Security & governance

Built for operators who answer to owners, auditors and parents — with least-privilege access, full audit history and integrity rules enforced by the system.

Access control

Three checks on every action.

  1. Permission

    The user’s role grants the action — e.g. Finance can post invoices, a Warden cannot.

  2. Organisational scope

    The record sits inside a city, cluster or branch the user is assigned to.

  3. Effective period

    The assignment is open today. Staff who moved or left lose access on the end date.

Roles

Super Admin · City / Cluster / Branch managers · Warden · Finance · Front Desk · Technical · Auditor — configurable to your organisation.

  1. Super Admin / PortfolioAll cities, all branches
  2. City / Area managerBranches within assigned cities
  3. Cluster managerHostels in the cluster + shared store & kitchen
  4. Branch managerOne or more assigned branches
  5. Warden · Front Desk · FinanceTheir branch, their permissions, their dates
Data integrity

Rules that prevent silent corruption.

  • Insert-only audit trail

    Who did what, when, in which session and module — with a redacted payload. Audit records are appended, never edited.

  • Immutable posted finance

    Posted invoices and receipts cannot be rewritten. Corrections are adjustments with a reason and an approver.

  • Enforced status transitions

    Applications, reservations, occupancy and checkout follow defined state machines — no skipping from ‘applied’ to ‘checked in’.

  • Facts over flags

    Bed status is recomputed from occupancy, blocks and offers. Stock is the sum of ledger movements. Balances derive from allocations.

  • Lift, don’t delete

    Person alerts and blacklists are lifted with history, so a reviewer can always see why and when.

  • Safe concurrency

    Occupancy locking prevents two check-ins landing on the same bed, even on the busiest admission day.

Governance

Decisions, documents and configuration — all on record.

Approval matrix

Waivers, deposit overrides, transfers and price exceptions route to the right approver by scope and amount.

Central configuration

Waitlist days, offer expiry, notice periods and KYC rules are configuration with history — not hard-coded exceptions.

Documents & storage

KYC documents, photos and signatures in secure object storage, with metadata and access controlled in the platform.

Business IDs vs system IDs

Human-readable numbers for staff; UUIDs internally; external provider IDs stored as references, never as replacements.

Enterprise posture

Ready for your security review.

  • Privacy

    Personal and identity data access limited by role and scope; audit payloads redacted.

  • Backup & continuity

    Backup and recovery practices documented for your continuity planning. Details shared under NDA during procurement.

  • Compliance reviewers

    Auditor role with read access to audit and session history screens.

Bring your IT and audit team to the demo.

Book a 45-minute demo. Bring your hierarchy — cities, clusters, branch count — and we’ll walk through admissions, the bed map, billing and scoped access against it.