Platform
One connected control layer
Request management, workflow, risk, control, policy, audit, and reporting share one workflow, notification, and audit engine — configurable per sector, not forked per customer.
Platform architecture
Users and connected systems reach the platform through a common API layer. Every domain module — request, workflow, approval, risk, control, policy, and audit — shares the same identity, tenancy, and platform services beneath it.
Architecture, top to bottom: Users and connected systems → Marketing / Company Portal / APIs → Identity, Tenant and Access Services → Request, Workflow, Approval, Risk, Control, Policy, Audit → Notifications, Files, Search, Reporting, Integration → MongoDB, Blob Storage, Messaging and Monitoring.
Request and workflow lifecycle
- 1
Capture the business request
- 2
Validate policy, risk, control, and evidence
- 3
Route to the correct authority
- 4
Record approval, rejection, clarification, or escalation
- 5
Return the decision and retain an immutable history
Modules
Request Management
Capture business actions — financial, procurement, production, legal, vendor, safety — as structured, auditable requests instead of emails and spreadsheets.
Workflow & Approvals
Route every request through the correct approval chain automatically, based on sector, action type, amount, and configured risk conditions.
Digital Signatures & Audit Trail
Bind every approval or rejection to a verified identity, timestamp, and the specific request version being decided on.
Risk Management
Maintain a risk register with inherent and residual scoring, treatments, and appetite thresholds, tied directly to the requests and controls they affect.
Control Library
A reusable catalogue of control objectives, activities, evidence requirements, and test procedures — the same library the finance audit checklist is built from.
Policy Management
Version, approve, and publish the policies and SOPs that requests and controls are reviewed against.
Audit & Assurance
Plan audit work, run control tests, and keep working papers, samples, and recommendations in one traceable record.
Findings & Remediation
Track issue severity, root cause, owners, due dates, and verification through to closure — so findings don't quietly go stale.
Notifications
Keep every party informed in real time across in-app, email, and WhatsApp — with rejections and escalations always sent on every channel.
Reporting & Analytics
Operational dashboards for units and the audit team, plus enterprise-wide executive views — all with drill-down into the underlying requests.
Integrations
Connect to ERP, finance, procurement, and HR systems so requests can originate from — and decisions flow back to — the systems of record, without replacing them.
Shared platform services
- Identity & Tenancy
- SSO, tenant context, and role-based access shared across every module.
- Notifications
- In-app, email, and WhatsApp delivery with retries and delivery tracking.
- Files
- Evidence storage with malware scanning and configurable retention.
- Search
- Cross-entity search over authorised, tenant-scoped projections.
- Reporting
- Pre-aggregated dashboards with drill-down into the underlying requests.
- Integration
- REST/JSON APIs and webhooks for ERP and other enterprise systems.
Integration approach
The platform connects to ERP, finance, procurement, and HR systems through documented REST/JSON APIs and webhooks — creating requests from source-system transactions and pushing final decisions back to the originating record. It does not replace those systems as the system of record.
Learn more about Integrations →Reporting
Unit, audit, and executive dashboards with drill-down into the underlying requests and audit trail.
Explore Reporting →Deployment portability
The same platform runs as shared SaaS, dedicated private cloud, or on customer-managed infrastructure.
Compare deployment models →Security
SSO, MFA, segregation of duties, encryption, and a tamper-evident, append-only audit trail.
Read Security & Trust →