One control plane, every department
Atlas splits cleanly into two layers: a commercial control plane that runs the business of delivering ERP, and an open tenant runtime that runs the ERP itself. Every module in the runtime is licensed independently from the control plane.
The provider portal
Onboard a client organization, subscribe them to a plan, and provision a fully isolated tenant workspace, live. The portal shows every organization and tenant in your fleet, with real fleet metrics: tenant growth, plan mix, and module adoption across your whole client base.
- Create an organization and provision its tenant in one flow
- Set product name, logo, and brand colors per tenant
- Toggle any module on or off, live, no redeploy
- See fleet-wide metrics: growth, plan mix, module adoption

The tenant workspace
Every tenant gets a real application, not a stripped-down demo: a dashboard built on their own live data, department navigation scoped to what they are licensed and permitted to see, and a workspace that feels like it was built for them alone because, structurally, it was.
- Schema-per-tenant Postgres isolation, verified continuously
- Role- and department-scoped navigation and permissions
- A dashboard built on real charts, not placeholder numbers
- Team messaging, notifications, and an AI copilot built in

What makes the foundation trustworthy
True multi-tenant isolation
Every tenant gets its own schema on a shared Postgres instance. Data never crosses tenant lines, and it is verified by an automated isolation suite on every release, not just tested by hand.
White-label, live
Set a tenant's product name, logo, and brand colors from the provider portal. Colors that would fail accessibility contrast are corrected automatically, so a client can never ship an unreadable brand.
License what you sell
Every module is a toggle. Enable or disable Finance, Sales, HR, or any department per client, and the change reaches their workspace on the next request. No redeploy, no waiting.
Deny-by-default access
Every route declares its own permission and, if it belongs to a licensed module, its own entitlement. Nothing is reachable unless it is explicitly granted.
API-first, always
The entire product surface is a versioned, generated API contract. Every client, including our own web apps, consumes the same generated SDK, so nothing drifts silently out of sync.
Real accounting, real inventory
Balanced double-entry journals, period close, and moving-average valuation. The numbers you see are the numbers a finance-literate client will trust.
Department modules
Each department is its own workspace in the tenant navigation. License the ones a client needs; the rest stay invisible, not just disabled.
Finance
Double-entry general ledger, accounts receivable, period close, and reconciliation.
Sales
Quotes, orders, credit limits, and the full order-to-cash flow.
CRM
Lead pipeline, contacts, and deal tracking from first touch to close.
Inventory
Stock levels, movements, and valuation with a real audit trail.
Procurement
Purchase orders, supplier management, and approvals.
HR
Employee records, leave requests, and approvals.
Payroll
Payroll runs, approvals, and payment.
Assets
Fixed asset registers and depreciation schedules.
Projects
Project boards, tasks, and timesheets.
Manufacturing
Bills of materials, work orders, and production that settles itself against inventory and the ledger.
Support Desk
Ticketing with SLA tracking for customer-facing support teams.
Reporting
One view of the company, scoped to what each person is allowed to see.
Workflow
Approval rules that gate real documents, not just a form.
Platform capabilities
These are not a place in the navigation. They change how the whole workspace behaves.
Messaging
Built-in team channels and notifications, scoped by department.
AI Copilot
An assistant that answers from your live data, with receipts for every answer.
Integrations
Signed outbound webhooks for finance events, with delivery history and retries.