Role sets
Screen permissions are grouped into role sets: director, finance, HR, production, retail. The implementer is not lost among dozens of technical groups.
What follows are existing mechanisms, not promises. Every item corresponds to a working part of the system.
Last updated: 2 September 2026
Screen permissions are grouped into role sets: director, finance, HR, production, retail. The implementer is not lost among dozens of technical groups.
Model-level permission is not enough: rules decide which ROWS are visible - another company's document, for instance, is not.
Login through an OIDC provider with the role assigned automatically. When someone leaves, access is closed in the central directory.
The audit trail is a separate financial report: who made an entry and when is visible.
Nothing posts into a closed period. That prevents accidental edits and keeps reports stable.
A document cannot be deleted before its period is over; afterwards it is archived. There is no automatic deletion - an irreversible operation was deliberately left out.
⚠ This page describes technical mechanisms. Concrete commitments - response times, where and how long backups are kept, access procedures - are written into the contract and the SLA.
Write to info@erpona.app. Telling us before making it public gives us time to fix it.