# Complete Software Feature and Access Analysis

Analysis date: 18 September 2026  
Scope: static, read-only review of the application source in this repository.

## 1. Executive summary

This is a multi-business, multi-location POS/ERP platform built on Laravel. Its core is retail/wholesale transaction management: products, purchases, inventory, POS/direct sales, invoices, payments, contacts, expenses, accounts and reports. It also includes restaurant operations, manufacturing, CRM, a B2B ordering portal, WooCommerce synchronization, IndiaMART lead capture, WhatsApp notifications, a mobile/API connector and a SaaS superadmin/subscription layer.

The system has four separate levels of access control:

1. **Tenant/business boundary**: normal records are scoped to a business, with optional physically separate tenant databases.
2. **Subscription/module boundary**: paid/add-on modules can be enabled or denied per tenant package.
3. **Role permission boundary**: roles receive granular permissions such as view/create/update/delete, own/all records, payments, invoice printing and reports.
4. **Data boundary**: users can be limited to locations, selling-price groups and selected contacts.

It is therefore not accurate to say that every cashier, manager or sales person always receives a fixed set of rights. Except for the built-in Admin and initial Cashier setup, rights are composed by the business administrator when creating a role.

## 2. Platform structure and tenancy

- Each user belongs to a business; roles are business-specific and carry a `#business_id` suffix internally.
- Business data models use the tenant connection trait. When tenant database mode is enabled, middleware resolves the signed-in business and switches to its active/migrated database.
- Custom domains can resolve tenants, and the B2B store supports a per-business custom domain.
- Each business can have multiple active/inactive locations. Products can be assigned only to selected locations.
- A user can receive `access_all_locations` or individual dynamic permissions such as `location.3`. Operational queries use these permitted locations.
- A user may be restricted to selected contacts through a user/contact mapping.
- Feature availability is the intersection of business-enabled core modules, installed modules, subscription/package entitlements and role permissions.

## 3. Users, roles and effective rights

### Built-in identities

- **Superadmin**: platform-wide SaaS operator. The superadmin can manage businesses, packages, subscriptions, global settings, pages, communications, statistics, module pricing/requests and module installation. Superadmin checks bypass tenant module restrictions.
- **Business Admin**: the default `Admin#business_id` role. It is treated as the business-level administrator and receives broad authorization through the application gate.
- **Cashier**: the demo/default assignment includes sales view/create/update/delete, cash-register view/close and invoice printing. The Cashier role is editable; consequently its effective rights can differ by business.
- **Custom roles**: a business may create any number of named roles, mark one as service staff, assign granular permissions, locations and price groups, then assign users to them.
- **CRM contact/customer login**: separate external contact access exists for CRM profile, ledger, purchases, sales, bookings, order requests and proposals where enabled.
- **B2B customer**: separate storefront account authenticated by OTP or registration, subject to approval/block status and an optional customer-specific selling-price group.

### Permission matrix

| Area | Rights that can be granted |
|---|---|
| Users and roles | View/create/update/delete users; view/create/update/delete roles; create/manage commission agents; impersonate/sign in as a user through the management route |
| Locations and contacts | All or chosen locations; all or own suppliers; all or own customers; selected-contact restriction; customer inactivity cohorts (1/3/6/12 months or irrespective of sales) |
| Products | View/create/update/delete; opening stock; import; bulk edit/deactivate/delete; price-group access; view purchase price |
| Purchases | View all or own; create/update/delete; update status; add/manage payments; edit/delete payments; create a purchase without seeing price; purchase requisition/order own/all and CRUD |
| POS sales | View/create/update/delete; edit line price; edit line discount; edit payment; print invoice; independently disable pay-and-checkout, drafts, express checkout, discount, suspended sale, credit sale, quotation and card controls |
| Direct sales | View all or own; filter entitlement to paid/due/partial/overdue sales; add/update/delete; payments; edit/delete payments; edit invoice number; edit line price/discount; view commission-agent sales |
| Drafts, quotes and sales orders | Own/all view plus update/delete; sales-order create/update/delete; quotations and pro-formas are distinct sale statuses |
| Returns and shipping | Sell-return all/own; shipping all/own/commission-agent/pending-only; stock transfer own/all and CRUD |
| Inventory | Opening stock; stock adjustment own/all and create/update/delete; stock transfers; stock report; stock details; product stock value |
| Expenses/accounts | All/own expense, add/edit/delete; expense reports; account access; account transaction edit/delete |
| Reports | Purchase-and-sale, contacts, stock, tax, trending product, register, sales representative, expense and profit/loss permissions |
| Settings | Business, invoice, barcode, tax-rate and printer access; types of service, restaurant tables and notification templates |
| CRM | All/own leads, schedules, campaigns and call logs; reports; contact login; sources; life stages; proposals; B2B marketplace |
| Manufacturing | Access/add/edit recipes and access production |
| WooCommerce | API settings, categories, products, orders and tax mapping |
| WhatsApp | Manage settings and notification logs; some current controllers also explicitly permit Admin/Superadmin |
| API | API access and OAuth client/token features where Connector is entitled |

### Important access behavior

- “Own” generally filters records to those created by or allocated to the signed-in user.
- Selling-price groups use dynamic permissions (`selling_price_group.<id>`). The default selling price is independently protected by `access_default_selling_price`.
- Reports are individually permissioned; dashboard data is separately controlled by `dashboard.data`, and custom dashboards retain their own dynamic permissions.
- Sensitive commercial data can be hidden: `view_purchase_price` controls cost visibility, `view_product_stock_value` controls valuation visibility, and a stock-person role with `purchase.add_without_price` can enter receiving information without purchase totals/payment details.
- Button visibility is not the sole protection: the reviewed controllers also perform permission checks and return 403 responses.

## 4. Product catalogue and pricing

### Product master

- Single, variable and combo/bundle product structures are supported.
- Core attributes include product name, SKU/sub-SKU, barcode type, unit and sub-units, optional secondary unit, brand, category/subcategory, tax, description, weight, image/media and custom fields.
- Products can be stock-enabled or non-stock/service items, active/inactive, or marked not for selling.
- Variations use variation templates and values, their own SKU, purchase cost and selling price. Combo products retain component variation definitions.
- Optional facilities include warranty, rack/row/position, serial/IMEI descriptions, lot numbers, expiry, featured products by location and WooCommerce sync exclusion.
- Product operations include quick add, spreadsheet import/export, bulk update, bulk location assignment, mass deactivate/delete, label/barcode PDF printing, stock history and opening-stock import.

### Multiple-price system

The software has several price layers:

1. **Default variation price**: each variation stores purchase cost, margin and sell price before/after tax.
2. **Selling-price groups**: any number of named active groups can be created. Each variation may have a group price as a fixed tax-inclusive value or a percentage calculation based on its default tax-inclusive price.
3. **Location default**: a business location may select its default selling-price group.
4. **Transaction/customer choice**: a sale records the selected group, and B2B customers can be assigned a specific group.
5. **Role visibility**: users see only the default price and price groups for which their role has permission.
6. **Manual override**: separate POS and direct-sale permissions decide whether a user may edit product price and discount during a sale.
7. **Customer groups/discounts**: customer groups and scheduled discounts can alter commercial treatment, with discounts assignable to products/variations and selling-price groups.

Prices and taxes may be configured as tax-inclusive or tax-exclusive. Currency and quantity precision are business-configurable. Purchase in a different currency and exchange rate are also supported.

## 5. Inventory and stock status

- Stock is maintained per **variation per location** in variation-location detail records.
- Quantity is increased through received purchases, opening stock, inbound transfers, production and sale returns; it is reduced through finalized sales, outbound transfers, stock adjustments, production consumption and purchase returns.
- Stock is linked from sale lines to purchase lots, supporting FIFO/accounting allocation, lot traceability, returns and profit computation.
- Inventory can be moved through stock transfers with lifecycle statuses such as pending/in-transit/final/completed, depending on the workflow.
- Stock adjustments record normal/abnormal loss and can remove expired stock.
- Low-stock status is derived from available quantity against each product’s alert quantity and is exposed on the dashboard.
- Expiry settings support expiry date or manufacturing date input, alert lead time and either continued selling or stopping sales before expiry.
- Stock views/reports include current stock, stock detail, stock by selling price, valuation, stock history, lot report, expiry report, opening stock, adjustment report, product purchase/sale movement and purchase-sale reconciliation.
- Available stock can be checked through both the UI and Connector API.

Because the database service was unavailable during this review, this report describes the stock engine and statuses implemented in code, not the current live quantity of any SKU.

## 6. Purchasing workflow

- Supplier management includes contact information, tax number, credit terms/limit, opening balance, documents, custom fields, ledger, payment history and supplier stock report.
- Purchase requisitions can be created and viewed as own/all records.
- Purchase orders support creation, editing, deletion, status updates and PDF download.
- Purchase entry supports supplier, location, reference/date, purchase and payment status, line products/variations, quantity, unit/sub-unit, lot/expiry, purchase cost, line discount, tax, additional expenses, shipping and documents.
- Purchase lines can be imported from a spreadsheet or populated from purchase orders/requisitions.
- Status and payment status are distinct. Relevant transaction states include received, pending, ordered, draft, in transit, final and completed; payments may be paid, partial, due or overdue by term.
- Payments can use configured methods/accounts and support add/edit/delete controls and documents/reference numbers.
- Purchase returns can be generated against purchases and affect supplier balance, payment and stock.
- A special stock-person workflow allows receipt entry without exposure to price/payment/total information.

## 7. Sales and POS workflow

### POS

- Location-aware product search, category/brand filtering, featured products, barcode entry and recent transactions.
- Customer selection/quick creation, customer credit limit, price group, sale date and salesperson/commission agent.
- Line quantity, unit, lot/expiry, warranty, price, tax, discount, serial/IMEI note, service staff and modifiers where enabled.
- Order-level discount, tax, shipping/delivery details, round-off, custom fields and internal/sale notes.
- Multiple/tendered payments, change return, cash denomination, payment accounts and register tracking.
- Pay-and-checkout, express checkout, credit sale, draft, quotation and suspended-sale flows; each may be hidden globally or per role.
- Customer-facing display screen and optional weighing-scale integration.
- Service staff availability/timer, PIN check, table and restaurant service integration.

### Direct sales and order states

- Direct sale creation and editing outside the POS.
- Sales can be final invoices, drafts, quotations or pro-formas.
- Draft/quotation copying, sale duplication, conversion to draft/pro-forma/invoice and spreadsheet sale import with batch rollback.
- Sales orders are separately managed and can be converted/linked to sales.
- Shipping includes address, status, delivery person, documents, custom fields and filtered shipment lists.
- Sales returns validate the source invoice, return line quantities to stock, produce a return invoice and reconcile payment/balance.
- Recurring invoices/subscriptions can be enabled/disabled and repeated by configured interval/repeat day.
- Sales commission agents can be selected, with calculation based on invoice value or payment received.

## 8. Invoice generation and documents

### Number generation

- Invoice schemes are business-specific and can be selected as defaults.
- A scheme controls prefix, start number, number of digits and number type. The transaction receives a generated invoice/reference number; authorized users may manually edit invoice numbers.
- Separate reference prefixes exist for other transaction types such as purchases, returns, expenses, transfers, orders and payments.
- Locations may select their default sale invoice scheme and invoice layout. POS settings can expose scheme/layout selectors at checkout.

### Layout and output

- Multiple invoice layouts can be configured and assigned to locations.
- Layout capabilities include business/location identity, logo/letterhead, invoice heading, contact and tax labels, date/time formatting, table headings, subtotal/discount/tax/total/payment/due/change sections, previous balance, reward points, salesperson/commission agent, lot/expiry, product image/description/custom fields, contact/location custom fields, shipping fields, QR-code fields and terms/notes.
- The software renders normal sales invoices, quotations, packing lists, sales-return invoices, purchase documents, purchase orders and stock-transfer documents.
- Output paths include browser print, downloadable PDF and public tokenized invoice/quote links.
- A public invoice link can lead to online payment. Implemented gateway integrations include Razorpay, Stripe, PayPal, Paystack, Flutterwave, PesaPal and MyFatoorah, subject to configuration/module context.
- `print_invoice` controls printing for normal business roles. Notification templates can send invoices/payment information through email/SMS/WhatsApp channels where configured.

## 9. Contacts, CRM and lead management

- Contacts can be supplier, customer or both, with multiple addresses/details, tax ID, credit limit, payment terms, opening balance, custom fields, documents and status.
- Import, duplicate mobile/contact/tax-ID checks, Google map view (when key exists), ledger, statement sending, dues and contact payments are provided.
- Customer groups support group-specific pricing/percentage rules.
- CRM provides leads, allocation to users, life stages, sources, conversion to customer, schedules/follow-ups, recurring schedules, schedule logs, call logs, campaigns, notification campaigns, proposals/templates, contact logins, commissions, contact bookings, marketplace lead import and conversion/follow-up reports.
- IndiaMART receives CRM Push API webhooks, persists receipts/details and creates/maps leads into CRM; it includes configuration and receipt/detail inspection.
- CRM own/all permissions separately restrict leads, schedules, campaigns and call logs.

## 10. B2B wholesale portal

- Public storefront per business slug and optional custom domain.
- Product/category browsing using the tenant catalogue, prices and stock rules.
- OTP login through WhatsApp Connect, registration, profile/address management and customer session/token handling.
- Guest checkout as well as authenticated checkout.
- Cart add/update/remove/clear, saved cart state and abandoned-cart timestamps/tracking.
- Bulk order placement and order history/detail.
- Backend settings, customer list, customer approval/blocking, price-group assignment and token regeneration.
- Portal orders are converted into the central transaction/sales system, so stock, invoices and reporting share the POS data model.
- Access is package-gated by the B2B Portal entitlement and tenant/domain resolution.

## 11. Payments, cash register and accounting

- Payments are attached to sales, purchases, expenses, returns, opening balances and contact dues.
- Payment records carry method, reference, account, date, amount, notes and optional document; child payments are supported.
- Cash registers can be opened by user/location, receive transaction movements, show register details and be closed with denomination reconciliation.
- Payment accounts support account types, opening balance, deposits, fund transfers, activation/closure and transaction editing/deletion.
- Accounting reports include cash flow, balance sheet, trial balance and payment-account report.
- Contact ledgers and aging reports cover receivable/payable behavior. Due dates are derived from transaction date plus day/month terms, and partial/due items become overdue when the term passes.
- Ledger discounts are implemented as a separate transaction capability.

## 12. Expenses and operational records

- Hierarchical expense categories and subcategories.
- Expense create/edit/delete, import, refund/payment data, tax, location, expense-for user, contact/payee, title, recurring information, documents and custom fields.
- All-expense versus own-expense access and a dedicated expense report.
- General documents and notes can be attached polymorphically to supported records, with media upload and CRUD controls.
- Activity logging records important field/status changes and exposes an activity report.

## 13. Reports and dashboards

Implemented reporting includes:

- dashboard totals, product stock alerts, purchase dues, sales dues and calendar events;
- profit and loss, purchase/sale summary and detailed purchase/sale reports;
- stock, stock details, stock value, stock by selling price, item report, lot, expiry and adjustment reports;
- product purchase, product sale, grouped product sale, sale-with-purchase and purchase-sale product reconciliation;
- tax details/report plus GST purchase and GST sales reports;
- customer/supplier, customer group and payment aging;
- purchase payment and sales payment;
- register, sales representative totals/commission/expense and service staff/table reports;
- trending products and activity logs;
- manufacturing report and CRM lead/follow-up/conversion reports when entitled.

Export buttons have their own permission and the business can globally enable/disable exports. Dashboard widgets can be configured and custom dashboard access is role-specific.

## 14. Restaurant and service operations

- Tables, bookings, modifiers/modifier sets, service types, service staff and kitchen modules can be independently enabled.
- POS orders can be assigned to a table and waiter/service staff, and products can carry modifiers.
- Kitchen display receives kitchen orders and line orders; staff can mark cooked, served or individual lines served and print line orders.
- Booking permissions distinguish all bookings from own bookings.
- Service type can add its own price-group/layout behavior and custom fields.
- Service staff supports PIN validation, availability, timers and line-level assignment.

## 15. Manufacturing

- Product recipes/BOMs with ingredient variations, quantities, units, waste percentage, ingredient groups and production cost calculation.
- Recipe create/edit/view and automatic update of recipe-product prices.
- Production orders consume ingredient stock and add finished-product stock, with create/edit/view/delete and reporting.
- Manufacturing settings and profit/loss contributions are integrated.
- Access requires both the subscription entitlement and the relevant recipe/production role permission.

## 16. Integrations and communication

- **Connector/API**: OAuth/Passport clients; products, variations, price groups, contacts, sales/returns, expenses, locations, brands, categories, units, taxes, service types, tables, registers, attendance/clock-in/out, holidays, notifications, profit/loss and stock endpoints.
- **WooCommerce**: API setup; category/product/order synchronization; tax mapping; webhooks for create/update/delete/restore; sync logs; reset mappings; per-product “do not sync.”
- **WhatsApp Connect**: provider/instance settings, QR connection/reconnection, Meta templates, local template management, automatic new-order notifications, test/manual send, log/retry functions and Connector integration.
- **IndiaMART**: inbound webhook lead capture into CRM.
- **Email/SMS**: business SMTP/SMS configuration testing and templated event notifications with CC/BCC support.
- **Cloud/storage**: configured filesystem support includes local, S3 and Dropbox packages.
- **OpenAI**: an OpenAI Laravel dependency/config is present, but the reviewed business routes do not establish a major end-user AI workflow; it should not be marketed as a confirmed feature without runtime verification.

## 17. SaaS and module administration

- Superadmin dashboard and statistics.
- Business/tenant creation, editing, activation/deactivation, user listing and password update.
- Subscription packages with duration, price, location/user/product/invoice limits and custom module permissions.
- Public pricing/subscription purchase, renewals and manual/admin subscription management.
- Module/add-on price catalogue and tenant add-on requests with approval workflow.
- Global settings, frontend/static pages and broadcast communication/history.
- Backup creation, download and deletion are present in the core admin area.

## 18. Business configuration

Configurable areas include:

- business identity, tax numbers, logo, currency, symbol placement, timezone, date/time format, financial-year start, accounting method and numeric precision;
- default profit margin, sales tax/discount, tax-inclusive/exclusive selling prices and inline tax;
- product expiry/lot behavior, alert periods, brands/categories/subcategories, sub-units/secondary units, racks/rows/positions, warranties and mandatory images;
- enabled modules, transaction-edit window, reference prefixes and keyboard shortcuts;
- POS control visibility, editable subtotal, transaction date, service staff, weighing scale, customer display, invoice scheme/layout, product suggestion pricing and recent transactions;
- payment methods/accounts, cash denomination and strict denomination checking;
- sales commission mode, required payment terms/commission agent and payment links/gateway credentials;
- default contact credit limit and export/table-page settings;
- location-specific invoice scheme/layout, price group, payment options, receipt printer and featured products.

## 19. Important findings and limitations

1. **Runtime data was not available.** `php artisan route:list` attempted to read the database and failed because MySQL was not reachable through the configured socket. Therefore active users, actual role assignments, live stock, live invoices and current package entitlements were not inspected.
2. **“Who gets what” is configuration-dependent.** The code defines possible rights, while the database defines who currently has them. A live access audit requires a database export or working read-only connection.
3. **Module presence is not the same as tenant access.** All eight module codebases are marked active in `module.json`, but tenant packages and role checks can still hide/deny them.
4. **Some labels contain legacy naming/typos.** For example the WooCommerce category permission is stored as `woocommerce.syc_categories`; changing such identifiers could break existing roles.
5. **Admin/Superadmin bypass matters.** A least-privilege review must inspect gate behavior and actual role membership, not only checkbox permissions.
6. **Static review confirms implemented paths, not successful third-party connectivity.** Payment gateways, WhatsApp, WooCommerce, email/SMS, IndiaMART and custom domains require valid credentials and external setup.

## 20. Recommended role design

| Suggested role | Recommended scope |
|---|---|
| Owner/Admin | All business settings, users/roles, locations, commercial data, reports and enabled modules |
| Store manager | Assigned locations; products, purchases, sales, returns, stock, registers and operational reports; no subscription/global settings |
| Cashier | Assigned location; POS create/view, register view/close and invoice print; no cost, stock value, manual price/discount override or deletion unless explicitly needed |
| Sales executive | Own customers and own direct sales/quotes/orders; allowed price groups; payments only if responsible for collections |
| Purchase manager | Suppliers, purchase orders/purchases/returns/payments and purchase reports; assigned locations |
| Stock receiver | Product view, assigned location, opening/receiving or `purchase.add_without_price`, stock transfer/adjustment as required; no cost/financial reports |
| Accountant | Payments, accounts, expenses, ledgers, tax, profit/loss and financial reports; no product/user administration |
| Warehouse manager | Product/stock view, transfers, adjustments, expiry/lot reports and stock valuation; no sales deletion |
| CRM agent | Own leads/schedules/campaigns/call logs, proposals and permitted contacts |
| Production operator | Assigned location plus manufacturing production; recipe view, but recipe editing only for a production manager |
| Waiter/service staff | POS/order functions, own bookings/table/service orders and service PIN/timer; no settings or financial reports |

These are recommendations, not automatically enforced job definitions. They should be implemented as custom roles and tested with representative user accounts.

## 21. Evidence map

- Core routes: `routes/web.php`, `routes/api.php`
- Menu/feature exposure: `app/Http/Middleware/AdminSidebarMenu.php`
- Role construction: `app/Http/Controllers/RoleController.php`, `resources/views/role/create.blade.php`
- User location/contact restrictions: `app/User.php`, `app/UserContactAccess.php`
- Products/pricing/stock: `app/Product.php`, `app/Variation.php`, `app/VariationGroupPrice.php`, `app/SellingPriceGroup.php`, `app/VariationLocationDetails.php`, `app/Utils/ProductUtil.php`
- Transactions/invoices: `app/Transaction.php`, `app/Http/Controllers/SellPosController.php`, `app/InvoiceScheme.php`, `app/InvoiceLayout.php`
- Reports: `app/Http/Controllers/ReportController.php`, `app/Http/Controllers/AccountReportsController.php`
- Tenant boundaries: `app/Http/Middleware/UseTenantDatabase.php`, `app/Services/TenantModuleAccess.php`
- Add-ons: each `Modules/<Module>/module.json`, routes, controllers and `DataController.php`

