Skip to main content
SOLUTION

Permissions and stock scoped by location, enforced at the database

For businesses operating more than one location, AccountDesq scopes stock, registers, and staff permissions per branch or warehouse - enforced by Postgres row-level security in addition to the application layer - while still giving owners and managers an aggregated view across every location, and Entity Groups for consolidating across separate legal entities entirely.

Get started free

The problem

As a business adds locations, access control usually becomes an afterthought - either everyone can see everything, or the business resorts to separate logins or spreadsheets per site, neither of which gives accurate real-time visibility or genuinely stops staff at one site from seeing another's data.

How AccountDesq fits

Branch and Warehouse are modeled as distinct, first-class entities. A member-scopes system determines what each staff member can see and act on per warehouse, branch, or POS register, and that restriction is enforced by Postgres row-level security, not just hidden in the UI - so it holds even if application code is bypassed. Stock transfers between locations are a tracked workflow, and for businesses running multiple separate legal entities, Entity Groups provide consolidated reporting with intercompany elimination on top of the per-location scoping.

app.accountdesq.com
Two branches, two warehouses - each a real, scoped entity, not a shared location field.

How it works, step by step

  1. Model your footprint

    Set up each branch and warehouse to match your actual locations.

  2. Scope access per location

    Assign staff to the specific warehouses, branches, or registers relevant to their role.

  3. Operate locally, see globally

    Each location's staff work within their own scope; owners and managers see aggregated data across all locations.

  4. Consolidate across entities

    If locations are run as separate legal entities, Entity Groups consolidate their financials with intercompany elimination.

Connected to the rest of AccountDesq

Nothing here works in isolation - it posts through the same ledger as everything else.

In practice

A regional retail chain with locations run as separate legal entities for local compliance uses per-warehouse scoping for day-to-day staff access at each store, and groups all entities together at quarter-end through Entity Groups to see consolidated results - with intercompany stock transfers between locations eliminated correctly instead of double-counted.

What this means for your business

  • Location-based access restrictions that actually hold, enforced at the database layer, not just the UI.
  • Owners and managers get an aggregated view without giving every staff member visibility into every location.
  • A genuine path to consolidated reporting if locations are structured as separate legal entities.

Frequently asked questions

Is location-based access control enforced at the database level?

Yes - in addition to application-layer permission checks, Postgres row-level security enforces the same scoping, so the restriction holds even if app code is bypassed.

Can I consolidate reporting across multiple legal entities?

Yes, through Entity Groups, which span multiple workspaces and produce consolidated statements with intercompany elimination.

Related pages