+1-905-282-9675 query@smartmilestones.com
Select Page

SM Space · Security & Access Control

User Access Control and Security for Your ERP

SM Space has user access control down to individual fields: someone who is not cleared for a salary column does not see it on the screen, in a report, or through the built-in AI assistant. Two-factor sign-in, sign-in with Google or Microsoft, and rules stopping one person holding two jobs that should not be combined are all built in.

The controls sit underneath the product rather than on the screens — so a report, an export, an integration and the assistant all get the same answer the screen does.

Last updated: September 2026

Two people, one record

Employee record · A. Kelo

HR manager

  • NameA. Kelo
  • DeptOperations
  • Salary72,000
  • SIN••• ••• 214
  • Start04 Mar 2024

Site supervisor

  • NameA. Kelo
  • DeptOperations
  • Start04 Mar 2024

no gaps, no blanked rows — the list is just shorter

Off means off

R. Vance · 192.0.2.44

  • 09:14signed inChrome
  • 09:15deactivatedby D. Whitfield
  • 09:15session endedsame minute

reporting ✗export ✗integration ✗

not at the end of the hour their token had left

Each fine, together not

a rule you could not write down before

Raise requisition Approve purchase order

  • M. Duarteholds both⚠ 1 violation
  • S. Okaforholds one
  • R. Singhholds one

New grant to R. Singh ✗ refused

unless a waiver is recorded, with who approved it and when it runs out

The key changes

without taking the system down

  • Key 2024-Ain use
  • Key 2026-Baddedboth readable

Moving values… 1,284 of 4,902

Key 2024-A retired · the system stayed up

each value records which key sealed it, so nothing has to be guessed

Above: the same employee record seen by two people, where the one without clearance simply has no salary or identifier fields; a user being deactivated and the session they were sitting in front of ending in the same minute, closing reports, exports and the interface at once; a rule saying two permissions may never be held together, finding the one person who already holds both and refusing a new grant without a recorded waiver; and an encryption key being replaced while the system stays running.

What you can do

  • Control access down to individual fields, not just screens
  • See who is signed in right now, from where, and end a session yourself
  • Deactivate someone and have the sessions they are holding end with them
  • Turn on two-factor sign-in, with ten single-use recovery codes
  • Let people sign in with their Google or Microsoft account
  • Set your own password rules, and force a change when you need to
  • Have an account lock itself after repeated failed sign-ins
  • Bring your users in from Microsoft 365 or Google Workspace instead of typing them in
  • Give integrations their own service accounts, separate from people
  • Write down which permissions may never be held by the same person
  • Find everyone who already holds a combination you have just banned
  • Record a waiver with who approved it, why, and the date it runs out
  • Replace the encryption key protecting stored secrets, while the system keeps running

01

Sessions End When Access Does

Switching someone off should switch them off. In most systems it takes effect the next time they try to sign in, which is not the moment anybody has in mind when they click it.

This was our own bug, and it is the reason the module exists. A token lasted an hour and carried the roles it was issued with, so an administrator who deactivated somebody the minute they were dismissed had, in fact, done nothing for the next sixty minutes.

Now deactivating a person ends the sessions they are holding. R. Vance signs in at 09:14 from 192.0.2.44; at 09:15 D. Whitfield deactivates the account, and the session R. Vance is sitting in front of stops answering — reports, exports and the interface an integration uses, all at once.

Being exact about “immediately”, because a reviewer will ask. The check runs against a short cache, thirty seconds by default, so it takes effect within seconds rather than on the same instant. Set that to nought and every request is checked. Either way it is seconds, not the rest of an hour.

You can also see who is signed in right now, from which address, and end any one of those sessions on its own. Every sign-in and sign-out is kept, failures included, and the record says how each session ended — signed out, timed out, ended by an administrator, blocked, deactivated, or ended by a password change.

Signed in now · 2 sessions
  • R. Vance 192.0.2.44 Chrome · Windows ended
  • S. Okafor 198.51.100.17 Firefox · macOS active
  1. 09:14 R. Vance signed in 192.0.2.44
  2. 09:15 Deactivated by D. Whitfield reason recorded
  3. 09:15 Session ended the same minute
  • Reporting
  • Export
  • Integration
  • AI assistant

The check runs off a short cache — thirty seconds by default, and you can set it to nought and have every request checked. Seconds, either way, rather than the rest of an hour.

R. Vance signs in at 09:14 from 192.0.2.44. At 09:15 D. Whitfield deactivates the account and the session ends in the same minute — reporting, export and the integration interface with it.

02

Segregation of Duties

Every access screen ever built asks one question: does this person need this? Nobody is asked whether they need it together with what they already hold.

Raise a purchase requisition is reasonable. Approve a purchase order is reasonable. One person holding both is a way to pay themselves, and in most products nothing has an opinion about it — not because the administrator was careless, but because they answered the only question the form asked.

You can write that down here: these two things may not be held by the same person. Turning the rule on strips nothing from anybody. It scans, and it tells you who already holds both — M. Duarte does; S. Okafor and R. Singh hold one side each. The next attempt to give R. Singh the other half is refused as it is saved, naming the rule, both sides, and the grant already in the way, so the administrator knows which to take off.

You choose how hard each rule pushes. A blocking rule refuses the save. A warning rule lets it through and records the violation — for conflicts a business wants visible but does not want stopping work at five o’clock on a Friday. Somebody with a live waiver passes either quietly, and the waiver records who approved it, why, and the date it runs out.

One boundary, because it is what a good reviewer asks next. This is about standing access: what a person may do at all. It does not check, when a purchase order is approved, whether this same person raised that particular one. That check is specified and not built.

Rule · may not be held together

Raise a purchase requisition Approve a purchase order

Checking everyone who already has access…

  • M. Duarte holds both 1 violation
  • S. Okafor holds one clear
  • R. Singh holds one clear

A new grant

refused R. Singh already has “Raise a purchase requisition” — remove that one first

Where the business needs an exception

  • Waiver forT. Brennanone person, one rule
  • Approved byJ. Sørensenrecorded, not routed
  • Runs out31 Dec 2026then the rule applies again

Turning the rule on took nothing away from anybody. It scanned, and it told you about M. Duarte.

The rule is written down, then checked against everyone who already has access: M. Duarte holds both, S. Okafor and R. Singh hold one side each. The next grant to R. Singh is refused, naming the permission already in the way.

03

Field-Level Permissions

Permissions here go down to individual fields, and the part that matters is what hidden means.

Open one employee record as two people. The HR manager sees the name, the department, a salary of 72,000, a partly hidden identifier and a start date. The site supervisor sees the name, the department and the start date. Not a blanked row, not a line of asterisks, not a greyed-out box — a shorter list, with nothing to notice.

A field somebody is not cleared for is absent from the screen, from the reports they can build, and from the AI assistant — not blanked out. Reporting leaves it out of the fields you can choose, refuses a report that names it, and drops it from results. The column is stripped from the description of your data before the assistant is ever handed one, so there is no clever way to ask for it. And through the interface an integration uses, the value does not come back.

That last one matters more each year. A permission that only applies to screens is one that every new way of asking walks around — and a report, an export and an assistant are three new ways of asking.

Employee record · A. Kelo

HR manager sees

  • NameA. Kelo
  • DepartmentOperations
  • Salary72,000
  • SIN••• ••• 214last three only
  • Start date04 Mar 2024

Site supervisor sees

  • NameA. Kelo
  • DepartmentOperations
  • Start date04 Mar 2024

Three rows, not five with two crossed out.

  • On the screenthe field is not drawn
  • In reportingnot in the fields you can choose; a report naming it is refused
  • To the AI assistantthe column is removed before it is shown your data
  • Through an integrationthe value does not come back

A permission that only applies to screens is a permission that every new way of asking walks around.

The same record, two people. The HR manager sees a salary of 72,000 and a partly hidden identifier. The site supervisor sees three rows — not five with two crossed out.

04

Encryption and Key Rotation

Sensitive values are encrypted where they are stored: the connection to each tenant’s database, every two-factor seed, the Google, Microsoft and directory credentials, outbound email passwords, storage keys and access tokens, passport and permit numbers, and social insurance numbers.

The part worth saying out loud is that the key protecting all of it can be replaced. Each stored value carries a note of which key sealed it, so a new key is brought in and the old values moved across while both keys stay readable and the system keeps serving. Nothing has to know in advance which value used which key.

Most products our size encrypt under one key from one setting, with no way to ever change it. That is fine until the day it is not.

Two honest details. A rotation is a command run by whoever operates the deployment, not a button on your screen. And a backup restored from before a rotation still needs the key it was written with, so the old key is kept until every restore point that needs it has gone.

Encryption keys
  • Key 2024-A retired kept — an older backup still needs it
  • Key 2026-B in use new values are sealed with this one

Moving values across

1,284 of 4,902

both keys stay readable · the system stays up

  • Tenant database connections
  • Two-factor seeds
  • Google & Microsoft credentials
  • Email passwords
  • Storage keys and tokens
  • Passport and permit numbers
  • Social insurance numbers

A rotation is a command run by whoever operates the deployment, not a button on your screen. Each value records which key sealed it, so nothing has to know in advance which key it needs.

Key 2026-B is added beside 2024-A, 1,284 of 4,902 values have moved across, and both keys stay readable while it runs. The old key is kept, because a backup taken before the rotation still needs it.

How SM Space user access control compares

The one-line answers a reviewer asks for, and then the part that matters more — what it does not do.

  • Field-level permissions Down to a single column, not just a screen.
  • One place, every surface The screen, reports, exports and the assistant get the same answer.
  • Segregation of duties Write down which permissions may never be held together.
  • Existing holders found Turning a rule on scans everyone. It reports; it does not strip.
  • Two-factor sign-in An authenticator app or a mailed code, with ten single-use recovery codes.
  • Single sign-on Google and Microsoft.
  • Directory import Pull your users from Microsoft 365 or Google Workspace.
  • Session control See who is signed in, from where, and end a session.
  • Password policy Your own length and complexity rules, expiry, and a forced change.
  • Automatic lockout After repeated failed sign-ins, with no one watching.
  • Service accounts An identity for an integration, with no mailbox and no seat.
  • Encryption at rest Named columns sealed with a key that can be replaced while the system runs.
  • Full audit trail Who changed what, and who signed in when.
  • Cloud Runs in a web browser, nothing to install.

What it does not do. Four limits, because a security page that lists only capabilities is the one nobody believes.

Hiding a column stops its value being returned. It is not a defence against somebody deliberately testing values against a list to see which ones match — on an ordinary list screen a hidden column can still be filtered on. The assistant’s own search already refuses that; closing it everywhere else is a change to every screen in the product.

Segregation of duties is about standing access, not a single document. It stops one person holding two conflicting permissions and finds who already holds both. It does not check, when a purchase order is approved, whether this same person raised that particular one.

Directory import does not sync by itself. Somebody disabled in your directory keeps an open SM Space account until an administrator runs a re-check — they cannot sign in, because your identity provider will not issue them a token, but the account is open.

SM Space holds no security certification and claims none. Everything on this page is a mechanism you can check on a demo, not an assurance we are in a position to give.

How it fits with the rest of SM Space

These are not controls bolted onto screens. Roles are built from menu access, so a permission is a real place in the product rather than a string somebody typed, and field permissions are resolved in one place underneath everything else.

  • Screens — the field is not drawn asks
  • Reporting — not in the catalog, refused in a report asks
  • Exports and integrations — the value does not come back asks
  • The AI assistant — the column is removed first asks
One set of permissions Resolved once, underneath — so a screen, a report, an export, an integration and the assistant all get the same answer
  • keeps Audit & compliance — every change, and every sign-in
  • keeps HR management — the records most field permissions are written about
  • keeps System administration — where users, roles and directory connections live

That is why the same answer comes back from a screen, a report, an export, an integration and the assistant — and why a feature shipped next year inherits it without anyone having to remember to apply it.

Audit and compliance keeps every change and every sign-in. The built-in AI assistant is shown a description of your data with the protected columns already removed. Reporting and dashboards leaves a hidden field out of the catalog and refuses a report that names it. HR management holds the records most field permissions are written about, and system administration is where users, roles and directory connections live.

Who this user access control is for

Companies of roughly 20 to 500 people where everyone can see everything because setting it up properly was never worth the effort, one person both raises and approves the payments, and last month somebody left and nobody is certain what they can still get into. SM Space is a cloud ERP system: it runs in a web browser, with nothing to install.

Frequently asked questions

Can we control what individual people can see?
Yes, down to a single field. A role that is not cleared for the salary column does not get it — the screen does not draw it, reporting leaves it out of the fields you can choose and refuses a report that names it, the AI assistant is never shown the column at all, and it does not come back through the interface an integration uses. You can also limit which records a person sees.
Does it support two-factor authentication?
Yes. Each person sets it up with an authenticator app, or receives a code by email if you prefer that, and gets ten single-use recovery codes for the day the phone is gone. You can require it for everyone in your company or leave it to each person. An administrator can reset somebody’s second factor but can never read it, and cannot enrol on their behalf.
Can people sign in with Microsoft or Google?
Yes, and you can pull your users in from Microsoft 365 or Google Workspace rather than typing them in. The client ID and secret are set on a screen, so a secret can be rotated without a redeploy, and the sign-in page only draws a button for a provider you have actually configured. There is no automatic sync — an administrator runs a re-check.
What happens when someone leaves?
Deactivate them and the sessions they are holding end with them, within seconds rather than whenever their token would have expired. Reports, exports and the interface an integration uses all stop at the same moment. You can see beforehand exactly which sessions are open and from which address, and the history keeps every sign-in and how each session ended.
Can we stop one person from both raising and approving a payment?
Yes. Write the pair down as a rule and SM Space refuses to give one person both, naming the rule and the grant already in the way. Turning the rule on scans everyone first and reports who already holds both rather than stripping anyone. Where the business genuinely needs an exception, a waiver records who approved it, why, and when it expires.
Is our data encrypted?
Specific values are encrypted where they are stored: two-factor seeds, sign-in and directory credentials, outbound email passwords, storage keys and access tokens, the connection to each tenant’s database, passport and permit numbers, and social insurance numbers. The key protecting them can be replaced while the system keeps running, because each value records which key sealed it. For anything beyond that list, ask us rather than reading it in.

See exactly who can reach what.

Book a 30-minute demo and we’ll open the same record as two different people.

Book a 30-minute demo