Who gets in and what they can do
Users organized into groups with granular privileges. Each person sees and modifies only what their role allows — by module, by action, and even by branch.
Adm Cloud protects your data with enterprise-grade security: decide who gets in, what each person can see and do, and keep a record of everything. Multi-factor authentication, strong passwords, access control by day, time and IP, and an audit log that leaves nothing untracked.
Adm Cloud security is not a separate module: it accompanies every screen and every operation. It is organized into three fronts that work together to protect your information.
Users organized into groups with granular privileges. Each person sees and modifies only what their role allows — by module, by action, and even by branch.
Multi-factor authentication, complex passwords with periodic renewal, and access control by day, time and IP. Only the right people get in, from where they should.
An audit log records who did what, when and from where — with the values before and after every change. Nothing is lost and everything is traceable.
From user management to real-time threat monitoring. These are the controls that protect your Adm Cloud, all manageable from within the system itself.
Manage your company's users, invite them by email and control their status. The same user can belong to several companies with different roles.
UsersMulti-companyOrganize people into groups (roles) and define their permissions, data scope and security behavior in a single place.
User GroupsAdministratorGrant access by module and by action: view, create, edit, delete, authorize and void. Authorize and void are independent permissions.
View · Create · EditAuthorize · VoidBeyond permissions, control which menu options and which custom forms and reports each user group can see.
Menu accessForms and reportsSecond factor via authenticator app (TOTP) or a one-time code by email. It can be required for an entire user group.
Authenticator app (TOTP)Code by emailMandatory strong passwords, no reuse of the previous one, and periodic renewal. They are stored encrypted, never in plain text.
Minimum 10 charactersRenewal every 180 daysDefine for each employee which days of the week and within which time window they can sign in. Outside that range, access is blocked.
Allowed daysTime windowLimit which IP addresses or ranges each employee can connect from, with an additional layer of firewall rules at the database.
Allowed IP rangeDatabase firewallEvery creation, change, deletion, authorization or void is recorded with user, date, screen, and the before-and-after values.
Before-and-after valuesGeolocationLogs every sign-in attempt with IP, country and device. Blocks high-risk countries, detects impossible travel and checks IP reputation.
Country blockingIP reputationAfter repeated password attempts, the system warns and locks the account, notifying by email. Only one active session per user is allowed.
Lockout after several attemptsSingle sessionEach company lives in its own database, isolated from the rest. Within the company, data is scoped by branch, location and employee.
Database per companyBy branch and locationUsers, groups and privileges work in layers to give you fine-grained control without complexity. You define the permission once at the group level and it applies to everyone in that role.
Permissions are assigned per group and drill down to the detail: which modules, which actions and over which data. That way you separate duties and reduce the risk of errors and fraud.
Sales, purchasing, accounting, inventory, payroll… each area is enabled separately.
View, create, edit, delete, authorize and void: six independent levels.
Limit what each role sees by branch, location and employee, even within the same company.
| Module | View | Create | Edit | Del. | Auth. | Void |
|---|---|---|---|---|---|---|
| Quotes | ||||||
| Invoicing | ||||||
| Accounts receivable | ||||||
| Accounting |
On top of permission control comes a second wall: how, when and from where users can sign in. Multiple layers you can combine to match your company's level of rigor.
Add a second factor with an authenticator app (time-based TOTP code) or a one-time code sent by email. The administrator can require MFA for an entire user group; the trusted device skips the step for 7 days.
Passwords require a minimum of 10 characters with uppercase, lowercase and numbers, cannot repeat the previous one, and are renewed every 180 days. They are stored encrypted, and every change is notified to you by email with the originating IP and device.
Define for each employee which days of the week and within which time window they can sign in. An attempt outside the schedule or on a non-allowed day is rejected automatically, evaluated against the company's time zone.
Allow access only from the IP addresses or ranges authorized for each employee — for example, the office network — with an extra layer of firewall rules at the database level.
After several failed password attempts, the account is locked and a notification is sent by email. The system blocks high-risk countries, detects simultaneous sign-ins from different countries (impossible travel) and checks the reputation of every IP.
Only one active session per user: if another one opens on a different device, the previous one is closed. Password recovery links are single-use and expire within minutes.
The audit log records every operation with the level of detail that management and formal reviews demand. If something changed, you will know who, when, from where and what was there before.
Every event — creation, edit, deletion, authorization, void or status change — is documented with its full context, ready to review or export whenever you need it.
In just a few steps you define who gets in, under which rules and with what oversight. All from within Adm Cloud itself.
Invite each person by email. The same user can work in several companies, each with its own role.
Define roles such as Sales, Accounting or Administrator. Mark which ones are administrators and what data scope they have.
Set, by module and action, what each group can view, create, edit, delete, authorize or void, plus their menus and forms.
Require MFA for the groups that need it and define each employee's allowed days, schedules and IPs for signing in.
Review the audit log and the security report to check access, changes and potential risks at any time.
Control, traceability and real protection, with no need for external tools or dedicated technical staff.
The audit log and the audit report give you the traceability that management and formal reviews demand.
Segregation of duties — authorize and void as separate permissions — prevents a single person from controlling the entire process.
MFA, IP and schedule control, attempt-based lockout and threat monitoring shut the door on unauthorized access.
You define who sees and does what, and adjust it whenever you need to, without depending on third parties or programming.
Yes. Permissions are assigned per user group and are granular: for each module you define whether the group can view, create, edit, delete, authorize or void. Authorize and void are independent permissions, and you also control which menus, forms and reports each group can access.
You can use an authenticator app that generates a time-based code (TOTP) or receive a one-time code by email. The administrator can require MFA for an entire user group. Once verified, the device becomes trusted and the second factor is not requested again for 7 days.
Every creation, edit, deletion, authorization, void or status change, with the responsible user, the date and time, the screen and the document, the before-and-after values of every modified field, and the origin of the access (IP, country, device and geolocation). It also records whether the action came from the user interface, the API or the online store.
Yes. For each employee you can define the days of the week and the time window in which they can sign in, as well as the allowed IP addresses or ranges. Any attempt outside those rules is rejected automatically.
Passwords must be at least 10 characters long with uppercase, lowercase and numbers, cannot repeat the previous password, and are renewed every 180 days. They are always stored encrypted, and every change is notified to you by email with the originating IP and device.
After several failed attempts the system warns and then locks the account, sending an email notification with the device details. On top of that come high-risk country blocking, detection of simultaneous sign-ins from different countries, and IP reputation checks.
Yes. Each company resides in its own database, isolated from the rest. Within the same company, access to information is further scoped by branch, location and employee according to the user group.
Access control, robust authentication and complete auditing, built into the same ERP that already runs your operation.