Security

Roles & audit

Seven fixed roles, per-yard permission tuning, two-factor authentication and an audit trail of who changed what.

At a glance

Plan
All plans
Last updated
September 2, 2026

What this covers

Who on your team can see and do what — and, afterwards, the record of who actually did it.

How it works in ELVPro

Seven roles, one shape

Owner, administrator, inventory manager, sales, content, accountant and viewer. Each starts from a least-privilege set: the accountant sees invoices but not the customer inbox; the viewer changes nothing.

Tunable inside your yard

The owner can adjust what each role may do in their own yard without affecting anyone else. The owner role itself is fixed, so a permission edit can never lock a yard out of its own account.

Checked on the server, every time

Permissions are enforced at the resource, not by hiding a button, and every query is additionally scoped to the yard that owns the record — so one yard cannot reach another's data even by guessing an id.

Two-factor authentication

Mandatory for ELVPro platform staff. Your yard can require it for everyone or for named users; recovery codes are issued at enrolment, and an administrator can reset someone who has lost their authenticator.

Session hygiene

Idle sessions expire, the screen can be re-locked, and revealing or changing stored credentials asks for the password again.

An audit trail

Model changes are logged with the actor, the fields and their before/after values. Yard-lifecycle events — suspension, archiving, deletion — go to a separate, immutable trail. API calls and payment-processor exchanges keep their own logs, with secrets redacted.

When it happens

When this runs, and what it does
When What happens
On every request authorisation and yard scoping.
At login two-factor, wherever it is required.
On every change the audit entry is written in the same transaction as the change it describes.
On lifecycle events the immutable trail, which nothing in the interface can rewrite.

Why it matters

Most data incidents are not break-ins; they are ordinary accounts able to do more than they needed to. Least privilege limits what a mistake or a stolen password can reach, and an audit trail is what lets you answer "when did this price change, and who changed it?" — which GDPR Article 5(2) expects you to be able to do.

Questions about security or compliance?

We will gladly walk you through how ELVPro handles your data — or fill in your compliance questionnaire.