The problem
As a business adds locations, access control usually becomes an afterthought - either everyone can see everything, or the business resorts to separate logins or spreadsheets per site, neither of which gives accurate real-time visibility or genuinely stops staff at one site from seeing another's data.
How AccountDesq fits
Branch and Warehouse are modeled as distinct, first-class entities. A member-scopes system determines what each staff member can see and act on per warehouse, branch, or POS register, and that restriction is enforced by Postgres row-level security, not just hidden in the UI - so it holds even if application code is bypassed. Stock transfers between locations are a tracked workflow, and for businesses running multiple separate legal entities, Entity Groups provide consolidated reporting with intercompany elimination on top of the per-location scoping.
How it works, step by step
Model your footprint
Set up each branch and warehouse to match your actual locations.
Scope access per location
Assign staff to the specific warehouses, branches, or registers relevant to their role.
Operate locally, see globally
Each location's staff work within their own scope; owners and managers see aggregated data across all locations.
Consolidate across entities
If locations are run as separate legal entities, Entity Groups consolidate their financials with intercompany elimination.
Connected to the rest of AccountDesq
Nothing here works in isolation - it posts through the same ledger as everything else.
In practice
A regional retail chain with locations run as separate legal entities for local compliance uses per-warehouse scoping for day-to-day staff access at each store, and groups all entities together at quarter-end through Entity Groups to see consolidated results - with intercompany stock transfers between locations eliminated correctly instead of double-counted.
What this means for your business
- Location-based access restrictions that actually hold, enforced at the database layer, not just the UI.
- Owners and managers get an aggregated view without giving every staff member visibility into every location.
- A genuine path to consolidated reporting if locations are structured as separate legal entities.
Frequently asked questions
Is location-based access control enforced at the database level?
Yes - in addition to application-layer permission checks, Postgres row-level security enforces the same scoping, so the restriction holds even if app code is bypassed.
Can I consolidate reporting across multiple legal entities?
Yes, through Entity Groups, which span multiple workspaces and produce consolidated statements with intercompany elimination.