Module: Platform & Technology Prerequisites: Admin rights in InnoVisions; for self-hosting, a server with Docker

Overview

This guide explains how InnoVisions is built and how to look after it. It covers the three parts the system runs on, how each company's books are kept apart, users and permissions, the audit trail, the REST API and the optional AI assistant. It ends with what the person running the server must set up before go-live.

How the System Is Built

1
Three Docker containers

InnoVisions runs as three containers started with Docker Compose: a MySQL 8 database, a FastAPI (Python) backend and a Next.js web frontend. One command builds and starts all three: docker compose up -d --build.

2
One database per company

Each company (tenant) has its own MySQL database for its books. A separate platform database holds users, companies and company groups. One company's figures never sit in another company's database.

3
Schema updates at start-up

When the backend starts, it creates any new tables and adds any missing columns to existing tables. It only adds; it never drops a column. There is no separate migration tool to run.

PartTechnologyRole
DatabaseMySQL 8One database per company, plus a platform database
BackendFastAPI (Python)Business rules, ledger posting, REST API
FrontendNext.js (TypeScript)The web screens staff use in the browser

Companies, Users and Access

1
One login across group companies

A user can have access to more than one company with a single login. The company switcher moves between them. Each company's admin decides who may enter that company.

2
Add users

Go to Settings → Users to add staff and set their role. Only users with the user-management permission see this screen.

3
Set permissions

Go to Settings → Access to control what each role may do. Menu items and actions such as approvals or report exports follow these permissions.

4
Customer portal users

Go to Settings → Portal Users to give customers access to the customer portal, where they can see their documents and statements. Portal payments come in through a payment-gateway webhook that is checked with a signed (HMAC) message.

Passwords

Passwords are stored as bcrypt hashes, never as plain text. Login attempts are limited to 10 a minute from one IP address. There is no "forgot password" link for staff yet. An admin resets a password in the app, or on the server with the script scripts/set_password.py.

Audit Trail

1
Open the audit trail

Go to Settings → Audit Trail. Only admins with the user-management permission can open it.

2
Read an entry

Every change made through the system is logged: who made it, when, from which IP address, which endpoint was called and the data that was sent. Search by user email and filter by date.

What the log does not hold

The audit trail records the data sent with each change. It does not store the value a field had before the change.

REST API

1
Read the API docs

Every screen works through the same REST API. Interactive OpenAPI documentation is at /api/docs on the backend. Calls use the same login and permissions as the screens.

2
Check that the backend is up

GET /health answers when the backend is running. Use it for a simple up-check from your own monitoring tool.

AI Assistant (Optional)

1
Turn it on only if you want it

The assistant is under ERP → AI Assistant. It works only when an OpenAI API key is set on the server. Without a key, no questions leave your server.

Data leaves your server

With a key set, questions typed into the assistant are sent to OpenAI. Check this against your POPIA duties and company policy before you switch it on.

Quality Checks on Every Change

A GitHub Actions pipeline runs on code changes. It runs the backend test suite, and the frontend tests, lint and type check. A change that breaks these checks shows as failed before it is released.

Recommended for the Server Operator

These are not built-in features. They are tasks for the person or company that runs the server, and they should be done before go-live.

1
Daily database backup with a tested restore

InnoVisions does not make backups by itself. Back up every company database and the platform database each day, keep copies off the server, and test a restore regularly.

2
HTTPS in front of the app

Put a web server or reverse proxy with a valid certificate in front of the frontend and backend, so that logins and data travel encrypted over the internet.

3
Production start command

The backend container starts with the development --reload setting. Change it to a production start command for live use.

4
Keep secrets out of shared places

The .env file holds the system's secrets and is not kept in Git. Copy it by hand to the server and never paste it into email, chat or another tool.

Tip

After every rebuild, open /api/docs and download one invoice PDF. If both work, the backend and its PDF libraries are running.

Related Modules