Store Operation Security

Store controls protect financial data, company-owned references, and uploaded files from unauthorized use.

Separation of loyalty and points duties

The system separates loyalty viewing, settings updates, and manual customer-points adjustments, so read access does not grant financial-change authority.

  • The owner receives the full available capability set.
  • Restricted roles do not automatically receive financial-change capabilities.

Company data isolation

The system verifies that references used in administrative changes belong to the same company and checks record ownership before modification.

  • Countries and governorates remain shared global references.
  • References owned by another company are rejected.

Upload controls

The legacy generic upload facility is reserved for authorized ERP staff and validates file type, size, and folder before storage.

  • Accepted types include common images, PDF documents, plain text, and comma-separated data.
  • The limit is ten megabytes per file and ten files per multi-upload.
  • Storage and deletion paths are contained within the company's scope.

Resource image uploads

From administrative screens, images are uploaded with the owning resource's creation or update instead of relying on generic uploads.

  • This ties the file directly to the record that uses it.