Security Architecture
Layered IMS security covering workstation authorization, global authentication, Global Administrator access, company membership and company-local permissions.
Security layers
| Layer | Control |
|---|---|
| Workstation | IMS checks the registered workstation identity before authentication; authorized administrators can approve or block devices. |
| Global identity | Login credentials and account state are centralized and are not duplicated as independent passwords in each company database. |
| Global administration | IMS Global requires a valid Global Administrator session. Administrative modules revalidate that session before opening. |
| Company membership | Only companies assigned to the global user are eligible for login/selection. |
| Company-local authorization | Group Policies, Store/Supplier scope, transfer scope and operational privileges are maintained in the selected company. |
| Secrets | Sensitive service/database credentials are stored and mediated through server-side API security rather than being exposed as reusable plaintext configuration. |
Administrative self-protection
IMS Global prevents the account currently running the administration application from removing its own Global Administrator flag, disabling itself or resetting its own password from the Global Users screen. It also prevents the current workstation from blocking itself.