Single Sign-On
Enterprise Single Sign-On, Typically Against Microsoft Entra ID
SAML 2.0 and OIDC Both Supported
Multi-Factor Authentication Enforced at Your Own Identity Provider
A Written Onboarding Runbook for Connecting Your Identity Provider
Role-Based Permissions
483 Individually Controllable Page Actions
Set per Page and per Action: View, Create, Update, Delete, Export, Print, Assign, and Sync
Seven Seeded Roles: Admin, Manager, Operator, IT, Quality, Visual Audit Manager, and Visual Audit Operator
Roles Customized per Tenant, with Customer-Specific Override Sets Running in Production
The Navigation Menu Renders Only What That Role Permits
Audit Trail
Every Movement Logged: Who Did It, How Long It Took, Source and Destination, Lot, and Comment
The Transactions Report Filters Nine Ways
Active Holds Shows What Stock Is Frozen, Why, Who Froze It, and When
Excel Exports Stamped with Who Ran Them and Which Filters Applied
Data and Access Boundaries
Verified TLS with Server-Certificate Verification on Every Cloud Database Connection
Users Scoped to Specific Warehouse Sites, with a Global Site Switcher
Duplicate-Action Protection, so a Double-Tap or Dropped Connection Cannot Double-Post
Rocket Local Runs Inside Your Own Network to Bridge a Firewalled Legacy Database
Linked Client and Server Traces, so a Reported Issue Can Be Reproduced Exactly
AI Assistant Safeguards
24 of the 25 Assistant Tools Are Read-Only
The One Tool That Writes Requires a Two-Turn Confirmation
Every Confirmed Write Is Audit-Logged
A Per-Tenant Kill Switch and Per-Tenant Rate Limits
Available to Admin and Manager Roles Only
Internal Knowledge-Base Tools Removed, so Tenant Chat Cannot Surface Internal Detail