Roles, Permissions & Security (RBAC)

Security is the foundation

Fine-grained roles and permissions, revocable user and device tokens, signed reader events, encryption at rest and strict tenant isolation.

Fine-grained RBAC
Revocable tokens
Signed device events
Tenant isolation
RBAC — deny by default

9 capabilities, per screen

View, create, edit, delete, manage, finance, audit, devices and alerts — finance fields stay protected by default.

Revocable access

Short-lived, always revocable

Rotating refresh tokens let you revoke a user session or a device instantly.

Signed reader ingest

Replay-proof, rate-capped

HMAC signatures with a timestamp window and nonce, plus rate and size caps, keep reader ingest trustworthy.

Encryption & isolation

Keys live outside your tenant DB

Device secrets are AES-256 encrypted, tenants are strictly isolated, data is encrypted in transit, and everything is audit-trailed.

Data ownership

Your data, export anytime

Export your data whenever you want. SSO/SAML, data residency and 2FA are on the roadmap.

How it works

1

Assign roles

2

Grant least privilege

3

Revoke anytime

Everything included

  • RBAC (9 capabilities)
  • Per-screen guards
  • Revocable user/device tokens
  • Signed ingest
  • Encryption at rest / in transit
  • Tenant isolation
  • Audit trail
  • Data export
  • SSO / data residency / 2FA (roadmap)

Frequently asked questions

Through fine-grained, deny-by-default RBAC: nine capabilities per screen (view, create, edit, delete, manage, finance, audit, devices, alerts), with finance fields protected, backed by revocable tokens and a full audit trail.

Ready to account for every asset?

Tag, track and audit everything you own — from a handheld scanner to a boardroom report.

No card required · Live in a day · TZS/USD/GBP