Platform, security & admin

Multi-tenant isolation, roles, vault, branding, and platform control for operators.

Book a demo · See all modules

What you get

Who runs this

Questions

How are workspaces isolated? Every row is org-scoped; roles gate pages and APIs per workspace.

Multi-tenant isolation is the default. A member of one company cannot read another company’s journals, files, or HR records through the product APIs.

Can operators back up a tenant? Yes — encrypted platform backups and structured org backup/restore.

Operators with the right access can schedule encrypted backups and restore a single organisation without rewinding every tenant on the shared database.

What authentication options exist? Invite-only access with optional TOTP and recovery codes.

Admin, manager, and accountant presets ship with page-level grants. Two-factor authentication is available when the workspace requires it.

Can we brand the workspace? Yes — logo, favicon, and workspace branding in settings.

Bank accounts, number series, catalogs, legal profile, and fiscal year start live beside branding so go-live setup stays in one admin surface.

How do tenant subdomains work? Active workspaces serve on {slug}.omnizone.app.

Platform operations attach and verify workspace hostnames so each company opens on its own host while the shared cookie domain stays under Omnizone control.

Who runs platform operations? Super-admins — orgs, job queue, backups, and jurisdictions.

The platform layer is for operators: create organisations, watch the import queue, manage reserved subdomains, and apply statutory packs — not for day-to-day bookkeeping inside a tenant.

What this does not do

Connected to the rest of the system

FAQ

Can operators back up a tenant?

Encrypted platform backups and structured org backup/restore are available to operators with the right access.