Isolated books, permissions down to the action
Many outlets and entities in one system, each with its own books: company + country dual-dimension isolation is enforced architecturally, and permissions go from menus down to buttons.
Architecture-level tenant isolation
Isolation by design, not by discipline.
- Tenant identity extracted from auth tokens — the client cannot forge it
- Every query is tenant-filtered by force; cross-tenant access is structurally unreachable
- One-click tenant initialization: company, outlets, accounts and menus configured together
Dual role & menu systems
Platform operators and outlet tenants each get their own permission world.
- Operator-side roles for tenant, contract and system management
- Tenant-side roles for departments, staff and module visibility
- Per-person control over sensitive reports
Commercial gating, automated
Contract rules live in the system and take effect on schedule.
- Tiered contract-expiry reminders and access gating
- Account expiry / freeze status pages with self-service recovery
FAQ
Can data leak between outlets?
No. Multi-tenant isolation is enforced at the architecture level; identity tokens resolve data ownership automatically and tenants cannot see each other.
Can staff be limited to specific features?
Yes. Menus and operations are authorized per role with fine granularity — each role sees only what it is granted.
What about one person managing several outlets?
One account can join multiple outlets and switch quickly; owners can also check every outlet from the WeChat mini-program.
Many outlets, one clean system
Tenants and permissions configured to match your org structure.
Get Started · Scan on WeChat