Tenant isolation
Organization operational databases remain separate from the platform control database and from other organizations.
FIXMANOrganization Operations PlatformSECURITY & GOVERNANCE
FIXMAN separates platform administration from organization operations and combines server-side permissions, audit-sensitive workflows, tenant encryption and controlled synchronization.
Organization operational databases remain separate from the platform control database and from other organizations.
Modules and actions are enforced server-side. Hiding a menu item is not treated as the security boundary.
Important configuration, workflow and administrative changes are recorded for traceability.
Supported controlled payloads use tenant-specific application key material. Existing keys must be preserved during upgrades.
Fingerprint, face or iris templates remain on the external biometric system/device. FIXMAN receives mapped attendance events, not biometric templates.
The server remains authoritative. Offline capability is limited and replay uses idempotency/version controls rather than creating a separate master database on devices.
The Platform Control Plane is designed to receive operational aggregates and supervision data. Detailed employee location evidence belongs in the organization tenant context.