Platform & Technology
How InnoVisions is built and run: Docker containers, a database per company, users and access, the audit trail, the REST API, the optional AI assistant and what the server operator should set up.
Overview
This guide explains how InnoVisions is built and how to look after it. It covers the three parts the system runs on, how each company's books are kept apart, users and permissions, the audit trail, the REST API and the optional AI assistant. It ends with what the person running the server must set up before go-live.
How the System Is Built
InnoVisions runs as three containers started with Docker Compose: a MySQL 8 database, a FastAPI (Python) backend and a Next.js web frontend. One command builds and starts all three: docker compose up -d --build.
Each company (tenant) has its own MySQL database for its books. A separate platform database holds users, companies and company groups. One company's figures never sit in another company's database.
When the backend starts, it creates any new tables and adds any missing columns to existing tables. It only adds; it never drops a column. There is no separate migration tool to run.
| Part | Technology | Role |
|---|---|---|
| Database | MySQL 8 | One database per company, plus a platform database |
| Backend | FastAPI (Python) | Business rules, ledger posting, REST API |
| Frontend | Next.js (TypeScript) | The web screens staff use in the browser |
Companies, Users and Access
A user can have access to more than one company with a single login. The company switcher moves between them. Each company's admin decides who may enter that company.
Go to Settings → Users to add staff and set their role. Only users with the user-management permission see this screen.
Go to Settings → Access to control what each role may do. Menu items and actions such as approvals or report exports follow these permissions.
Go to Settings → Portal Users to give customers access to the customer portal, where they can see their documents and statements. Portal payments come in through a payment-gateway webhook that is checked with a signed (HMAC) message.
Passwords are stored as bcrypt hashes, never as plain text. Login attempts are limited to 10 a minute from one IP address. There is no "forgot password" link for staff yet. An admin resets a password in the app, or on the server with the script scripts/set_password.py.
Audit Trail
Go to Settings → Audit Trail. Only admins with the user-management permission can open it.
Every change made through the system is logged: who made it, when, from which IP address, which endpoint was called and the data that was sent. Search by user email and filter by date.
The audit trail records the data sent with each change. It does not store the value a field had before the change.
REST API
Every screen works through the same REST API. Interactive OpenAPI documentation is at /api/docs on the backend. Calls use the same login and permissions as the screens.
GET /health answers when the backend is running. Use it for a simple up-check from your own monitoring tool.
AI Assistant (Optional)
The assistant is under ERP → AI Assistant. It works only when an OpenAI API key is set on the server. Without a key, no questions leave your server.
With a key set, questions typed into the assistant are sent to OpenAI. Check this against your POPIA duties and company policy before you switch it on.
Quality Checks on Every Change
A GitHub Actions pipeline runs on code changes. It runs the backend test suite, and the frontend tests, lint and type check. A change that breaks these checks shows as failed before it is released.
Recommended for the Server Operator
These are not built-in features. They are tasks for the person or company that runs the server, and they should be done before go-live.
InnoVisions does not make backups by itself. Back up every company database and the platform database each day, keep copies off the server, and test a restore regularly.
Put a web server or reverse proxy with a valid certificate in front of the frontend and backend, so that logins and data travel encrypted over the internet.
The backend container starts with the development --reload setting. Change it to a production start command for live use.
The .env file holds the system's secrets and is not kept in Git. Copy it by hand to the server and never paste it into email, chat or another tool.
After every rebuild, open /api/docs and download one invoice PDF. If both work, the backend and its PDF libraries are running.
Related Modules
Compliance & Governance
Use the audit trail and role permissions to show who changed what and when.
Financial Management
Each company keeps its own books; group reports combine them across the companies you choose.
CRM & Sales
Customer portal users are set up under Settings and see their own documents and statements.
HR & Payroll
HR and payroll screens follow the same role permissions and audit trail as the rest of the system.