← muthari.com

The record that defends you

Muthari OS · the Project Operating System for Specialist Contractors

Governance in Muthari OS answers ‘who decided what, and when’ with a line written at the time, for contractors who fabricate what they install. Access is by capability, not job title: each role holds a set of capabilities, and any person can be granted or denied one individually. Every approval, rejection, stamp and issue carries the actor, their role and the time, and the audit line states the fact — ‘Direct approval by X’ — never a verdict about the person. Your company’s data is isolated from every other company on the server, not in the browser, and an administrator can export the whole tenant: every table, and a manifest of every uploaded file.

Capabilities, not titles

Gates check what a person may do, not what their designation is called. Roles bundle capabilities, per-person grants adjust them, and there are no hard-coded recipients — approvers are resolved from your live roster. A person approving their own request is recorded as exactly that, not quietly blocked or quietly allowed.

Facts, never verdicts

Audit lines name the actor and the act. A verbal go-ahead used to start take-off is written as a verbal go-ahead, with the name. Names live in records forever, so the record is kept fair to the people in it.

Void, never delete

Expenses are voided with the voiding recorded; the original stays. Variations, invoices and expenses keep structured approval history, each purchase order keeps its own log, and superseded drawings and delivery notes stay on file rather than being overwritten.

Tenant isolation on the server

Row-level policies keyed to a server-resolved session decide what a request may see; a client cannot name another company and read its data. Sessions are issued by the server, failed logins are throttled on the server, and changing your password signs out your other devices.

Evidence you can take with you

Photo downloads are logged. Administrators can export the full tenant — every table, plus a manifest listing every uploaded file — and the per-view exports honour the filters on screen, so the sheet you send is the list you saw.

Honest limits: there is no tenant-wide audit log table — trails live on each record, so ‘everything X approved last month’ is answered record by record, not with one filter. Tenant users sign in with a username and password; there is no MFA or SSO for them. Within a tenant, capability checks are enforced in the application and are being moved into the database table by table; isolation between companies is already server-side.

Where it shows

The same audit lines appear on every order in Procurement, every stamp in Production and every claim in Commercial. Muthari OS is built by contractors in the trade.

Book a free demo  See the whole system →