Skip to content

Feature · Plattform

Who sees what,
who may do what — fully traceable.

Five predefined roles with individual additional permissions per user. Immutable audit log. Multi-tenant isolation at the database level with two independent protective layers.

The auditor asks who changed the hourly rate. Open the audit log, filter: name, date, old value, new value. Question answered — in thirty seconds.

Was diese Funktion macht

Five roles — from admin to purchasing/inventory — run day-to-day operations; where they fall short, you grant individual users specific additional permissions, even time-limited ("only until Dec 31"). Sensitive figures like purchase prices and hourly rates are their own permissions: whoever may not see them sees them nowhere — not in the costing, not in the export. Every critical change is recorded immutably in the audit log, with before and after values. And beneath it all lie two independent protective layers of tenant separation: even a fault in the application would never mix your data with that of other businesses.

Was Sie damit können

Who may do what, who did what. Both answered at any time.

01

Five predefined roles

Admin (everything), Planner (orders, desk, quotes), Team lead (own orders), Employee (My Work, time clock), Purchasing/Inventory (materials and procurement). The roles are fixed and cover the common areas of responsibility in a trade business.

02

Individual permissions per user

Even though the roles are fixed, individual users can receive individual additional permissions. Example: employee Max has the standard role "Employee" but is additionally granted permission to create quotes — because he acts as the boss's right hand. This keeps the system simple yet flexible.

03

Visibility of purchase and sales prices

Purchase and sales prices, margins, and hourly rates can be shown or hidden per role. Employees see no costing figures, team leads optionally. The admin decides who may see what.

04

Time-limited permissions

Every additional permission can be given a "valid until" date — ideal for external consultants, interns, or temporary stand-ins. After expiry, the permission is ignored on every check; the user loses access from midnight of the cutoff date. The admin can extend it at any time.

05

Comprehensive audit log

Logged are all write operations on important objects (orders, tasks, materials, times, customers, employees), login and logout, password resets, permission changes, data exports, soft deletes, and configuration changes. Read accesses are not recorded — for data protection and performance reasons. The log is append-only, is never deleted automatically, and cannot be altered after the fact.

06

Multi-tenant isolation with two protective layers

Every tenant is strictly separated from all others at the database level. Gantway uses PostgreSQL Row Level Security on all relevant tables — systematically, without exception. In addition, the application code also filters by tenant on every query. Two independent protective layers ensure that data is never visible across tenants — even in the theoretical event of a fault at the application level.

Anwendungsfälle

So nutzen Sie es.
Drei typische Situationen.

01

Journeyman without margin visibility

A journeyman should see his tasks and book times, but no prices or margins. You assign him the "Employee" role — margin fields are hidden, purchase/sales prices not visible.

02

External consultant with a time limit

A consultant comes in for an optimization project and should have read access for three months. You create a user with the role "Planner (read-only)" and an expiry date of June 30. On July 1, their access is automatically revoked.

03

Data protection request

A former employee requests their data. In the audit log you filter by user, see all actions — and can generate a complete extract.

Permissions, Audit & Security
in Ihrer Werkstatt sehen.

In 15 Minuten zeigen wir Gantway anhand Ihrer typischen Aufträge — unverbindlich, kostenlos, mit Fokus auf Ihre Branche.