PZone ERP v1.0 · Manual

Chapter Ten - Governance & Permissions: the layer that guards the whole system

After going through every module, this closing chapter brings together the full governance model: the organizations and roles, the gates that reveal the modules, the two protection layers (the front end and the database), the audit and approvals, and the enterprise "Governance" module — so you understand who can do what, where, and why.

Chapter 10 — Governance & Permissions: the layer that guards the whole system

🏛 organizations and roles 🧩 gates and add-ons 🛡 two protection layers 📜 audit and approvals 🔐 account security and privacy
☰ Chapter index

01 Before we start

This is the closing chapter. After going through every module, we gather here the "layer" that guards the whole system: who you are (your organization and your role), what you see (the gates/add-ons), and what you are actually allowed to do (the protection in the database).

i
"Governance" in PZone ERP has two meanings: (1) the permissions system that governs all the modules — the subject of most of this chapter; and (2) the independent enterprise "Governance" module (board decisions, minutes and approvals — Section 7) that appears only if its add-on is enabled.
The active organization — the scope of everything Membership and role (per organization separately) Gates — add-ons (which modules appear) RLS — the guard in the database your data and your actions
Figure 1 — The nested governance layers: the active organization surrounds the role, the role passes through the gates (the add-ons), and at the heart RLS guards your data and your actions
!
A golden principle: hiding a button in the front end is not protection — the real protection is in the database (RLS). All the permissions you saw in the previous chapters are enforced by the database, not by the screen alone.

02 Organizations and membership

Everything in the system is owned by an organization. You may be a member of more than one organization, each with your own independent role.

The active organization
You can belong to several companies, and you switch between them from the company switcher at the top of the menu — and the selected one is the "active" one.
A role per organization
Your role is taken from your membership in the active organization — so you may be an owner in one company and a viewer in another.
The scope follows the active one
All the data, permissions and visible modules are confined to the active organization — you do not see the data of your other companies until you switch to them.
!
Switching the company changes everything at once: the role, the visible modules, the governance/rentals permissions, and the displayed data. Always make sure of the active company before working.

03 Roles

Five roles within the organization (plus "candidate" at the account level before joining). And the permission is built on the role.

Role Read Edit Delete Key permissions Owner✔✔✔legal identity · settings · permanent role Admin✔✔✔all administration and member permissions Manager✔✔✖editing content without deletion Recruitment officer✔✖✖inviting candidates and recruitment Viewer✔✖✖view only (read)
Figure 2 — The five roles and their permissions: reading for everyone, editing for the Owner/Admin/Manager, and deletion for the Owner/Admin only — with the highlight unique to each role
Owner
The highest role: all the Admin's permissions + exclusive privileges (the legal identity, company settings, the danger zone). Their role is permanent within the organization: it is not granted, transferred or ended between members (Section 4) — the only exception is a transfer or assignment carried out by the platform owner under their oversight (Section 9).
Admin
Full administration: editing, deletion, and managing members and roles.
Manager
Edits the operational content but does not delete, and does not manage members.
Recruitment officer · Viewer
The "recruitment officer" is like a viewer operationally but invites candidates and manages recruitment; and the "viewer" is view-only with no editing or deletion.
i
On top of the role, the Owner/Admin can grant an "authorized editor" to a specific member in the Governance and Rentals modules — so they can edit within them even if they are a viewer (the governance/rentals editors lists).

04 Members and invitations

Teams join by invitation, and their roles are managed from the Users page (HR center ← Users, for the admin).

Creation and ownership
Whoever creates the company becomes its owner — and this is the usual source of ownership. There is an exceptional path managed by the platform owner (transferring ownership, or assigning an owner to an "orphan" company with no owner, or approving a user's claim) — its details are in Section 9.
The invitation then the promotion
Every invitation is sent with the "viewer" role by force (the owner or recruitment officer invites); and after acceptance the admin promotes them to the appropriate role from "Users". No one can be invited directly as an admin/manager.
Changing roles
The admin switches roles among admin/manager/recruitment officer/viewer — and never touches the owner role at all (no promotion to it and no demotion from it).
Termination and resignation
The admin/owner ends a member's membership (and their tasks are reassigned), but an admin cannot end another admin, and the owner is neither ended nor resigns.
!
No ownership transfer between members within the organization: neither the owner nor the admin can transfer ownership to anyone. The only two ways to change it: deleting the whole company (company settings ← danger zone), or a transfer carried out by the platform owner under their oversight — see Section 9.

05 Gates and add-ons

Not all modules appear for every organization. "Gates" (add-ons) determine which modules are visible and available.

Permanent core modules
Projects · Monitor · Facilities · Library — always enabled for everyone.
Optional modules
Commercial (Pricing/Procurement/Warehouses/Tenders) · Reports · Finance · Technical office · Contracts · HR · Governance · Rentals — disabled by default and enabled when needed.
The gate works on two layers
It hides the menu item, and prevents opening the link (redirecting you to Projects) if the module is not enabled.
!
Enabling/disabling add-ons is in the hands of the "platform administrator", not the organization. Even the company owner does not enable their modules themselves — they request that from the platform administrator (the "Add-ons" panel). And "platform administrator" is a platform-wide permission, entirely different from the company "owner".

06 The two protection layers

Permissions are enforced on two layers: the front end (apparent) and the database (the real one) — and the second is the one that actually protects.

User Front end (client)module gate + hiding buttonsan apparent layer RLS — the databasethe scope + the rolethe real guard your data the standard rule: reading for any member · editing for admin/manager/owner · deletion for admin/owner. the platform administrator bypasses both layers — and the front end alone is not protection.
Figure 3 — Every request passes through two layers: the front end hides and disables (display convenience), and RLS in the database actually prevents or permits according to the scope and the role
The front-end layer
It hides the buttons and fields and disables them according to your role, and guards the routes (the gates). But it is a display convenience and courtesy, not protection.
The RLS layer
In the database: it enforces on every table that reading is for any member in the organization, and writing/deletion is according to the role — even if the API is called directly.
The standard rule
Reading for any member · editing for admin/manager/owner · deletion for admin/owner. And the "platform administrator" bypasses.

07 Settings, audit and governance

Where is governance set in practice? In the settings and administration pages, the audit log, the approvals, and the enterprise "Governance" module.

Company settings
The logo, name and manual profile, the legal identity (commercial register/tax card — for the owner only), the estimating and tax defaults, the e-invoicing data, and the danger zone (deleting the company).
Audit log
In Finance only: an immutable log that documents changes to entries, accounts and vendor invoices (who changed what and when), read by the owner/admin. There is no general activity log for the rest of the modules.
Approvals
Approval flows in Finance (amount limits and segregation of duties: whoever submits is not whoever approves) and in Governance (signatures and step-by-step approval).
PPropose RReview TRecommend AApprove EExecute MMonitor each step is signed by the holder of its permission in the "authority matrix" — approval by an unauthorized person does not suffice. the final approved decision has public verification via a QR code.
Figure 4 — The governance model cycle: propose ← review ← recommend ← approve ← execute ← monitor, with signatures of the permission holders, and a final decision that has public verification via QR
i
The enterprise "Governance" module (if enabled) manages governance models: board decisions, minutes, committee formation, the RACI matrix and the authority matrix, delegations, periodic reports, incentives and penalties, conflict of interest and confidentiality, related parties, and evaluations (individuals/entities/vendors) — all with approved steps and signatures, and public verification with the QR.

08 Account security and privacy

In addition to organization permissions, PZone ERP gives you tools to protect your personal account and control your privacy — you manage them yourself from My profile.

Two-factor authentication (2FA)
Enable two-step verification from My profile by scanning a QR code with an authenticator app (Google Authenticator / Authy…); afterward a 6-digit code is requested at every login. Optional, and you can disable it later with confirmation.
Public visibility is optional
Your public professional profile is no longer visible by default — it stays private until you enable its visibility yourself (opt-in), and you can reverse it at any time.
Sensitive documents with secure links
HR, medical and custody documents are opened via temporary links that expire after minutes, instead of permanent public links — so only the permission holder reaches them.
Consent and privacy
When creating an account you agree to the Terms of Service and the Privacy Policy (two public pages that open without signing in), and your consent is recorded in your profile.
Account deletion (the right to erasure)
From My profile ← danger zone, by typing DELETE to confirm: it removes you from all companies (and your assigned tasks are transferred to the owner of each company) then permanently deletes your account. A company owner? Delete the company first, or ask the platform owner to transfer its ownership (Section 9).
✓
These tools are an implementation of the personal data protection principle (Law 151/2020): clear consent, control over visibility, secure access to sensitive documents, and a right to erase your account.
!
A security tip: enable two-factor authentication especially for owner and admin accounts — it is the strongest protection if the password is leaked.

09 Platform owner: companies and ownership

Alongside the organization roles, the platform owner (not the company owner) holds special tools for managing company ownership across the whole platform — they appear on the Platform page under the Companies & ownership tab, and are visible only to the platform owner.

i
What is an "orphan company"? A company that exists in the system without an owner — created in an unusual way (such as an import or a pre-provisioning) rather than via "create company". No one can enter it as an owner until the platform owner assigns it an owner, or approves a claim to it.
Ownership transfer
The platform owner selects the company, then a new owner from its current members only (not from outside it). The previous owner automatically moves to the admin role — so the company is not left without administration. Every operation is recorded in the ownership events log.
Assigning an owner to an orphan company
In the Orphan companies section: the platform owner searches for the user by name or email, then assigns them as an owner of the orphan company — so it becomes an ordinary owned company.
Creating a protected company
The Create protected company button — at the top of the Orphan companies section — creates a company without an owner with a specified name and type. It reserves the name immediately so no one can register under it, until an owner is assigned to it or a claim to it is approved. And the system does not accept two identical names (after normalization), so two companies are not created with the same name.
Ownership claims
The Pending claim requests section shows everyone who tried to register under the name of a protected/orphan company. Each has its data (the name, email, phone and note) and two buttons: Approve (which makes them an owner of the company and rejects the rest of the claims on it) and Reject.
i
Ownership events log: every transfer, assignment or claim approval is recorded automatically (the event type · from whom · to whom · who carried it out · the time) in an immutable audit log — for complete tracing of each company's ownership history.
!
The name-reservation gate — from the user's side: if any user tries to create a company with a name matching an existing protected/orphan company, a new account will not be created; instead a pending claim request is recorded automatically and they see an amber notice stating that the request is under review. There is no separate button for the claim — the same creation attempt in Create company is what records the request. Then the platform owner reaches out and approves or rejects from the tab above.
✓
The reservation compares names after normalizing them (ignoring differences in spaces and letter case) so it cannot be circumvented with an extra space or a slight difference. And all these tools are protected in the database with the platform owner condition — hiding the tab is not enough.

10 Summary: who does what

A consolidated matrix of the system's key actions against the roles — it summarizes what we detailed across all the previous chapters:

ActionOwnerAdminManagerViewer
View the active organization's data (read)✔✔✔✔
Edit content (tasks · items · module records)✔✔✔✖
Deletion✔✔✖✖
Manage members and roles (promote/terminate)✔✔✖✖
Legal identity · company settings · danger zone✔✖✖✖
Enable/disable add-ons (modules)✖✖✖✖

"Recruitment officer" ≈ viewer + inviting candidates and recruitment. And "Owner" = admin + exclusive privileges (the legal identity, company settings, the permanent role). Enabling add-ons is in the hands of the "platform administrator" not the organization (hence all roles ✖). And the Owner/Admin can grant an "authorized editor" to a specific member in Governance and Rentals on top of their role. Reading and editing are confined to the active organization, and the real guard is RLS in the database not the hiding of buttons.

✓
Chapter Ten summary — and the manual's conclusion: Governance is the layer that makes everything before it safe and organized: an organization defines the scope, a role defines what you do, gates define what you see, and RLS guards everything deep down, with audit and approvals for accountability. With this the manual's journey through PZone ERP is complete — from the first project to the accounting entry to the governance that protects everyone. 🏛