules/team.md)
- [Enquiries & quotations](https://intigra.app/modules/enquiries.md)
