Stackroom

Security

Your data, isolated and in your control

Stackroom is multi-tenant by design, with configurable roles and careful handling of your assets, people and history.

How does Stackroom keep our data secure?

Every organisation's data is isolated at the tenant boundary, access is governed by configurable roles and permissions stored in the database, and changes are audit-logged. Deletions are soft, so an accidental removal is recoverable from trash rather than gone. Authentication and rate limiting protect accounts and API keys.

Foundations

Built for accountability

Tenant isolation

Every organization's data is separated — your records are yours alone.

Configurable roles

DB-driven roles and permissions control who can view, assign and edit.

Access controls

Rate limiting and authentication protect your account and API.

Trash & recovery

Soft-delete with a trash bin means an accidental deletion is recoverable.

SSO/SAML and advanced enterprise controls are on the roadmap — talk to us about your requirements.

Roles

Permissions you configure, not tiers you pick

A technician who records handovers need not see finance fields, and a viewer can be genuinely read-only. Because roles are data rather than a fixed set of tiers, the awkward cases — a department admin, a read-only auditor — are configuration rather than a support ticket.

Screenshot to come

The roles screen with a role open, showing its permission matrix across assets, people, audits and billing.

Roles and their permissions are stored in the database rather than hardcoded, so a role can be shaped to the job.
Audit trail

Every change, attributed and dated

Edits, handovers, returns, status changes and deletions are recorded with the person and the timestamp — including anything Stackroom AI does on someone’s behalf, attributed to it by name.

Deletion is a soft delete into a trash bin, so an accidental removal is recoverable. That matters more for assets than most records, because deleting one would otherwise destroy its whole history.

Screenshot to come

The activity log filtered to one asset, showing each change with who made it and when.

The activity log is what makes a custody chain evidence rather than an assertion.

FAQ

Questions about security

Is our data separated from other customers?

Yes. Every query is scoped to the organisation, so records belonging to one tenant are not reachable from another. This is enforced in the data layer rather than only in the interface.

Can we control what each person can see and do?

Yes. Roles and their permissions are configurable rather than a fixed set of tiers, so a technician who records handovers need not see finance fields, and a viewer can be genuinely read-only.

Does Stackroom support SSO or SAML?

SSO and SAML are enterprise capabilities — talk to us about your identity requirements and what is available on your plan rather than assuming from this page, because the answer changes as they roll out.

What happens if something is deleted by mistake?

Deletion is a soft delete into a trash bin, so the record and its history can be restored. That matters more for assets than most objects, because deleting one would otherwise destroy its custody chain.

Ready to know where every asset is?

Start free — tag your first 100 assets and run a real checkout in your first session. No credit card required.