Security Model
- Role-based permissions control page access and API behaviour.
- Tenant scoping keeps each organisation’s data separated, enforced at the database layer.
- Client portal access is additionally constrained to the granted client relationship.
- Server-side code performs sensitive operations such as export delivery, billing sync, AI calls, and PDF generation.