-
AM

Batch Expiry Management

Status Batch Number Product Name Expiry Date Days Remaining Storage Location Action
v1.11.0 · SFM — Shop Floor Management Platform

Application
Training Manual

Everything you need to know about using SFM — section by section, role by role. Learn what each screen does, who can access it, and how to get the most out of every feature.

0
Screens
0
Modules
0
Access Levels
0
Releases
0
API Endpoints
Getting Started

Welcome to SFM

SFM is a Shop Floor Management Platform — one place to run the daily work of a plant. It is built as a set of modules on a shared plant model, so every site switches on the functions it actually needs and adds more over time. There is no fixed focus area: quality, operations, maintenance, materials, people, safety, facilities and supply-side functions all live on the same foundation, with the same login, the same plant hierarchy and the same role-based access control.

Every module is built around a real use case and a real user profile. We start from how your team already works — who walks the floor, who signs the check, who approves the pass, what the auditor asks for — and shape the module to that. If a function you need is not on this list yet, it gets built to your process and added to your plant: the platform is designed to grow on request, not to be worked around.

🏭
What SFM Covers Today
Live modules on your plant
7 MODULES

Each module is licensed and switched on per user, so two people at the same plant can see completely different sidebars. Your admin controls which of these you have.

1
Sample Management — QC sample lifecycle: intake, storage location down to rack and bin, check-in/check-out transactions, batch expiry monitoring and full history.
2
Equipment Calibration — equipment register, calibration due dates and status, certificate PDFs, automated caution alerts before a device falls out of calibration.
3
Quality Walkabout — structured floor walks: raise an observation where you stand, assign it, track it to closure, and review the activity trail.
4
Pest Control — device master and layout heatmaps, readings, spray and lizard-control planning and services, chemical master, meetings with MOM and action items, compliance reporting.
5
Blue Cards — shop-floor improvement and observation cards raised by anyone, worked through to implemented, with rewards, recognition and analytics.
6
Checklists & Inspections — build any check without code, schedule it to recur, assign it to groups or people, and run it on a phone, tablet or shop-floor Station kiosk.
7
Visitor Management — visitor register, gate passes with approval workflow, badge printing, gate kiosk QR check-in, RFID card tap and door control.
Built on a shared foundation: every module reads the same Company → Country → State → Plant → Department hierarchy and the same in-plant asset tree (Area → Work Center → Equipment, modelled on ISA-95 and SAP), and can be run from a Station kiosk bound to a physical place. That is what lets a new module be added to your plant quickly and behave like it was always there.
🔑
Log In

Open the app URL in your browser. Enter your email — the system auto-detects your company and authentication method (password or SSO).

1
Enter company email → system routes you to the correct login method
🧭
Navigate Modules

Use the left sidebar to switch between modules. Module groups (Sampling, Calibration, Walkabout, Pest Control) are shown based on your assigned permissions.

2
Sidebar shows only modules your admin has granted you access to
📋
Understand Your Role

Your access level determines what you can see and do. Regular users (Level 7) manage day-to-day operations. Admins (Level 1–5) have additional configuration and reporting access.

3
Your role appears in the top-right dropdown under your name
📤
Export Data

Every module supports PDF and Excel/CSV exports. Look for the Download or PDF button at the top of list/history screens to export filtered results.

4
PDF exports use the QCPdfEngine — clean A4 layout, no browser print dialog
🔔
Alerts & Notifications

The system sends email notifications for walkabout submissions, reopens, and calibration due dates. Make sure your email is correctly set in your user profile.

5
Email config is handled by your admin in Administration → Email Configuration
🏭
Plant Scope

All data is scoped to your assigned plant and department. You will only see records for your plant unless you have Country, State, or Company admin access.

6
Hierarchy: Company → Country → State → Plant → Department
📌
Sidebar Navigation Reference
All modules · All screens
ALL USERS

Overview sits on its own at the top of the sidebar (this page). Below it, screens are organised into 8 collapsible groups — one per module, plus Administration. A module group only appears if your account has been granted access to that module, so your sidebar is usually shorter than this list.

📦 Sampling
Enter New Sample · Search Samples · Log Sample Transactions · Log Samples History · Batch Expiry · Batch Expiry History · Data Visualization · Storage Configuration
⚙️ Calibration
Equipment Calibration · Calibration Register · Calibration Update History · Data Visualization
🚶 Quality Walkabout
Walkabout Register · Walkabout History · My Actions · Activity Log · Data Visualization · WQA Admin
🐛 Pest Control
Team · Annual Plan · Layout · Device Master · Readings Entry · Spray Plan · Spray Tracking · Lizard Plan · Lizard Services · Documents · Meetings · Reports · Data Visualization · Activity Log · Pest Master
🟦 Blue Cards
Blue Cards · My Blue Cards · Admin View · Data Visualization · Activity Log · Settings
✅ Checklists
Create Checklist · Run a Checklist · My Checklists · Checklist History · Templates · Checklist Groups · Checklist Schedules · Settings
🎫 Visitor Management
Gate Passes · Register Visitor · Visitors · History · QR Scanner · Download · RFID Config · Data Visualization
🔧 Administration (Level 1–2 only)
Master Data · User Management · Subscriptions · Branding · Audit Log · SSO Configuration · Printer Configuration · Email Configuration · System Documentation · Data Visualization · Know More · Workflow Diagram
Note: Storage Configuration lives under Sampling, not Administration — it defines the racks and bins that sample locations use. Settings appears inside both Blue Cards and Checklists, each configuring its own module for your plant.
Module 1

Sample Management

Track the complete lifecycle of QC samples from receipt to expiry. Log check-outs and returns, monitor batch expiry dates with colour-coded alerts, and export reports for audits.

📊
Overview Dashboard
Sidebar → Overview
ALL USERS

The dashboard gives a live snapshot of your plant's QC health — total active samples, expiry alerts, recent transactions, and calibration due counts — via KPI cards and interactive charts.

1
KPI cards at the top show total active samples, expiring soon, overdue calibrations, and open walkabout observations.
2
Charts below show sample distribution by rack/bin, calibration status breakdown, and recent transaction activity.
3
Clicking a KPI card navigates directly to the relevant section for quick drilldown.
Tip: The dashboard refreshes on every page load. Use it as your daily starting point before beginning lab work.
Enter New Sample
Sidebar → Enter New Sample
ALL USERS

Register a new QC sample into the system by filling in batch details, storage location, and expiry information. Generates a printable label with QR code.

1
Select your Plant → Rack → Bin using the cascading dropdowns. Only locations assigned to your plant appear.
2
Fill in Batch ID, Sample Name, Manufacturing Date, and Expiry Date. Batch ID must be unique.
3
Add Quantity, Unit, and Supplier details as required by your lab's SOP.
4
Click Save Sample. The system assigns a unique Sample ID and creates the storage record.
5
Optionally print a QR label immediately using the Print Label button — supports A4 and POS thermal printers.
Tip: Labels include batch ID, expiry date, and a QR code that links directly to the sample record when scanned.
🔍
Search Samples
Sidebar → Search Samples
ALL USERS

Find any sample in your plant's inventory using free-text search, batch ID lookup, or filter by storage location, status, or expiry range.

1
Type a Batch ID or Sample Name in the search box. Results update as you type.
2
Use the Plant / Rack / Bin filters to narrow results to a specific storage location.
3
Click a row to open the sample detail card showing full history, current location, and expiry status.
4
From the detail card you can Edit sample info, Transfer it to a new bin, or Print Label.
Tip: Expiry status is colour-coded: Red = Expired, Orange = Expiring Soon, Green = Safe.
🔄
Log Sample Transactions
Sidebar → Log Sample Transactions
ALL USERS

Record when samples are taken out from storage for testing and when they are returned. Every transaction is timestamped and linked to the user who performed it.

1
Search for the sample by Batch ID using the lookup field — the current bin and quantity auto-populate.
2
Select transaction type: Take Out (removing for use) or Return (putting back after use).
3
Enter the Quantity and add a Purpose / Remarks note for traceability.
4
Submit — the bin inventory updates in real time and the transaction is saved to history.
📜
Log Samples History
Sidebar → Log Samples History
ALL USERS

Full audit trail of all sample take-outs and returns. Filter by date range, batch ID, user, or transaction type. Export as Excel for compliance reporting.

1
Use the date range picker to scope the history to a specific period.
2
Filter by User to see all transactions by a specific person — useful for user activity audits.
3
Click Download Excel to export the filtered results for external reporting.
Batch Expiry Monitor
Sidebar → Batch Expiry
ALL USERS

A live dashboard of all samples sorted by expiry date. Colour-coded rows immediately highlight which batches need attention — from Expired to Safe.

1
Rows are colour-coded: Red = Expired, Orange = Expiring within 30 days, Yellow = Expiring within 90 days, Green = Safe.
2
Sort by any column — clicking the expiry column sorts from most urgent to latest.
3
Use the Filter by Status dropdown to focus on just expired or about-to-expire batches.
Tip: Check this screen at the start of every shift to ensure no expired samples remain in active storage.
🗃️
Batch Expiry History
Sidebar → Batch Expiry History
ALL USERS

Archive of all batches that have been expired or removed from active inventory, with full audit trail including who removed them and when.

1
Search by batch ID or date range to find specific historical records.
2
Click Download Excel to export history for compliance documentation.
📈
Data Visualization
Sidebar → Data Visualization (Sampling)
ALL USERS

Interactive charts showing sample trends, storage utilization by rack/bin, transaction volume over time, and expiry distribution across your plant.

Module 2

Equipment Calibration

Manage the full calibration schedule for all lab instruments. Track due dates, upload calibration certificates, log updates, and receive proactive alerts before equipment becomes overdue.

⚙️
Equipment Calibration
Sidebar → Equipment Calibration
ALL USERS

The main equipment register showing every instrument in your plant with its current calibration status. Status is automatically calculated from the due date.

1
Each equipment row shows Equipment ID, Name, Last Calibration Date, Next Due Date, and a colour-coded Status badge.
2
Status colours: 🔴 Overdue (past due), 🟠 Critical (≤7 days), 🟡 Warning (≤30 days), 🔵 Caution (≤60 days), 🟢 Safe, ⚫ Not In Use, 🔷 Gone For Calibration.
3
Click Update Due Date on any row to record a new calibration and advance the next due date.
4
Upload a Calibration Certificate PDF (up to 10 MB) directly from the update modal.
5
Click Download PDF for a clean A4 report of the full equipment register filtered by status.
Tip: Sort by "Next Due Date" to see which instruments need attention soonest. Filter by "Overdue" to get a quick audit list.
📋
Calibration Register
Sidebar → Calibration Register
ALL USERS

Full history of all calibration events per instrument — shows who performed each calibration, when, certificate reference, and any notes added.

1
Select an equipment from the dropdown to load its full calibration history.
2
Each row shows Calibration Date, Due Date Set, Calibrated By, Certificate No., and a link to the uploaded PDF.
3
Click the PDF icon to open or download the calibration certificate.
4
Edit historical records inline if a correction is needed — changes are logged with timestamp.
🔁
Calibration Update History
Sidebar → Calibration Update History
ALL USERS

A chronological log of all updates made to any equipment record — tracks both calibration updates and due date changes, with user attribution for every entry.

1
Filter by date range or specific equipment to focus on what you need.
2
Use the Export Excel button to download for external audit packages.
📈
Data Visualization
Sidebar → Data Visualization (Calibration)
ALL USERS

Charts showing calibration status distribution (pie/bar), upcoming due dates by month, and historical calibration completion rates across equipment categories.

Module 3

Quality Walkabout

Capture, track and close quality observations found during plant walkabouts. Follows a Draft → Open → Closed workflow with CAPA tracking, email notifications, attachments, and PDF reporting.

🚶
Walkabout Register
Sidebar → Walkabout Register
ALL USERSLEVEL 5+ ADMIN FEATURES

The main register lists all active (Draft + Open) walkabout observations for your plant. Raise new observations, assign action persons, and track progress through the lifecycle.

1
Click Raise New Observation to open the submission form. Fill in area, observation description, and select an Action Person.
2
Set a Target Close Date — the system will colour-code the observation red/orange when the date approaches.
3
Optionally check Repeat Observation and link to a previous closed walkabout for trend tracking.
4
Attach images or PDF evidence using the file upload field. Multiple attachments supported.
5
Submitting sends an automatic email to the Action Person (CC: Reporter + Plant Coordinators).
6
The Action Person updates the CAPA Details field inline once corrective action is taken.
Admin Only (Level 1–5): Can Open draft observations (sets the official start date), Close completed observations, and Reopen closed ones. Each reopen adds to the Reopen Counter badge on that observation.
Plant Coordinator (Level 9): Can also close observations for their assigned plant — without needing full admin access.
📚
Walkabout History
Sidebar → Walkabout History
ALL USERS

All closed walkabout observations with full audit trail — close date, CAPA notes, reopen count, and all comments/attachments. Paginated 20 per page.

1
Filter by date range, area, action person, or repeat observation flag.
2
Observation IDs follow the format PPPP-NNN (plant prefix + sequential number) — unique and permanent.
3
Export the filtered view as CSV or PDF for compliance packages.
4
Admins (Level 1–5) can Reopen any closed observation directly from this screen.
Tip: The due date column is colour-coded even for closed observations — useful for seeing how many were closed overdue vs. on time.
My Actions
Sidebar → My Actions
ALL USERS

Personal view showing every open walkabout observation where you are the assigned Action Person. Paginated 20 per page. Your personal to-do list for CAPA completion.

1
Observations due soon appear in orange/red — address these first.
2
Click any row to open the detail view — update the CAPA Details field and add comments once action is taken.
3
Once CAPA is complete, notify your supervisor so they can close the observation.
🔖
Activity Log
Sidebar → Activity Log (Walkabout)
LEVEL 5+ ADMIN

Complete audit log of every state change, comment, attachment upload, and edit across all walkabout observations — with user name and timestamp for each action.

📈
Data Visualization
Sidebar → Data Visualization (Walkabout)
ALL USERS

Charts showing observation trends over time, status distribution, top areas with repeat observations, average close times, and department-wise breakdown.

Module 4

Pest Control

Comprehensive pest management covering insect traps, rodent bait stations, spider pads, chemical spray tracking, meetings with MOM, and annual planning — all with heatmap dashboards and PDF reporting.

👥
Team
Sidebar → Pest Control → Team
LEVEL 5+ ADMIN

Manage the pest control team for your plant — list team members with their roles (Internal/External contractor), contact details, and assignment status.

📅
Annual Plan
Sidebar → Pest Control → Annual Plan
ALL USERSEDIT: LEVEL 5+

12-month schedule of planned pest control activities — fogging, spraying, baiting — for every area of your plant. Shows planned vs. completed activities with status tracking.

1
View the year grid: rows = activities, columns = months. Each cell shows Planned / Done / Missed status.
2
Admins can add/edit planned activities and mark them as completed when done.
3
Export the annual plan as PDF for regulatory submission or internal records.
🗺️
Layout (Heatmap Dashboard)
Sidebar → Pest Control → Layout
ALL USERS

Visual heatmap of your plant layout showing device placement and current pest pressure level by location. Four heatmap views available, each colour-coded by activity intensity.

1
Select the heatmap type: Insect Internal, Insect External, Rodent, or Spider Pad.
2
Each device marker is colour-coded by last reading — green = low, yellow = medium, red = high activity.
3
Click a device on the layout to see its recent readings and navigate to its detail record.
4
The plant image background is customized per plant — uploaded by the admin in Device Master.
📍
Device Master
Sidebar → Pest Control → Device Master
LEVEL 5+ ADMIN

Master register of all pest control devices in your plant — fly catchers (previously "insect killers"), rodent bait stations, glue traps, and spider pads. Each device has a unique code, type, and location coordinates for the heatmap.

1
Add devices with Device Code, Type (Fly Catcher / Rodent Bait / Glue Trap / Spider Pad), Location, and Zone (Internal/External).
2
Upload the Plant Layout Image — this becomes the heatmap background in the Layout screen.
3
Pin each device on the layout by clicking its desired position on the uploaded image.
4
Deactivate devices that have been removed without deleting historical data.
🔢
Readings Entry
Sidebar → Pest Control → Readings Entry
ALL USERS

Enter fortnightly or monthly readings for every pest device in the plant. Five device types have their own input format: Insect Internal, Insect External, Rodent Bait (Outer), Rodent Glue (Inner), and Spider Pad.

1
Select the Device Type tab and the Period (1st or 2nd fortnight, or month).
2
Insect devices: enter counts for each species — HF (House Fly), YW (Yellow Wasp), Mo (Moth), M (Mosquito), FF (Fruit Fly), RC (Red Cockroach), CB (Crawling Bug), MR (Mouse/Rodent).
3
Rodent stations: enter status for each bait point — B (Bait consumed), R (Refilled), O (Open/undisturbed), D (Disturbed), NA (Not accessible), EB (Empty bait), M (Missing), S (Secured), G (Gone).
4
Spider pads: monthly B (Baited) / O (Open/clear) / NA status per pad.
5
All entries are saved per period — re-entering the same device/period updates (not duplicates) the record.
Tip: The system highlights devices with no reading entered for the current period so you know which ones are pending.
💧
Spray Tracking
Sidebar → Pest Control → Spray Tracking
ALL USERS

Log every chemical spray application — chemical name, quantity used, target area, applicator, and date. Linked to the Pest Chemical Master for chemical details.

1
Select the Chemical from the Pest Master dropdown — pre-populated with name, dilution ratio, and safety notes.
2
Enter Area treated, Quantity used, Method (fogging/spraying/baiting), and Applicator name.
3
View all spray history with filters by chemical, date range, and area.
📋
Spray Plan
Sidebar → Pest Control → Spray Plan
LEVEL 5+ ADMIN

The planned spray schedule for the year — which areas get treated, with what, and how often. Spray Tracking then records what actually happened against this plan, so you can show planned-versus-done to an auditor.

🦎
Lizard Plan & Lizard Services
Sidebar → Pest Control → Lizard Plan / Lizard Services
ALL USERS

Dedicated planning and service logging for lizard control, kept separate from general spraying because it runs on its own schedule and method.

1
Lizard Plan — set out the intended coverage and frequency across the plant's areas.
2
Lizard Services — log each service visit as it is carried out, building the record against the plan.
📜
Activity Log
Sidebar → Pest Control → Activity Log
LEVEL 5+ ADMIN

A full audit trail for the module — every device, reading, spray, chemical and meeting change, with who made it, when, and what it was before.

📝
Meetings & MOM
Sidebar → Pest Control → Meetings
ALL USERSMOM EDIT: ATTENDEES + ADMIN

Schedule pest control review meetings, record attendance, and manage Minutes of Meeting (MOM) with action items, owners, and due dates.

1
Create a meeting with Type (Monthly / Quarterly / Annual / Special), Date, and Agenda.
2
Add attendees from the user list — they will receive a meeting invitation email.
3
After the meeting, open the MOM editor to record discussion points and add action items.
4
Each Action Item has an owner, due date, and status (Open / Closed). Owners can update their action item status.
5
Export the MOM as a PDF with a clean formatted layout for distribution or filing.
📁
Documents
Sidebar → Pest Control → Documents
ALL USERS

Pest control document repository — upload and manage SDS sheets, contracts, compliance certificates, inspection reports, and any other regulatory documents.

📊
Reports
Sidebar → Pest Control → Reports
ALL USERS

Generate comprehensive pest control reports — monthly readings summaries, trend analysis, infestation level reports, and compliance documentation — all exported as clean A4 PDFs.

🧪
Pest Master (Chemical Master)
Sidebar → Pest Control → Pest Master
LEVEL 5+ ADMIN

Master list of all pesticides and chemicals approved for use at your plant. Each entry stores name, active ingredient, dilution ratio, target pest, regulatory registration number, and safety notes.

Module 5

Blue Cards

A shop-floor improvement-suggestion system. Anyone can raise a Blue Card describing a problem and a suggested solution, tagged to a Zone and Working Place. Each card moves through its lifecycle — Open → Acknowledged → In Progress → Implemented (or Rejected) — with optional savings tracking, and implemented ideas can be Rewarded to recognise the person who raised them. All data is plant-isolated, with a full activity log behind every change.

🟦
Raise a Blue Card
Sidebar → Blue Cards
ALL USERS

The kiosk-style entry screen where any employee submits an improvement idea. Each submission gets a unique, permanent card number and starts in the Open state.

1
Enter your name (and optional employee/contact number) as the submitter.
2
Pick the Zone and Working Place from the plant's configured lists (or free-type if allowed).
3
Describe the Problem and, optionally, your Suggested Solution.
4
Submit — the card is saved with today's date and a generated card number, ready for review.
Tip: The screen is designed for a shared shop-floor kiosk — after each submission it resets for the next person.
🗂️
Admin View
Sidebar → Blue Cards → Admin View
LEVEL 5+ ADMIN

The management board for all cards raised at your plant. Move each card through its lifecycle and record who did what at every stage.

1
Acknowledge a new card to confirm it has been received and is under consideration.
2
Move it to In Progress and record an Action Plan describing how the idea will be implemented.
3
Mark it Implemented with a closure note — and optionally log the savings realised.
4
Reward an implemented card to recognise the submitter — pick a reward category and record the amount, currency and a note. The card moves to the Rewarded state.
5
Or Reject a card that cannot be actioned, with a reason for the record.
Lifecycle: Open → Acknowledged → In Progress → Implemented → Rewarded, with Rejected available at any stage. Each transition stores the acting user's name so the full history is auditable.
Excel export — download every card for your plant as a formatted, colour-coded workbook with a summary sheet.
🗑
Delete archives, it does not erase. Deleted cards move to Trash and can be restored, so a mis-click never loses a submission.
🔍
Universal search works across all Blue Card views.
👤
My Blue Cards
Sidebar → Blue Cards → My Blue Cards
ALL USERS

Every card you have raised, with its current status — so a submitter can follow their own idea through to implementation without asking an admin.

Closing the loop: This is where the person who raised an idea sees it acknowledged, actioned and rewarded — the visibility that keeps people submitting.
📊
Data Visualization
Sidebar → Blue Cards → Data Visualization
ALL USERS

Dashboards summarising card activity for the plant — totals by status, cards by zone and working place, implementation rate, and cumulative savings from implemented ideas.

⚙️
Settings
Sidebar → Blue Cards → Settings
LEVEL 5+ ADMIN

Per-plant configuration for the module, across three tabs:

1
Cards — manage the Zones and Working Places that appear in the linked dropdowns, and customise the printed card's title, subtitle, notice line and dimensions with a live preview.
2
Contact Users — a name-only roster of submitters who have no login (contractors, temporary staff). These names feed the create-card typeahead so their cards still get full history and analytics.
3
Notifications — who gets emailed when a card is raised at this plant.
Plant isolation: Zones, working places, contact users, cards, and settings are all scoped to your plant — one plant never sees another's Blue Cards data.
📜
Activity Log
Sidebar → Blue Cards → Activity Log
LEVEL 5+ ADMIN

A complete audit trail of every create, edit, status change, reward, delete and restore in the module — who did it, when, and exactly what changed from what to what.

For audits and disputes: because the log records the before and after of each change, you can answer "who changed this card's status, and what was it before?" months later.
Module 6

Checklists

A universal, configurable checklist and inspection engine — build any checklist without code, run it on mobile with photo evidence, and get an automatic pass/fail with a full audit trail. Templates are organised into sections and questions with per-question rules, and every published template is versioned so past runs never change retroactively. All data is plant-isolated, with optional company-standard templates shared across plants.

🧩
Templates & Create Checklist
Sidebar → Checklists → Templates / Create Checklist
LEVEL 5+ ADMIN

Templates lists every checklist at your plant with its category, scope, status and version. + New Checklist there — or Create Checklist in the sidebar — opens the designer, where process owners build a checklist from scratch with no code. A template is organised into sections, each holding a list of questions.

1
Add sections to group related questions (e.g. "Housekeeping", "Documentation").
2
Add questions to each section, choosing a response type: Yes/No/NA, OK/Not OK/NA, Pass/Fail, Text, Number, Date, Dropdown, or Photo.
3
Set per-question rules — mandatory, photo required, remark required, and a criticality level that determines whether a failed answer fails the whole run.
4
Save as a draft to keep editing, or Publish when ready — publishing snapshots an immutable version that operators will run against.
Versioning: Once published, a version is frozen. Editing a template again and republishing creates a new version — completed runs stay permanently tied to the version they were executed against, so historical results are never altered by later template changes.
Company-standard templates: A template can be marked as a company standard and made available across all plants, in addition to plant-specific templates.
▶️
Run a Checklist
Sidebar → Checklists → Run a Checklist
ALL USERS

The execution screen operators use to carry out an inspection, designed as a single scrollable form that works well on mobile devices.

1
Pick a checklist from those published and available to your plant (your plant's own templates plus any company-standard ones).
2
Starting a run freezes the current published version, so the questions you see stay fixed even if the template changes later.
3
Work through each section, answering every question. Attach a photo or add a remark where the template requires it — and always where an answer fails.
4
Submit the run — the rules engine checks every answer, and any single failed question fails the overall run.
Mandatory fields: Submission is blocked until every mandatory question has a valid answer (and photo/remark, if required).
📥
My Checklists
Sidebar → Checklists → My Checklists
ALL USERS

Your personal inbox of checks that are due. When a schedule generates runs, everyone on the recipient list sees them here — this is where an operator starts their day.

1
Each card shows the checklist, the subject it applies to (e.g. Machine 4), and the due time. Overdue items are flagged.
2
Tap Claim to take ownership. Claiming is first-come-first-served — once you claim it, it disappears from everyone else's list, so two people never fill in the same check.
3
The run opens directly in the execution screen with the subject and place already stamped on it.
Recipients are notified by email when their runs are generated, so the board is not the only prompt.
🧑‍🤝‍🧑
Checklist Groups
Sidebar → Checklists → Checklist Groups
ADMIN / SCHEDULER

Named, reusable sets of people at your plant — "Shift A Operators", "QA Team", "Line 3 Leads". Build the group once and target it from any schedule instead of re-picking individuals every time.

1
Create a group and give it a clear name that matches how your plant actually talks about that team.
2
Add members from the users at your plant. Changing a group's membership immediately changes who receives every schedule pointed at it.
3
A schedule can target any mix of groups and individual users at the same time.
Groups are per-plant — they never span plants, so one site's team list is never visible to another.
🗓️
Checklist Schedules
Sidebar → Checklists → Checklist Schedules
ADMIN / SCHEDULER

Set a check up once and let it run itself. A schedule generates the runs, assigns them to the right people, and emails them — every day, week, month or quarter, without anyone remembering to start it.

1
Pick the published template and a recurrence: daily, weekly, fortnightly, monthly, quarterly or annually — with a day picker and a due time.
2
Add subject labels to fan one schedule out into many runs — list "Machine 1…10" and you get ten separate checks per period, one per machine.
3
Choose recipients: any mix of Checklist Groups and named users. Everyone targeted sees the run on their My Checklists board.
4
A daily job creates the runs, so the board fills in automatically each period. Use the status board to see per-schedule, per-day completion — done, in progress, pending or overdue, and who did each one.
Who can schedule: Plant admins, plus anyone your plant designates as a Scheduler on the Settings page. That lets a line supervisor own their own recurring checks without being made an admin.
🖥️
Station Mode (Shop-Floor Kiosk)
Master Data → Stations → open station.html on the device
SETUP: LEVEL 1USE: ALL USERS

A shared tablet or panel PC mounted at a physical place on the floor, so operators run their checks where the work happens instead of walking to a desk. A Station is registered once and permanently bound to a place — a plant, an area, a work center, a specific machine, or a gate.

1
Register the device under Master Data → Stations, choose the place it lives at, and pick which apps its tiles show.
2
Open the full-screen kiosk page on the device. The operator identifies themselves, taps a tile, and the check opens with the station's place already stamped on the run — no typing the location.
3
On submit, the device returns to the kiosk home screen ready for the next person.
Station Mode is platform-wide, not checklist-only. Any module can add a tile to the same station, so one panel at the line can serve checks today and further shop-floor apps as they are added.
📊
Checklist History
Sidebar → Checklists → Checklist History
ALL USERS

A dashboard of every completed (and in-progress) run at your plant, with its overall pass/fail result, the template and version used, and who ran it and when.

1
Filter by template, status (pass/fail), or date range to find the runs you need.
2
Open any run to review every question, answer, remark, and attached photo evidence.
3
Export a run to a clean A4 PDF for sharing or record-keeping.
Plant isolation: Templates, runs, responses, and photo evidence are all scoped to your plant — one plant never sees another's checklist data.
Module 7

Visitor Management

A complete visitor and gate-pass system: register visitors once, raise and approve gate passes, print QR badges, and check visitors in and out at the gate — by QR scan or RFID card tap. Visitors are shared company-wide; gate passes and history are isolated by plant (or by Location for gate staff). Roles decide who sees what: admins get everything, Security runs the gate, and normal users only handle passes they raised or must approve.

It also covers the parts of a gate that only show up in real use: a Today list of who is expected, group and multi-day visits, vehicles arriving, a Muster List that prints for a fire drill with the network down, auto check-out for people who never tapped out, a blacklist, masked ID numbers, a full activity log — and a phone/tablet layout you can install on the home screen and run from the barrier.

Register Visitor & Visitors
Sidebar → Visitor Management → Register / Visitors
ALL USERS

Register a visitor once and reuse them anywhere in the company — no re-typing at each plant.

1
Capture a photo (webcam or file) plus name, mobile, company, ID type/number and category. Duplicate mobile numbers are detected so you don't create the same visitor twice.
2
The Visitors screen lists everyone in the company — search by name, mobile or company, then Edit details or the photo, or start a new gate pass straight from the card.
Company-wide: the visitor master is shared across all plants — register once, use at any gate.
🎫
Gate Passes
Sidebar → Visitor Management → Gate Passes
ALL USERS

Raise, approve and manage visit requests. Each pass gets a unique UGPN-YYYY-NNNNNNNN number and a QR code.

1
Pick the visitor and host (Host Phone and Department auto-fill from the host's profile), set expected date, a From–To time slot and the gate.
2
Approval is mandatory — add at least one approver (anyone in your location except yourself). Passes are never auto-approved.
3
Track status through Pending → Approved → On-Site → Checked Out (or Rejected / Denied). Approvers, requestor and gate staff are emailed at each step.
4
Answer “Coming with a vehicle?” — Yes reveals a required vehicle number, tidied to a standard format (mh-12/ab 1234MH 12 AB 1234). It appears on the pass, in the CSV export and in the activity log.
5
Print the 52×88 mm QR badge — to a Bluetooth thermal printer (POS) or the browser.
Normal users see only the passes they raised or need to approve; admins and Security see all passes in their scope. History is visible to everyone within the plant/location.
Today tab: the first tab on Gate Passes is everyone expected today — both Approved and still-Pending, on purpose, so the guard sees an unapproved arrival standing at the barrier instead of being surprised by them.
👥
Groups & Multi-Day Visits
Sidebar → Visitor Management → Gate Passes → +
ALL USERS

A party of people, or the same person for a run of days, without any new concepts to learn at the gate.

1
Pick several visitors in one form and the system raises one ordinary pass per person — each with its own number, QR, badge, check-in popup, check-out and emails. They are only linked together so the whole party can be approved in one click and the cards show a coloured group strip.
2
Add an optional Until date for a daily visit and you get one pass per person per day — 3 people × 5 days = 15 passes. Weekends included; the calendar is not restricted. Caps: 90 days and 200 passes per booking.
3
Give each person their own vehicle number, or leave it blank to share the group's.
4
Email is consolidated per booking: one approval request, one host notice, and one message per person at approval carrying a dated QR for every day of their visit.
Why one pass per person: every downstream step — self check-in, the liquor / safety / declaration popup, badge print, check-out, RFID — runs the single tested path it always has. Nothing at the gate behaves differently because a visit happens to be a group.
🧯
Muster List & Auto Check-Out
Sidebar → Visitor Management → Muster List
ADMIN + SECURITY

Who is inside the plant right now — for the daily count, and for the head count at the assembly point.

1
Everyone currently checked in, with their host, phone, time in, hours on site and vehicle. Anyone inside more than 12 hours is flagged as overdue.
2
Print roll call produces an A4 sheet with a signature column, rendered from data already in the page — so it still prints during an evacuation with the network down.
3
The same two numbers — vehicles inside and overdue — are shown on the gate QR Scanner, so the guard never has to leave that screen to check.
4
Auto check-out closes visitors who never tapped out, at a per-plant cutoff time. Set it in the plant's Visitor settings — blank means off, and blank is the default, because a night-shift plant would otherwise have real visitors evicted mid-visit.
Honest records: an auto check-out is stamped at the cutoff time, not the moment the sweep ran, and is logged as “automatically checked out by the system”. It never reads as a guard confirming someone left.
🔒
Privacy, Ownership & Activity Log
Sidebar → Visitor Management → Visitors / Activity Log
ALL USERS

The visitor master is shared so nobody re-types the same person — but sharing a list is not the same as sharing the right to change it.

1
You can read every visitor in the company, but only edit the ones you registered. Admins and Security can edit any. The Edit button only appears where the change would actually be allowed.
2
ID numbers are masked (••••234F) for anyone who may not edit that visitor. Passport and licence numbers are not casual browsing material.
3
Blacklist a person with a reason (admin only) and they are refused at pass creation and again at check-in.
4
The Activity Log (admin) records every change to a visitor or pass with before → after values, who did it and when — including gate actions and auto check-outs.
5
Safety training and liquor check are per-visit gate checks, not properties of a person: the guard records Yes/No/NA and Pass/Fail/NA at check-in, and they appear in Gate Pass Details.
Per-plant option: a plant can switch on “creator only”, which narrows the visitor list itself to the people each user registered.
📱
On Phone, Tablet & Installed as an App
Any screen → open on a phone or tablet
ALL USERS

Visitor Management is built to be run from a phone at the barrier, not only from a desk.

1
A bottom tab bar — Passes, Visitors, Register, Muster, Scan — appears on touch devices, following the same permissions as the sidebar. Forms become full-width sheets and every button is a proper thumb target.
2
Cards fit the screen: one per row on a phone, two on a tablet, three on a large landscape tablet. The desktop layout is unchanged.
3
Install SFM on the home screen and it opens full-screen like a native app — Chrome and Edge offer a one-tap install; on iPhone and iPad use Share → Add to Home Screen.
Requires HTTPS: the install prompt, camera and Bluetooth all need a secure connection. On a plain LAN IP with a self-signed certificate the browser will refuse them.
📷
Gate Check-In — QR Scanner & RFID
Sidebar → Visitor Management → QR Scanner / RFID Config
ADMIN + SECURITY

Two hands-free ways to check visitors in and out at the gate.

1
QR Scanner — a full-screen kiosk page for the gate PC; scanning a visitor's badge QR checks them in, or out on the second scan, with a live welcome/goodbye banner.
2
RFID — download the one-file installer (Mac or Windows) from RFID Config and double-click it on the gate PC; it connects an ACR122U reader. A card tap then auto checks the visitor in/out, and you can write a pass onto a card from the pass's NFC button.
3
A configurable minimum stay (default 3 min) blocks accidental instant check-out right after check-in.
4
The scanner shows four live tiles — Checked In, Checked Out, Vehicles inside and Overdue — from the same figures as the Muster List, so the two screens can never disagree. Overdue turns red only while it is non-zero.
Setup: RFID Config, Download and Data Visualization are admin-only. The gate PC needs the app open on HTTPS or localhost for camera and Bluetooth to work.
📈
Data Visualization, Gates & Roles
Sidebar → Visitor Management / Master Data → Gates
LEVEL 5+ ADMIN

Reporting and the master data behind the module.

1
Data Visualization (admin) — KPIs plus charts for visits-per-day, status distribution, visitor categories and peak check-in hours, all scoped to your plant/company.
2
Gates — managed under Master Data → Gates; each gate belongs to a plant with a type of Entry, Exit or Entry+Exit and feeds the gate dropdown when raising a pass.
3
Security role (access level 10) is created in User Management for gate staff. Assign a Location to a Security user so they cover every plant in that location, not just one.
Data isolation: gate passes and history follow the same plant/company rules as every other module; Location-assigned users additionally span all plants in their location.
Administration

System Administration

Full system configuration and user management. The Administration section is only visible to Master Admin (Level 1) and Company Admin (Level 2). Some sub-sections are Level 1 only.

Access Restriction: The entire Administration sidebar group is hidden for users at Level 3 and below. If you need access to any of these settings, contact your Company Admin or Master Admin.
🗄️
Storage Configuration
Sidebar → Sampling → Storage Configuration
LEVEL 1 ONLY

Define the physical storage infrastructure for samples — add Plants, Racks per plant, and Bins per rack. This structure is what all sample location dropdowns use throughout the system.

1
Add a Plant first — give it a code (used as the prefix for Walkabout IDs), name, and link it to a State in Master Data.
2
Under each Plant, add Racks (e.g. Rack A, Rack B). Racks represent physical storage units.
3
Under each Rack, add Bins with capacity. Bins are the individual storage slots a sample can occupy.
🌍
Master Data
Administration → Master Data
LEVEL 1 ONLY

Manage the organisational hierarchy used for data scoping — Companies → Countries → States → Plants → Departments — plus the shop-floor asset tree inside each plant. Every piece of data in the system belongs somewhere in this structure.

1
Start with Companies — each company gets an ID, name, and a primary domain (used for SSO tenant detection).
2
Add Countries under each company, then States under countries, then Plants under states.
3
Add Departments under each plant — users are assigned to a specific department for their day-to-day access scope.
4
Areas & Equipment — the shop-floor hierarchy inside a plant, as a tree: Area → Work Center → Equipment. This is what a checklist run, and any future machine-level function, is stamped against.
5
Stations — register shop-floor kiosk devices and bind each one to a place in that tree (or to a gate), then choose which app tiles it shows.
6
User Roles — the role titles that can be assigned to users.
Why the asset tree matters: Area / Work Center / Equipment is modelled on the ISA-95 standard and maps onto SAP's Functional Location, Work Center and Equipment objects, with dedicated fields held for those keys. It gives every module one shared answer to "where on the floor did this happen?" — and is the foundation new shop-floor modules plug into.
Delete is a deactivation, not an erase. Removing a company, country, state, plant, department or user sets it inactive: it disappears from pickers and lists, everything beneath it is hidden too, and affected users can no longer log in — but the history stays intact. Inactive rows appear greyed with a ♻ button to reactivate them.
👤
User Management
Administration → User Management
LEVEL 1–2

Add, edit, deactivate users and assign their access level, module permissions, and plant/department. User Roles are also managed here (moved from Master Data in v1.3.0).

1
Add a new user: enter First Name, Last Name, Email, Department, Access Level, and Role.
2
Set Module Access per user — individually enable/disable each of the seven modules as View, Edit or None. This is what decides the user's sidebar.
3
Optionally set a Reporting Manager via name/email typeahead — used to notify a submitter's manager when they raise a Blue Card.
4
A Company Admin (Level 2) can manage users within their company but cannot assign Level 1 users.
5
For Plant Coordinators (Level 9): use the Coordinator modal to assign them to specific plants for walkabout close authority.
6
For a Location Admin: assign a Location to cover all its plants, or hand-pick a subset of those plants for a narrower scope.
7
Deactivated users cannot log in but their historical records are preserved, and can be reactivated later.
New users are welcomed automatically — creating a user sends them a welcome email with a link to sign in.
Licensing: If your company has a subscription with user caps, adding or reactivating a user is checked against the cap for that role and plant. If a cap is reached you are told which one, so you can free a seat or have the cap raised.
💳
Subscriptions
Administration → Subscriptions
PLATFORM OWNER ONLY

Licensing control for each customer company — how long their subscription runs and how many users they may create, overall and per role.

1
Set the company's validity window — start date and expiry date.
2
Set the total user cap for the company, plus caps per admin tier (company, country, state, location and plant admins).
3
Optionally add per-plant caps — each plant can carry its own total-user limit and its own per-role limits for plant-bound roles.
4
Leave any cap blank for unlimited. A company or plant with no row set is fully unlimited.
Where caps are enforced: at user creation, at user reactivation, and at login (so an expired subscription stops access). Users see a renewal banner in the 15 days before expiry.
🎨
Branding
Administration → Branding
LEVEL 1–2

Make the app look like the customer's own. Turn branding on for a company and its users see that company's identity after they log in.

1
Upload the company logo and set an accent colour, applied to the surfaces where it reads cleanly.
2
Set a support email so that company's users are pointed at the right help desk.
3
A Company Admin edits their own company's branding; the Platform Owner can edit it for any selected company.
Off by default — a company keeps the standard look until branding is explicitly enabled.
⚙️
Settings (per-plant Configuration)
Sidebar → Checklists → Settings
LEVEL 5+ ADMIN

Per-plant, per-module behaviour — the knobs that let two plants on the same system run their processes differently. This page lives in the sidebar under Checklists, but it configures more than checklists, which is why it is documented here with the other admin screens.

1
Blue Card coordinators — who at this plant is emailed when a card is raised.
2
Schedulers — who at this plant may create and edit checklist schedules without being a full admin.
3
Signature location lock — require a check to be signed at the right place. Set a geofence and signing is permitted, warned or blocked depending on how far the device is from it.
Settings are per plant — changing them at one site never affects another.
🛡️
Audit Log
Administration → Audit Log
LEVEL 1–2

The authentication and account trail for compliance: logins, logouts, failed attempts, password changes, and account create / edit / deactivate events, with who and when.

Retention: entries are kept for a configured period and older ones are purged automatically each day, so the log satisfies storage-limitation requirements without manual housekeeping.
🔐
SSO Configuration
Administration → SSO Configuration
LEVEL 1 ONLY

Configure enterprise Single Sign-On (OIDC) per company. Once configured, users with a matching email domain are automatically redirected to your identity provider (Okta, Azure AD, Google).

1
Select the Company and enter the Email Domain (e.g. yourcompany.com) that triggers SSO.
2
Enter the OIDC Issuer URL, Client ID, and Client Secret from your identity provider.
3
Set the Redirect URI in your IdP to https://your-server/auth/callback.
🖨️
Printer Configuration
Administration → Printer Configuration
LEVEL 1 ONLY

Configure label printer settings — POS thermal printer connection details, label dimensions (width, height in mm), and QR code size. Supports both A4 and ESC/POS thermal formats.

✉️
Email Configuration
Administration → Email Configuration
LEVEL 1 ONLY

SMTP settings for system email notifications — walkabout alerts, calibration reminders, and meeting invites. Configure sender address, SMTP host, port, and authentication credentials.

Reference

Access Level Reference

SFM uses 10 access levels. Each level determines which sections are visible, what actions can be taken, and which data scope (company / country / state / plant / department) is applied.

LevelRole NameData ScopeKey CapabilitiesRestrictions
1 Master Admin All Companies
Full system access All modules All admin screens SSO Config Printer Config Email Config Master Data
None
2 Company Admin Single Company
User Management System Docs All modules
No SSO ConfigNo Printer/Email ConfigNo Data Vis (Admin)
3 Country Admin Country-wide
All module screens Reports & exports
No Administration section
4 State Admin State-wide
All module screens Reports & exports
No Administration section
5 Plant Admin Single Plant
All module screens WQA Open/Close Walkabout Activity Log Pest Team manage Device Master edit
No Administration section
6 Department Manager Department
All module screens Departmental data
No Administration section
7 Regular User Plant
Enter/search samples Log transactions Raise walkabouts Enter pest readings My Actions
No AdministrationNo WQA Open/Close
8 Viewer Plant
Read-only all screens Export/download
No create/editNo Administration
9 Plant Coordinator NEW v1.3.0 Plant-scoped
Close walkabout observations Auto CC'd on submissions Plant-scoped data
Cannot Open observationsNo Administration
10 Security NEW v1.9.0 Plant / Location gates
Visitor Register Gate Passes Check-in / Check-out QR Scanner RFID card writing Badge printing
Visitor module onlyCannot approve passesNo Administration
🔑
Module Access Control
Per-user module gating
CONFIGURED BY ADMIN

In addition to the access level, each user's visibility of the four main modules (Sample Management, Equipment Calibration, Quality Walkabout, Pest Control) is individually controlled via Module Access settings in User Management.

Master Admin (Level 1) always sees all modules regardless of Module Access settings.
All other users only see the sidebar groups for modules where Module Access is set to View or Edit.
If Module Access is None, the entire sidebar group is hidden and attempting direct navigation shows an "Access Denied" screen.
Tip: If a module is missing from your sidebar, ask your Company Admin to check your Module Access settings in User Management.
Version History

Release Notes

Complete changelog for SFM — every feature added, bug fixed, and improvement shipped since v1.0.0.

v1.11.0
MINOR RELEASE
2026-08-31
Quality Walkabout — Observations & MOC
  • Observations — findings that need no action — tick "No action required" and log just the place, category, subject, description and a photo. Until now every walkabout had to name an action person and carry a deadline, because the module exists to chase somebody; some things are worth recording but need nobody chased. An observation is complete the moment it is logged, so it never joins anyone's action list, never becomes overdue, and is never counted as a completed corrective action
  • MOC severity (60 days) — a fifth tier for changes that cannot be closed inside Minor's 30 days. The due date is calculated as +60 days, exactly as the other tiers calculate 1, 7, 15 and 30
Quality Walkabout Analytics — Filtering
  • Date range filter — a From → To calendar before the Refresh button narrows every KPI and chart to the period you pick. One tap plus Apply selects a single day; "All dates" clears it
  • Click any chart to drill down — clicking a status, severity, category, location, action person or due-date bucket re-filters the entire page to that value. Filters stack, combine with the date range, and each appears as a chip you can click to remove. Clicking a month on the trend chart narrows to that whole month
  • Monthly Trends now shows Closed as well as Raised — closures are counted in the month they actually closed, whenever the finding was first reported, which answers "how much did we clear last month?"
Fixed — Quality Walkabout Analytics
  • Six-month charts skipped two months and double-counted two others — the month cursor stepped back from today's date, so on the 31st "minus four months" became 31 April, a date that does not exist and rolls forward to 1 May. The Severity Trend axis read "Mar May May Jul Jul Aug": April and June were missing entirely and the duplicated months were merged into one bar. Months are also now keyed by year, so August of one year no longer merges into August of the next
  • "By Observation Location" was always one grey slice — the chart read a field the server has never sent, so every finding fell through to "Unknown". It now shows the real plants
  • Status Distribution hid Drafts and Observations — the chart showed only Open and Closed, and its "Open" slice silently also counted Drafts. It now shows one slice per real status
  • The Open KPI counted Drafts twice — drafts have their own tile, so they were billed to both, and the card disagreed with the chart beside it. Drafts are also no longer counted as overdue or due-soon, since they are not yet chaseable
  • Action Person and Due Date columns printed "null" in the register, history and my-actions tables for any finding without one
Everywhere
  • The header now says where you are — the block by your avatar shows your current plant in brackets after the company, e.g. "Henkel South Africa (Alrode)". An admin who spans several plants sees the plant they have selected, or the widest scope they hold — their location, country, state, or "All Plants"
Database Changes
  • Run on the VPS after pulling: add_walkabout_no_action_option.php (observations), then add_walkabout_moc_severity.php (MOC tier). Both are idempotent and additive — existing findings are untouched
v1.10.0
MAJOR RELEASE
2026-07-25
Platform — Shop Floor Foundation
  • Areas & Equipment — a per-plant shop-floor tree (Area → Work Center → Equipment) in Master Data, modelled on ISA-95 and mapped to SAP's Functional Location / Work Center / Equipment objects. One shared answer to "where on the floor did this happen?" for every module
  • Checklist runs are stamped with their place — the Run screen now picks Area → Work Center → Equipment instead of free text, so results are tied to real assets and can be analysed by line or machine. Only Area is required, so a check can cover a whole area, one line, or a single machine
  • Station Mode — register a shop-floor tablet or panel PC, bind it permanently to a place (plant, area, work center, machine or gate), and choose which app tiles it shows. The operator taps a tile and the check opens with the place already filled in, then returns to the kiosk on submit. Platform-wide, so any module can add a tile to the same station
Licensing, Branding & Tenancy
  • Subscriptions — per-company validity dates and user caps: a total cap, caps per admin tier, and optional per-plant caps. Enforced at user creation, reactivation and login, with a renewal banner in the final 15 days. Blank cap = unlimited, so existing companies are unaffected
  • Plant-wise licensing — per-plant, per-role user caps for plant-bound roles, so a customer can license each site to the size it actually is
  • Company Branding — per-company logo, accent colour and support email, shown to that company's users after login; edited by the Company Admin or the Platform Owner. Off by default
  • User avatars — anyone can set their own profile photo from their account dropdown; it is resized in the browser and appears in the header and menu
Visitor Management — Gate Reality
  • Today — the first tab on Gate Passes is everyone expected today, Approved and still-Pending on purpose, so an unapproved arrival at the barrier is visible instead of a surprise
  • Muster List — who is inside right now, with host, time in, hours on site and vehicle; anyone over 12 hours flagged overdue. Prints an A4 roll call with a signature column from data already in the page, so it still works during an evacuation with the network down
  • Auto check-out — closes visitors who never tapped out, at a per-plant cutoff time (blank = off, and blank is the default). Stamped at the cutoff rather than when the sweep ran, and logged as a system action, so a record never reads as a guard confirming someone left
  • Group visits — pick several people in one form and get one ordinary pass each, with its own number, QR, badge, check-in popup and emails; linked only so the party approves in one click and the cards show a group strip. Every downstream step keeps using the single tested path
  • Multi-day bookings — an optional Until date creates one pass per person per day (3 people × 5 days = 15 passes), weekends included; capped at 90 days / 200 passes. Emails are consolidated per booking, and each person gets one message carrying a dated QR for every day
  • Vehicles — “Coming with a vehicle?” on the pass, with the number normalised to a standard format, shown in pass details, CSV export and the activity log; per-person vehicles within a group
  • Activity Log — every change to a visitor or gate pass with before → after values, who and when, including gate actions and auto check-outs
  • Blacklist — bar a person with a reason; refused at pass creation and again at check-in
  • Installable app (PWA) — SFM can be installed on a phone, tablet or desktop and opens full screen. Icons are now served locally, so a plant on a closed network can still install it
Visitor Management — Privacy & Mobile
  • Visitor edit is ownership-based — the company-wide visitor list stays readable by everyone, but you may only change the visitors you registered (admins and Security may change any). Previously any user could edit anyone's record
  • ID numbers are masked for anyone who may not edit that visitor — passport and licence numbers are no longer casual browsing material
  • Gate-pass lists are scoped on the server — the “only mine” filter used to be requested by the browser, so History showed every pass in the plant. Ownership is now decided inside the endpoint
  • Auto check-out no longer crossed tenants — a company admin has no single plant, so the sweep ran unfiltered and could close visitors at every plant of every company. It now uses the central access filter
  • Phone and tablet layout — bottom tab bar, full-width sheets, thumb-sized targets, cards that fit the screen (1 on a phone, 2 on a tablet, 3 on a large landscape tablet). Desktop is unchanged
  • Safety training & liquor check are per-visit — recorded by the guard at check-in (Yes/No/NA, Pass/Fail/NA) and shown in Gate Pass Details, rather than being a property of the person
  • Module-wise email sender names — notifications now say which module they came from (Visitor Management, Blue Cards, Checklists, Pest Control…), instead of every module looking identical in the inbox
Blue Cards — Rewards & Audit
  • Rewards & Recognition — an implemented card can be Rewarded with a category, amount, currency and note, giving the submitter visible recognition and closing the improvement loop
  • Activity Log — a full audit trail of every create, edit, status change, reward, delete and restore, recording who changed what from what to what
  • The module is now called simply Blue Cards everywhere; the "HPS" label has been removed from the UI, emails and printed cards. Plants that had customised their card title keep it — only the default changed
Safer Data Handling
  • Delete now archives instead of erasing across companies, countries, states, plants, departments and users. Deleting deactivates: the row and everything under it disappears from lists and pickers and affected users cannot log in, but the history survives and a ♻ button reactivates it
  • Signature location lock — a per-plant geofence for checklist signatures, so a check can be permitted, warned or blocked depending on how far the signer is from the place it belongs to
Product
  • Renamed to SFM — Shop Floor Management Platform. The product covers the daily running of a plant across quality, operations, people, safety and facilities functions, with modules built per customer use case; the name now reflects that rather than any single focus area
  • Training Manual overview refreshed — screen, module, access-level and endpoint counts recounted from the application, the Security role added to the access reference, and every previously undocumented screen written up (My Checklists, Checklist Groups, Schedules, Station Mode, My Blue Cards, Blue Cards Activity Log, Subscriptions, Branding, Settings, Audit Log, Spray Plan, Lizard Plan & Services, Pest Activity Log)
v1.9.0
MAJOR RELEASE
2026-07-19
New Module — Visitor Management
  • Visitors master — register a visitor once (photo via webcam or file, mobile, company, ID type, category) and reuse them at any plant across the company; a dedicated Visitors screen to search and edit anyone, with duplicate-mobile detection
  • Gate passes — raise a pass for a visitor with host, department, expected date, time-slot (From/To pickers) and gate; unique UGPN-YYYY-NNNNNNNN numbers; mobile-first card layout matching the app theme
  • Approval workflow — every pass requires at least one approver (no auto-approval); pick any user in your location except yourself; statuses Pending → Approved → On-Site → Checked Out (plus Rejected / Denied) with full who-did-what audit and 5 branded email notifications
  • Badge printing — 52×88 mm visitor badge with QR; print to a Bluetooth ESC/POS thermal printer (POS button) or the browser
  • Gate QR Scanner — a full-screen kiosk page for the gate PC; scan a visitor's QR to check them in or out automatically, with live on-screen confirmation
  • RFID hardware bridge — one-file installer (Mac & Windows, double-click) that connects an ACR122U card reader; tap a card to auto check-in / check-out, or write a pass number onto a card from the pass; live Bridge + Reader connectivity status
  • Data Visualization (admin) — KPIs plus visits-per-day, status, category and peak-hour charts on one page
  • Gates master data — manage gates per plant (Entry / Exit / Entry+Exit) under Master Data → Gates; CSV export & import of visitors and passes
Roles, Access & Data Isolation
  • Security role (access level 10) — for gate staff; sees Register / Visitors / Gate Passes / History / QR Scanner and performs check-in/out and card writing
  • Location scoping — a Security user (or plant user) assigned to a Location works across all plants in that location; approver and host lists show every user whose plant is in the location
  • Per-role screens — admins see everything; normal users see only passes they raised or must approve; QR Scanner is admin + Security, while Data Visualization, Download and RFID Config are admin-only
  • Minimum-stay protection — a configurable minimum stay (default 3 min) prevents accidental instant check-out right after check-in, on card tap, QR scan and button
  • User Mobile Number — an optional mobile field (with country-code picker) on Add/Edit User; auto-fills the Host Phone on gate passes
Fixes & Improvements
  • New users start with NO module access — admins grant each module explicitly (was defaulting to full edit on everything)
  • Visitor Management is now selectable in Module Access Permissions and saves correctly
  • Badge print no longer overlaps the name onto the QR or cuts off the bottom text; the layout uses the full label with even spacing; hardened Bluetooth transfer against "GATT operation failed"
  • History page redesigned to match Gate Passes, with a single green from-to date-range calendar instead of two large date fields
v1.8.0
MAJOR RELEASE
2026-07-17
Checklist Scheduling & Assignment — Automatic Daily Runs
  • Schedules — set a checklist to run automatically on a recurrence (daily, weekly, fortnightly, monthly, quarterly, annually) with a day picker and due time; a scheduler sets it up once and the system creates the runs every period
  • Subject labels — one schedule fans out into multiple runs (e.g. "Machine 1"…"Machine 10"), so a single 8 AM schedule produces one check per machine each morning
  • Groups — per-plant named sets of users (e.g. "Line 1 Operators") as reusable assignment targets; a schedule can target any mix of Groups and individual users
  • Schedulers — designate per-plant which users may create/edit schedules, on the Configuration page (like Blue Card Coordinators)
  • My Checklists board — every recipient sees their due runs and claims one to fill it; the claim is first-come-first-served, so two operators can't take the same run
  • Supervisor status board — per-schedule, per-day completion view (done / in-progress / pending / overdue) with who did each
  • Recipients are emailed their assigned runs automatically when the daily job materialises them
Blue Cards — Contract Users, Trash, Export & Smarter Forms
  • Contract Users — a per-plant roster of name-only submitters (people without a system account), managed on a new Settings tab; their names appear in the card Name suggestions and get full history & analytics like any user
  • Name must be registered — the submitter Name must match a registered User or Contract User; an unknown name pops up a prompt to add them first (no more free-typed, inconsistent names)
  • Zone → Working Place linked dropdowns — pick-only lists; choosing a zone shows only that zone's working places, and auto-selects when there is just one
  • All fields required (except Number) — Zone, Working Place, Date, at least one 4C category, Problem and Suggested Solution must be filled before a card can be submitted
  • Trash & Restore — deleting a card now archives it (soft delete) instead of erasing it; deleted cards are recoverable from a Trash view — no data loss
  • Excel export from the Admin view — filtered by plant, with a formatted, colour-coded workbook (title block, filters, frozen header, per-status colours, a summary sheet)
  • Universal search across all Blue Card views — search by card number, name, number, zone, working place, status, problem, reward — any keyword
  • Dashboard boards — Contributors and Zone leaderboards now scroll (top rows visible, rest on scroll) plus a new "Working places by zone" breakdown
Fixes & Reliability
  • Blue Card creation emails now share one consistent Blue-Card look; automatic emails to plant Coordinators were removed (coordinators are configured per-plant on the Configuration page)
  • Fixed the 4C category checkboxes in Blue Card emails — checked boxes now render visibly and aligned even in clients that strip background colours
  • Logins survive redeploys — sessions are now persisted to disk instead of memory, so updating the app no longer logs everyone out
  • Hardened the scheduling engine — plant-level access isolation, atomic (no-duplicate) run creation, and safe date handling
v1.7.0
MAJOR RELEASE
2026-07-13
Universal Checklist & Inspection Engine — Build Any Checklist, No Code
  • New Checklists module — a configurable template builder for any inspection or audit: organise questions into sections with 8 response types (Yes/No/NA, OK/Not OK/NA, Pass/Fail, Text, Number, Date, Dropdown, Photo)
  • Per-question rules — mark any question mandatory, require a photo, require a remark, and set a criticality level that determines whether it fails the run
  • Publishing a template snapshots an immutable version — later template edits never retroactively change a run that already executed against a published version
  • One universal, mobile-friendly run screen — pick an available checklist, work through sections, attach photo evidence, and submit
  • Automatic pass/fail — the rules engine validates every answer as it's entered; any single failed question fails the overall run
  • Checklist Runs dashboard with template/status/date filters, full answer + photo review, and clean A4 PDF export via QCPdfEngine
  • Plant-isolated by default, with optional company-standard templates shared across all plants; granted via the new "checklists" module permission
Security & Access
  • Checklist photo evidence accepts image files only, is stored privately (outside the public web root), and is served exclusively through an authenticated, access-checked route
  • Full multi-tenant and plant isolation applied to templates, versions, runs, responses, and attachments — no cross-plant or cross-company data exposure
  • All checklist-entered text (questions, remarks, dropdown options) is rendered stored-XSS-safe throughout the module
v1.6.0
MINOR RELEASE
2026-07-12
Location Admin — Manage Multiple Plants with One Login
  • New Locations in Master Data — group several plants within one state into a named Location (e.g. "North Cluster"), with a plant checklist to pick which plants belong to it
  • New Location Admin (Multi-plant) access level — assign one admin to a Location and they manage all of its plants together with a single login, instead of needing a separate account per plant
  • A Location Admin sees the merged data of every plant in their Location (samples, calibration, pest control, blue cards, walkabouts) and nothing outside it; adding or removing a plant from the Location updates their access on next login
  • Company/State are set automatically from the chosen Location during user creation — no need to fill the hierarchy fields for a Location Admin
Security — Access Scope Fixes
  • Closed a cross-scope data leak: State Admin and Country Admin now correctly see only the plants in their state/country. Previously some screens (Samples, Walkabouts, Racks, Departments) fell back to showing the whole company's data
  • HTML-escaped all admin-entered names in the Locations screen to prevent stored script injection
v1.5.0
MAJOR RELEASE
2026-07-11
Blue Cards — New Module
  • Shop-floor improvement-suggestion system — anyone can raise a Blue Card describing a problem and suggested solution, tagged to a Zone and Working Place
  • Five-stage lifecycle — Open → Acknowledged → In Progress → Implemented, with Reject available at any stage; each transition records the acting user
  • Kiosk-style entry screen that resets after each submission for shared shop-floor use; every card gets a unique permanent card number
  • Admin View board to acknowledge, add action plans, close with a note, log savings, or reject cards
  • Analytics dashboards — totals by status, cards by zone and working place, implementation rate, and cumulative savings
  • Per-plant Settings — manage Zones and Working Places, and customise the printed card's title, subtitle, notice line, and size
  • Fully plant-isolated — cards, zones, working places, and settings are scoped per plant; granted via the new "blue_cards" module permission
User Onboarding — Welcome Email
  • New users are automatically emailed a branded welcome message with a login link — credentials no longer need to be shared by hand
  • Password is now optional on create; if left blank the system generates a strong temporary password (ambiguous characters removed for easy typing)
Security & Compliance — User Audit Log
  • GDPR-oriented audit trail — records logins, failed logins, logouts, and user create/edit/delete with IP address and device
  • Admin-only Audit Log screen (Administration → Audit Log) with event/date/email filters and CSV export; Company Admins see only their own company
  • Configurable retention — entries auto-purge after AUDIT_LOG_RETENTION_DAYS (default 365) to satisfy storage-limitation requirements
v1.4.1
PATCH
2026-06-30
Equipment Calibration — Enhancements
  • Model Number field — new optional free-text field on the add form, edit modal, history table, Excel export, bulk upload, and PDF export
  • Equipment ID label — renamed from "Equipment Serial Number (Unique)*" to "Equipment ID*" across the form and all related UI
  • "Under Calibration" equipment status (🔵) — third status option alongside "Not in Use" and "Gone for Calibration"; includes count tracking, blue row highlight, and legend modal entries in both Equipment History and Calibration Logs sections
Calibration Caution Email Notifications
  • Automated daily caution alerts — server sends an email to the last person who updated each equipment's calibration when the next calibration date falls within 16–30 days
  • One email per calibration cycle — dedup table with unique constraint on (equipmentID, nextCalibrationDate) guarantees no duplicate emails; resets automatically when equipment is recalibrated
  • Batched per recipient — if a user is responsible for multiple caution-stage devices, all are listed in a single email
  • Email includes Equipment ID, Model Number, Name, Used For, Plant, Last Calibration Date, Due Date, and Days Remaining
  • Skips equipment with "Not in Use", "Gone for Calibration", or "Under Calibration" status
Fixed
  • HTML-escaped all DB-sourced field values in email templates — prevents stored HTML injection across recipient inboxes
v1.4.0
MAJOR RELEASE
2026-03-28
Pest Control — Analytics & Slideshow
  • Slideshow carousel on all 4 analytics sections — auto-advances through KPI and chart cards
  • Timer selector — choose 5s / 10s / 15s / 30s auto-refresh interval on main Pest Control page
  • Monthly Pest Count chart — stacked bar by species (HF, YW, Mo, M, FF, RC, CB, MR) for current year
  • MOM % Reduction chart with fullscreen zoom button
  • Data Visualization tab in Reports — Monthly Count and MOM charts in one view
  • Corner triangle info tooltips on all 4 KPI cards with data source and update instructions
  • Year and Target % Drop filters in Pest Control Reports
  • Sub-stats on KPI cards — breakdowns by zone and species
  • Annual Pest Count bulk targets — import/export via Excel, month and owner dropdowns
Pest Control — Documents, Team & Activity
  • Pest Control Documents — versioned PDF upload per device with full upload history and download links
  • Pest Control Team — own sidebar section; user picker auto-fills name, email, department, and function from registered plant users
  • Activate / Deactivate button for pest control devices; inactive devices shown faded
  • RBC / RBG filter in Device Master to separate Rodent Bait and Rodent Glue devices
  • Pest Master (renamed from Chemical Master) — chemical/treatment master list with auto-fill dosage
  • Pest Control Activity Log — full audit trail of all pest control actions per plant
  • MOM spreadsheet view — inline editable Minutes of Meeting with row-level add/delete
  • Edit and Delete on Meeting History table; Special meeting type added
  • Pest Meetings redesigned as single-page layout — no tab switching required
Quality Walkabout Enhancements
  • WQA Category feature — plant-scoped category management with WQA Admin section
  • Subject field on QWA observations
  • Severity dropdown with auto due date calculation (Critical → 7 days, Major → 15 days, Minor → 30 days)
  • Admin edit modal with audit trail — records who changed what and when
  • Closed By shown in walkabout closure email
  • Action Person dropdown filtered to walkabout-module-enabled users only
  • Walkabout Analytics expanded — Severity, Category, Workload, and Trend charts added
Dudo (Chatbot)
  • Dudo — AI chatbot in sidebar; answers questions about samples, calibration, walkabouts, and pest control
  • Returns live charts and data tables from the database
  • Respects module access permissions — users only see data from their permitted modules
Admin & User Management
  • Tenant Group Admin (TGA) role — multi-company scoped access; manage a defined group of companies
  • Company Admin (Level 2) now has full admin section access with company-level data isolation
  • Workflow Diagram page in admin section — interactive system architecture visualization
  • Know More presentation page in admin section — feature overview and demo content
  • Training Manual (Overview section) rebuilt — 8 tabs covering all 40 screens, access levels, and step-by-step usage
PDF, System & Performance
  • QCPdfEngine — all PDF exports redesigned with clean A4 layout, consistent headers/footers
  • Gzip compression — faster load times across all API responses and static files
  • Section restore on page refresh — browser remembers last visited section
  • Deployment overlay — app shows "Deploying…" when it detects a server restart mid-session
  • Security hardening — auth checks, company isolation, and SSRF prevention across all endpoints
Fixed
  • handleFileSelect name conflict — calibration and bulk-upload shared the same global function; renamed to handleBulkFileSelect
  • MOM edit-mode SyntaxError — idArg computed before display-mode branch
  • checkModuleAccess — parseInt() required for access_level string comparison
  • Overview flash on page refresh — removed duplicate DOMContentLoaded handlers
  • Pest Control Team delete — confirm dialog now appears before delete, not after
v1.3.0
MAJOR RELEASE
2026-02-19
Quality Walkabout Register
  • Full Quality Walkabout module: Draft → Open → Closed lifecycle workflow
  • UID auto-generation with plant prefix (e.g. 0150-001)
  • CAPA details field with inline editing by action person
  • Repeat observation flag linking to previous closed walkabout for trend analysis
  • Attachment upload (image/PDF) on walkabout detail screen
  • Comments thread on each walkabout observation
  • Reopen closed observations with reopen counter badge tracking
  • Walkabout history view with colour-coded due date alerts (Overdue / Critical / Warning / Safe)
  • My Walkabout Actions section for personal to-do list per user
  • Export walkabout history to CSV and PDF (QCPdfEngine A4 layout)
  • Email notifications: submitted (To: action person, CC: reporter + coordinators), reopened, closed
  • 20-per-page pagination on all three walkabout tables (Register, History, My Actions)
Plant Coordinator (New Access Level 9)
  • New access level 9 "Plant Coordinator" — plant-scoped data access
  • Level 9 users can close Quality Walkabout observations for their plant
  • Plant Coordinators auto-CC'd on walkabout submitted and reopened emails
  • Warning shown in walkabout form when a Level 9 user is selected as Action Person
  • Level 9 added to all Access Level dropdowns (Add User, Edit User, User Roles)
  • Plant Coordinator role auto-seeded in roles table on server startup
Pest Control Module
  • Five device sections: Insect Internal, Insect External, Rodent Bait (Outer), Rodent Glue (Inner), Spider Pad
  • Dual-period insect killer readings (1st / 2nd fortnight)
  • Species count tracking: HF, YW, Mo, M, FF, RC, CB, MR
  • Rodent status ENUM: B, R, O, D, NA, EB, M, S, G
  • Spider pad monthly B/O/NA status per pad
  • Pest control access filter scoped by plant
Changed & Fixed
  • Application renamed from "QC Sample & Equipment's Calibration Management System" to "Quality Works" — since rebranded to SFM
  • User Roles section moved from Master Data to User Management (shown before Add New User)
  • Action-persons API now returns access_level to support frontend warning logic
  • Access level 9 was filtered out by ≤8 guard in dynamic dropdown loops — fixed to ≤9
  • Plant dropdown in coordinator modal showed "undefined" — corrected field names
  • Walkabout action-persons dropdown used innerHTML for reset — replaced with safe DOM methods
v1.2.0
MAJOR RELEASE
2025-01-23
Multi-Tenant SSO Authentication
  • OIDC SSO Support: Enterprise Single Sign-On with Okta (extensible to Azure AD, Google)
  • Tenant Detection: Automatic tenant identification via email domain
  • Redis Session Storage: Persistent sessions that survive server restarts
  • Tenant Isolation Middleware: Enforces data access boundaries between companies
  • Development SSO Mock: Test SSO flows without IdP connection (/auth/dev-login)
  • New table: tenant_auth_config — stores OIDC settings per company
  • New table: external_identities — maps SSO identities to local users
  • auth_type column added to users table (local/oidc/saml); password nullable for SSO users
  • Session middleware now supports Redis with in-memory fallback
  • Login page detects SSO domains and redirects automatically
v1.1.2
PATCH
2025-11-13
  • Fixed QRCode.toDataURL error in label printing
  • Fixed modal event listeners for equipment calibration updates
  • Fixed Update button not responding to clicks on equipment records
  • Made global functions globally accessible (loadEquipmentHistory, updateEquipmentDueDate)
  • Fixed Edit button click detection on equipment history table
  • Database connection pool timeout issues resolved
  • Comprehensive debugging system with console logging
  • Success notifications for equipment updates
  • Optimized QR code generation using constructor pattern
  • Refactored modal event listeners for reliability
v1.1.1
PATCH
2025-11-10
  • Input focus issues on mobile devices
  • Form field placeholder text visibility
  • Cascading dropdown population on page load
  • Sample search functionality with pagination
  • Mobile-responsive sidebar navigation
  • User dropdown menu in header
  • Equipment calibration alert notifications
  • Batch expiry colour-coded status indicators
  • Improved CSS media queries for mobile support
  • Enhanced table responsiveness on smaller screens
v1.1.0
MINOR RELEASE
2025-11-05
  • Equipment Calibration History feature
  • QR code label printing (Normal A4 + POS thermal printer)
  • Equipment due date update functionality
  • Calibration status alerts (Overdue / Critical / Warning / Caution / Safe)
  • Equipment notification system for approaching due dates
  • Customizable label dimensions (width, height, QR size)
  • Batch expiry tracking with alerts
  • Sample transfer between bins
  • User management role assignment
  • Master data cascading dropdowns
  • Improved dashboard layout and KPI cards
  • Enhanced data visualization charts
v1.0.0 – v1.0.5
INITIAL RELEASES
Sep–Oct 2025
  • v1.0.0: Initial release — sample management core, storage configuration, user auth, dashboard with KPI cards, data visualization, batch expiry monitoring, responsive design
  • v1.0.1: Login page validation, session management, Remember Me, password reset link
  • v1.0.2: Sample transaction logging (take-out/return), transaction history with filters, batch numbering system
  • v1.0.3: Master data management (Companies, Countries, States, Plants), department management, role management
  • v1.0.4: User change password, role-based access control, admin user management panel
  • v1.0.5: Batch expiry history tracking, sample storage location hierarchy
  • v1.0.1–v1.0.5: Cascading dropdown fixes, bin occupancy calculation, database connection pooling, improved error messages

Master Data Management

Companies

Company NameActions

Countries

CompanyCountryActions

States

CompanyCountryStateActions

Plants

CompanyCountryStatePlant CodePlant NameActions

Locations

Group several plants within one state into a Location, then assign a Location Admin (in User Management) to manage all of them together.

Select a state to list its plants…
LocationStatePlantsActions

Zones

PlantZone NameCodeDescriptionActions

Working Places

PlantZoneWorking PlaceCodeActions

Gates

PlantGate NameCodeTypeStatusActions

Departments

CompanyCountryStatePlant CodePlant NameDepartmentActions

Areas (per plant — SAP Functional Location)

PlantAreaCodeStatusActions

Work Centers (inside an Area — SAP Work Center)

PlantAreaWork CenterCodeStatusActions

Equipment (inside a Work Center — SAP Equipment / Asset ID)

PlantAreaWork CenterEquipmentAsset IDStatusActions

Stations (shop-floor tablets — a device locked to one place)

A station is one device (tablet/PC) fixed at a place — a line, a machine or a gate. Open station.html on that device once and choose its station; it then shows only the work for that place.

PlantStationCodeLocated atAppsStatusActions

User Management

Add New User

Leave blank to have the system generate a temporary password and email it to the user automatically. If you set one, it must be at least 8 characters and include:
  • ✗ 8 characters
  • ✗ 1 uppercase letter
  • ✗ 1 lowercase letter
  • ✗ 1 number
  • ✗ 1 special character

Module Access Permissions

Control which application modules this user can access. Changes take effect on the user's next login.

Module No Access View Only Full Edit

Existing Users

Email Full Name Company Plant/Location Department Access Level Role Reporting Manager Actions

User Roles

Role NameAccess LevelDescriptionActions

SSO Configuration

Manage Single Sign-On settings for each tenant. Company Admin can manage their own company's SSO settings.

Loading tenant configurations...

Printer Configuration

Configure network printer settings for label printing. Only Master Admin can modify settings.

Printer Settings

Label Settings

Light Dark
0 = lightest, 30 = darkest (default: 15)
Slow Fast
Slower = better quality, faster = lower quality (default: 4)

Connection Status

No test performed yet.

Email Configuration

View SMTP settings and send a test email to verify the email system is working correctly.

SMTP Settings

Host
Port
Secure (SSL)
Username
From Address

Send Test Email

Send a real test email to confirm delivery is working end-to-end.

📋 System Documentation

IT Governance & Technical Reference Guide

Product: SFM v1.11.0 | Company: STARENGTS | Generated:

📌 About SFM

SFM is a web-based Quality Control Management System developed by STARENGTS for manufacturing and laboratory environments. It centralises all quality-related operations across multiple plants, departments, and teams into one secure platform.

The system covers five core areas: QC Sample tracking (batch management, storage, expiry alerts), Equipment Calibration (schedules, certificates, audit trail), Pest Control (fly catchers, rodents, spray plans, lizard service, chemicals, meetings), Quality Walkabouts (inspections, photos, action tracking), and Reports & PDF Exports across all modules.

🏢 Multi-Plant
Supports Company → Country → State → Plant → Department hierarchy
🔒 Secure & Role-Based
8-level access control with SSO (Okta, Azure AD, Google)
📊 Full Audit Trail
Every change is logged — samples, calibration, pest activity
📄 PDF & Excel Reports
Export any module data as PDF or Excel with one click

📑 Table of Contents

1. Application Modules & Features

SFM is a multi-module web application for laboratory quality control. Each module below is accessible from the sidebar navigation.

🧪 QC Sample Management

Track laboratory samples from entry to disposal. Each sample is assigned to a physical storage location (Plant → Rack → Bin).

  • Add, edit, and check in/out samples
  • Batch ID, product name, manufacture & expiry dates
  • QR code label printing (ESC/POS thermal printers)
  • Barcode generation for samples
  • Expiry date tracking with alerts
  • Full movement audit log (transactions)
  • Excel export of sample data

⚙️ Equipment Calibration

Manage laboratory equipment calibration schedules and certificates.

  • Equipment registry with calibration due dates
  • Upload calibration certificates (PDF, max 10MB)
  • Calibration history and update audit trail
  • Overdue and upcoming calibration alerts
  • PDF certificate download and viewing
  • Excel export of calibration data

🦟 Pest Control

Full pest management system covering device monitoring, inspections, chemical usage, and reporting.

  • Fly Catcher Alerts: Log daily/weekly readings per device
  • Rodent Checks: Track rodent bait stations and findings
  • Spider Checks: Record spider activity by location
  • Spray Plans: Monthly spraying schedule with delay reasons
  • Lizard Plans: Monthly lizard control service tracking
  • Chemical Master: Manage approved pest control chemicals
  • Heatmap & Species Analysis: Visual activity dashboards
  • KPI Dashboard: Frequency-based counts with targets
  • Layout Images: Annotated plant floor plan overlays
  • PDF report export for all pest modules

📅 Pest Control Meetings

Schedule and track pest control review meetings including Minutes of Meeting (MOM).

  • Schedule regular, special, and review meetings
  • Create and track action items with owners
  • Record MOM (Minutes of Meeting) per meeting
  • Mark actions as open, in-progress, or closed
  • PDF export of meeting records

🚶 Quality Walkabouts

Conduct and document quality inspection walkthroughs across plant areas.

  • Create walkabout inspection records with categories
  • Attach photos and supporting documents
  • Add comments and observations
  • Track resolution history and closure authority
  • Filter by plant, department, and date

📊 Reports & PDF Exports

The built-in QC PDF Engine generates clean A4 PDF reports across all modules (introduced v1.1.3).

  • PDF export for pest control, meetings, calibration
  • Excel export for sample and equipment data
  • Print-to-PDF from any module
  • QR code and barcode label printing

1.1 Storage Location Hierarchy

Samples are stored in a physical hierarchy. Each level is configured by administrators:

Company → Country → State → PlantRackBin
Example: STARENGTS → India → Uttarakhand → Rudrapur Plant → Rack-A → Bin-001

1.2 Who Can Use Which Module?

Module visibility is controlled by the user's access level and module-level permissions (configurable by Master Admin).

Module View Add/Edit Delete Admin Config
🧪 QC SamplesAll usersLevel 7+Level 5+Level 2+
⚙️ Equipment CalibrationAll usersLevel 7+Level 5+Level 2+
🦟 Pest ControlAll usersLevel 7+Level 5+Level 2+
📅 Pest MeetingsAll usersLevel 6+Level 5+Level 2+
🚶 Quality WalkaboutsAll usersLevel 7+Level 5+Level 2+

* Module-level access can be fine-tuned per user by Master Admin using the User Module Access settings.

2. Data Access & Integration

2.1 Database Schema

Database Type: MariaDB 10.x (MySQL-compatible)

Database Name: qcsample

Table Name Purpose Key Fields
🔷 Core — Users & Storage
usersUser accounts and login credentialsid, email, password_hash, access_level, company_id, plant_id
user_company_accessMaps users to the companies they can accessid, user_id, company_id
user_module_accessPer-user module visibility overridesid, user_id, module_name, is_enabled
plantsPhysical plant/site locationsplantID, plantName, company_id, state_id
racksStorage racks inside a plantrackID, plantID, rackName, description
binsIndividual storage bins within a rackbinID, rackID, binNumber, maxCapacity, currentOccupancy
licensesSystem license keys and validitylicense_id, license_key, valid_from, valid_until
printer_configThermal label printer settings per plantid, plant_id, printer_ip, printer_port, label_format
🧪 QC Samples
samplesQC sample recordsbatchID, productName, dateManufactured, dateExpiry, binID, plantID
transactionsSample check-in / check-out historytransactionID, batchID, action, performedBy, timestamp
expiry_updatesAudit log for expiry date changesupdateID, batchID, oldExpiry, newExpiry, updatedBy, timestamp
⚙️ Equipment Calibration
equipment_calibrationsEquipment register with calibration datesequipmentID, equipmentName, lastCalibrationDate, nextCalibrationDate
calibration_documentsUploaded PDF calibration certificatesdoc_id, equipmentID, file_path, upload_date
calibration_updatesHistory of calibration date changesupdateID, equipmentID, oldDate, newDate, updatedBy, timestamp
🦟 Pest Control (17 tables)
pest_devicesFly catchers, rodent stations, and other devicesid, plant_id, device_type, location, device_code
pest_insect_readingsFly catcher count readings per deviceid, device_id, reading_date, count, recorded_by
pest_insect_species_countsSpecies breakdown per fly catcher readingid, reading_id, species_name, count
pest_rodent_checksRodent bait station inspection recordsid, plant_id, check_date, station_id, findings
pest_spider_checksSpider activity inspection recordsid, plant_id, check_date, location, findings
pest_spray_trackingMonthly spray plan schedule and completionid, plant_id, month, year, status, delay_reason
pest_lizard_serviceMonthly lizard control service trackingid, plant_id, month, year, status, delay_reason
pest_chemical_masterApproved pest control chemicals registryid, chemical_name, active_ingredient, approved_for
pest_meetingsPest control review meetingsid, plant_id, meeting_date, meeting_type, status
pest_action_itemsAction items from pest meetingsid, meeting_id, action_description, owner, due_date, status
pest_control_planAnnual pest control service planid, plant_id, year, service_type, schedule
pest_species_analysisSpecies trend analysis dataid, plant_id, period, species, total_count
pest_heatmap_configHeatmap display configurationid, plant_id, grid_rows, grid_cols, config_json
pest_layout_imagesPlant floor plan images for pest overlayid, plant_id, image_path, uploaded_at
pest_activity_logPest activity audit logid, plant_id, event_type, description, created_at
pest_control_documentsUploaded pest control service documentsid, plant_id, doc_type, file_path, upload_date
🚶 Quality Walkabouts (5 tables)
quality_walkaboutsWalkabout inspection recordsid, plant_id, walkabout_date, category_id, status, created_by
quality_walkabout_attachmentsPhotos and documents attached to walkaboutsid, walkabout_id, file_path, file_type, uploaded_at
quality_walkabout_commentsComments on walkabout recordsid, walkabout_id, comment, commented_by, created_at
quality_walkabout_historyStatus change history for walkaboutsid, walkabout_id, old_status, new_status, changed_by, timestamp
walkabout_categoriesCategory types for walkabout inspectionsid, category_name, description, is_active

2.2 Access Control Matrix

The system implements an 8-level hierarchical access control system:

Level Role Scope Key Permissions
1Platform OwnerAll CompaniesFull system access, user management, system configuration — info@starengts.com
2Company AdminCompany-wideManage all data within company, create users
3Country AdminCountry-wideManage all data within country
4State AdminState/Region-wideManage all data within state/region
5Plant AdminSingle PlantManage samples and equipment at assigned plant
6Department ManagerDepartmentManage department-specific samples and equipment
7Regular UserLimitedAdd/edit samples, view equipment, generate reports
8ViewerRead-onlyView-only access, no modifications

2.3 External Services & APIs

Email Service: Hostinger SMTP (via Nodemailer)

Purpose: Password reset OTP delivery, system notifications

Protocol: SMTP with TLS encryption

Configuration: Defined in environment variables (EMAIL_HOST, EMAIL_PORT, EMAIL_USER)

2.4 System Dependencies

Backend Dependencies

  • express ^4.18.2
  • mariadb ^2.5.6
  • express-session ^1.18.1
  • connect-redis ^8.0.1
  • redis ^4.7.0
  • bcryptjs ^2.4.3
  • nodemailer ^7.0.10
  • multer ^1.4.5-lts.2
  • exceljs ^4.3.0
  • xlsx ^0.18.5
  • compression ^1.8.1
  • cors ^2.8.5
  • dotenv ^17.2.3
  • axios ^1.13.2

Frontend Dependencies

  • Vanilla JavaScript (ES6+)
  • Chart.js (via CDN)
  • QRCode.js (via CDN)
  • JsBarcode (local library)
  • HTML5 & CSS3

2.5 Integration Capabilities

✅ Supported Integrations:

  • REST API: JSON-based endpoints for all CRUD operations
  • Excel Export: Sample and equipment data export to .xlsx format (exceljs + xlsx)
  • PDF Reports: QC PDF Engine generates clean A4 reports for pest control, meetings, and calibration (introduced v1.1.3)
  • QR Code Labels: QR codes generated on-screen for sample identification
  • Thermal Label Printing: ESC/POS compatible printers for label printing (print-processor.js)
  • Email / OTP: Hostinger SMTP via Nodemailer for password reset OTPs and notifications
  • File Uploads: PDF calibration certificates stored server-side (Multer, 10MB limit)
  • SSO / OIDC: OpenID Connect integration with Okta, Azure AD, Google Workspace

3. Security & Compliance

3.1 Storage Architecture

Server Specifications:

  • Hosting: VPS (Virtual Private Server)
  • RAM: 8GB DDR4
  • CPU: 2 vCPU Cores
  • Storage: 100GB SSD
  • OS: Linux-based

File Storage Structure:

  • /app/data/ - Application data directory
  • /app/data/backups/ - Database backup files
  • /app/data/logs/ - System log files
  • /app/uploads/ - User-uploaded files
  • /app/uploads/calibration-docs/ - Calibration PDF certificates

3.2 Enterprise Authentication

Multi-Tenant Authentication Architecture

Our platform supports multiple authentication methods per tenant, allowing each company to use their preferred identity provider while maintaining a unified user experience.

🔑
Local Login

Email & Password
bcrypt hashing

🔐
SSO / OIDC

Okta, Azure AD
Google Workspace

🏢
Tenant Isolation

Per-company config
Domain-based detection

🛡️
Session Security

Redis-backed sessions
Instant revocation

Platform Security Stack

Authentication:

  • Session-based with Redis persistence
  • OIDC (OpenID Connect) for SSO
  • bcrypt password hashing (10 salt rounds)
  • Per-tenant auth configuration

Transport & Network:

  • TLS 1.2+ (HTTPS enforced)
  • Secure, httpOnly session cookies
  • CORS policy configured
  • Firewall + VPN access control

Supported Identity Providers

Provider Protocol Features Status
Okta OIDC SSO, MFA, auto user provisioning ✅ Supported
Microsoft Azure AD OIDC SSO, MFA, directory sync ✅ Supported
Google Workspace OIDC SSO, Google account login ✅ Supported
Local Authentication Email/Password bcrypt hashing, password reset via OTP ✅ Default
Custom OIDC Provider OIDC Any OIDC-compliant identity provider ✅ Supported

How Multi-Tenant Authentication Works

Step 1: Tenant Detection

When a user enters their email, the system automatically detects their company (tenant) by the email domain (e.g., @example.com, @yourcompany.com).

Step 2: Auth Method Selection

Based on the tenant configuration, the system either shows the password field (local auth) or redirects to the company's identity provider (SSO).

Step 3: Authentication

For SSO: User authenticates with their corporate IdP (Okta/Azure/Google). For local: Password is verified against bcrypt hash in database.

Step 4: Session Created

A secure server-side session is created (stored in Redis) with user's access level, company scope, and permissions. Session cookie is httpOnly and secure.

Per-Tenant Configuration

Each company can be independently configured with their preferred authentication method:

Company Domain Auth Method Fallback
Example Corp example.com Local (SSO-ready for Okta) Local password
Your Company yourcompany.com Local authentication -
[New Company] company.com OIDC / Local / SAML Configurable

🔒 Why Session-Based + Redis?

Enterprise-Grade Session Management:

  • Immediate Revocation: Sessions can be terminated instantly if unauthorized access is detected - critical for laboratory environments
  • Server-Side Control: Session data stays on server (Redis), reducing client-side attack surface
  • Persistence: Redis-backed sessions survive server restarts - users stay logged in during deployments
  • Scalability: Shared Redis store enables horizontal scaling with multiple app instances
  • Audit Trail: Complete visibility into active sessions and concurrent users for compliance
  • SSO Compatible: Works seamlessly with both OIDC SSO and local authentication

Authentication Flows

🔑 Local Authentication Flow
1. User enters email + password
   ↓
2. System detects tenant by email domain
   ↓
3. Tenant auth_type = 'local'
   → Show password field
   ↓
4. POST /api/login
   → bcrypt.compare(password, hash)
   ↓
5. Session created in Redis
   → Secure cookie set
   ↓
6. User redirected to dashboard
   (access filtered by level)
🔐 SSO (OIDC) Authentication Flow
1. User enters email
   ↓
2. System detects tenant by email domain
   ↓
3. Tenant auth_type = 'oidc'
   → Redirect to IdP (Okta/Azure/Google)
   ↓
4. User authenticates at IdP
   → MFA if configured by company
   ↓
5. IdP redirects back with auth code
   → Server exchanges code for tokens
   ↓
6. User matched/created in database
   → Session created in Redis
   ↓
7. User redirected to dashboard
   (access filtered by level)

8-Level Hierarchical Access Control

Level Role Scope Data Access
1 Platform Owner All companies Full system access, SSO configuration, user management across tenants
2 Company Admin Own company All data within their company, user management
3 Country Admin Country-wide All plants and departments in their country
4 State Admin State-wide All plants and departments in their state
5 Plant Admin Plant-level All departments within their plant
6 Department Manager Department only Own department data, team management
7 Regular User Limited Create/edit own records within assigned scope
8 Viewer Read-only View data only, no modifications allowed

IT Governance Q&A

❓ How are passwords stored?

Passwords are hashed using bcrypt with 10 salt rounds before storage. Plain text passwords are never stored. SSO users have no local password at all - authentication is delegated to their corporate identity provider.

❓ Does the system support Single Sign-On (SSO)?

Yes. The platform supports OIDC (OpenID Connect) SSO with any compliant identity provider including Okta, Microsoft Azure AD, and Google Workspace. Each tenant can be independently configured with their preferred IdP. SSO can be enabled/disabled per company at any time without affecting other tenants.

❓ Can sessions be forcibly terminated?

Yes. Server-side sessions (stored in Redis) can be destroyed instantly by administrators. This is critical for security incidents or when employee access needs immediate revocation - regardless of whether they logged in via SSO or local credentials.

❓ What happens if the server restarts?

Sessions are stored in Redis (persistent key-value store), so users remain logged in during server restarts and deployments. Redis data is persisted to disk with append-only file (AOF) mode.

❓ How is tenant data isolated?

Every database query is filtered by the user's company_id and access_level. A user from Company A cannot access or modify data belonging to Company B. This is enforced at the server-side query level, not just the UI. The access control middleware validates tenant ownership on every API request.

❓ How is brute-force attack prevented?

Password reset OTPs have rate limiting (3 requests/hour, 5 verification attempts). Additional rate limiting is implemented at the reverse proxy level (nginx). SSO users are protected by their IdP's own security policies (MFA, lockout, etc.).

❓ Can our company use MFA (Multi-Factor Authentication)?

Yes. When using SSO with Okta, Azure AD, or Google, MFA is enforced by your corporate identity provider. This means your existing MFA policies (SMS, authenticator app, hardware keys) are automatically applied to SFM logins.

❓ How are user permissions enforced?

Hierarchical access control is enforced at the database query level. Each user has an access_level (1-8) and associated organizational scope (company, country, state, plant, department). Queries automatically filter results based on user context. SSO users are assigned appropriate access levels during provisioning.

❓ Can we enable SSO without disrupting existing users?

Yes. SSO can be enabled with a "local fallback" option, meaning users who haven't been migrated to SSO can still log in with their email/password. When ready, local fallback can be disabled to enforce SSO-only access for your company.

Production Security Checklist

Security Control Status
SSL/TLS Certificate (HTTPS)✅ ACTIVE
Password Hashing (bcrypt, 10 rounds)✅ ACTIVE
Secure Session Cookies (httpOnly, secure, sameSite)✅ ACTIVE
Redis Session Persistence✅ ACTIVE
Multi-Tenant SSO (OIDC)✅ ACTIVE
Tenant Data Isolation✅ ACTIVE
SQL Injection Protection (Parameterized Queries)✅ ACTIVE
CORS Policy Configured✅ ACTIVE
Firewall + VPN Access Control✅ ACTIVE
Environment Variables (secrets in .env)✅ ACTIVE
8-Level Hierarchical Access Control✅ ACTIVE
MFA Support (via IdP)✅ ACTIVE
Rate Limiting (login/OTP)✅ ACTIVE
Automated Vulnerability Scanning⚠️ RECOMMEND

3.3 Data Encryption & Protection

✅ In Transit

  • TLS 1.2+ for all HTTPS traffic
  • Secure WebSocket connections
  • SMTP TLS for email

⚠️ At Rest

  • Database: MariaDB default (upgradeable to encrypted tablespaces)
  • Files: Server filesystem (upgradeable to encrypted volumes)
  • Backups: Cloud VPS storage

3.4 Backup & Disaster Recovery

Backup Strategy

Frequency: Weekly (upgradeable to daily)

Method: MariaDB mysqldump

Storage: Cloud VPS

Retention: 4 weeks (recommended)

Recovery Plan

RTO (Recovery Time Objective): < 4 hours

RPO (Recovery Point Objective): 7 days (weekly backup)

Procedure: Automated restore script available

Testing: Quarterly restore drills recommended

3.5 Compliance & Audit Trails

Audit Logging

The system maintains comprehensive audit trails for:

  • Sample Transactions: All movements logged in transactions table with timestamp, user, and action
  • Expiry Updates: Complete history in expiry_updates table (who, when, old value, new value)
  • Calibration Changes: Full audit trail in calibration_updates table
  • User Actions: Login/logout events, access attempts
  • Data Modifications: Timestamp and user tracking on all critical tables

Compliance Readiness

  • ✅ Data integrity controls (foreign keys, constraints)
  • ✅ User authentication and authorization
  • ✅ Audit trail for all modifications
  • ✅ Role-based access control (8 levels)
  • ⚠️ GDPR: Data retention policies recommended
  • ⚠️ ISO 27001: Additional controls may be required

4. System Lifecycle & Maintenance

4.1 Development Workflow

Development → Testing → Staging → Production

1. LOCAL DEVELOPMENT
   - Developer workstation with Node.js
   - Local MariaDB instance for testing
   - npm run dev (nodemon for hot reload)

2. VERSION CONTROL
   - Git repository for source control
   - Branch strategy: main (production), dev (development)
   - Commit messages follow conventional commits

3. TESTING
   - Manual QA testing
   - Database migration scripts tested in isolation
   - User acceptance testing (UAT)

4. DEPLOYMENT
   - VPS deployment via Git pull
   - Environment variables configured via .env
   - npm start for production mode
   - Process manager (PM2/systemd) for auto-restart

4.2 Maintenance Schedule

Task Frequency Responsible Notes
Database BackupWeeklyIT AdminAutomated via cron job
Backup VerificationMonthlyIT AdminTest restore procedure
Security UpdatesMonthlyIT Adminnpm audit, OS patches
Log ReviewWeeklyIT AdminCheck for errors/anomalies
Database OptimizationQuarterlyDatabase AdminOPTIMIZE TABLE, index review
Disk Space MonitoringWeeklyIT AdminAlert at 80% capacity
SSL Certificate RenewalAnnuallyIT Admin90-day reminder
User Account AuditQuarterlyMaster AdminRemove inactive users
Performance ReviewSemi-AnnuallyIT AdminQuery optimization, caching

4.3 Documentation Locations

README.mdProject overview and quick start guide
API-DOCUMENTATION.mdAPI endpoints and usage examples
CHANGELOG.mdVersion history and release notes
.env.exampleEnvironment configuration template
qcsample.sqlComplete database schema
This PageSystem Documentation (IT governance reference)

4.4 Support Model

📧 Contact Information

Support Email: info@starengts.com

Company: STARENGTS

Product: SFM

Version: 1.4.0

⏰ Support Hours

Response Time: Business hours

Critical Issues: 24-hour SLA

Non-Critical: 48-hour SLA

Escalation: Email support team

4.5 Incident Response Procedure

🚨 Emergency Response

  1. Identify: Determine severity (Critical, High, Medium, Low)
  2. Isolate: If security breach suspected, isolate affected systems
  3. Notify: Alert Master Admin and IT team via info@starengts.com
  4. Document: Log all details, actions taken, timeline
  5. Resolve: Apply fix, restore from backup if necessary
  6. Verify: Test resolution, confirm system stability
  7. Review: Post-incident analysis and preventive measures

5. Technical Architecture

5.1 Complete Technology Stack

⚙️ Backend Stack

  • Runtime: Node.js v14+
  • Framework: Express.js v4.18.2
  • Language: JavaScript (ES6+)
  • Database: MariaDB v3.4.5
  • ORM/Driver: mariadb (native driver)

🎨 Frontend Stack

  • Framework: None (Vanilla JS)
  • Language: JavaScript ES6+
  • Markup: HTML5
  • Styling: CSS3 (custom)
  • Charts: Chart.js (CDN)
  • QR Codes: QRCode.js (CDN)
  • Barcodes: JsBarcode (local)

🔒 Security & Auth

  • Sessions: express-session v1.18.1
  • Hashing: bcryptjs v2.4.3
  • CORS: cors v2.8.5
  • Environment: dotenv v17.2.3
  • SSL/TLS: HTTPS enabled

📊 Data & Files

  • Excel: exceljs v4.3.0
  • Email: nodemailer v7.0.10
  • Uploads: multer v1.4.5-lts.2
  • HTTP Client: axios v1.13.2

5.2 Infrastructure Details

🖥️ Production Server

URL:https://qcapplication.starengts.com
Hosting:VPS
RAM:8GB
CPU:2 vCPU cores
Storage:100GB SSD
OS:Linux

🗄️ Database Server

Engine:MariaDB 10.x
Location:Same VPS
Port:3306
SSL:Enabled
Connections:10 pool limit
Charset:utf8mb4_unicode_ci

System Architecture Diagram

┌─────────────────────────────────────────────────────────────────┐
│                        CLIENT LAYER                              │
│  ┌───────────────┐  ┌───────────────┐  ┌───────────────┐       │
│  │   Desktop     │  │    Tablet     │  │    Mobile     │       │
│  │   Browser     │  │   Browser     │  │   Browser     │       │
│  └───────┬───────┘  └───────┬───────┘  └───────┬───────┘       │
└──────────┼──────────────────┼──────────────────┼───────────────┘
           │                  │                  │
           └──────────────────┴──────────────────┘
                              │
                         HTTPS/TLS
                              │
┌─────────────────────────────┼───────────────────────────────────┐
│                    VPS SERVER (8GB RAM, 2 CPU)                   │
│                              │                                   │
│  ┌───────────────────────────┴────────────────────────┐         │
│  │          NGINX REVERSE PROXY                       │         │
│  │     (SSL Termination, Load Balancing)              │         │
│  └───────────────────────┬────────────────────────────┘         │
│                          │                                       │
│  ┌───────────────────────┴────────────────────────────┐         │
│  │        NODE.JS APPLICATION SERVER                  │         │
│  │                                                     │         │
│  │  ┌─────────────────────────────────────────────┐  │         │
│  │  │         EXPRESS.JS FRAMEWORK                │  │         │
│  │  │                                             │  │         │
│  │  │  • Session Management (express-session)    │  │         │
│  │  │  • Authentication (bcrypt)                 │  │         │
│  │  │  • API Routes (/api/*)                     │  │         │
│  │  │  • Static File Serving                     │  │         │
│  │  │  • Multer (File Uploads)                   │  │         │
│  │  └─────────────────────────────────────────────┘  │         │
│  └────────────┬────────────────────┬──────────────────┘         │
│               │                    │                            │
│  ┌────────────┴─────────┐  ┌───────┴──────────┐               │
│  │   MARIADB DATABASE   │  │  FILE SYSTEM     │               │
│  │                      │  │                  │               │
│  │  • qcsample DB       │  │  • /uploads/     │               │
│  │  • 42+ Tables        │  │  • /data/        │               │
│  │  • Connection Pool   │  │  • /backups/     │               │
│  └──────────────────────┘  └──────────────────┘               │
│                                                                 │
│  ┌──────────────────────────────────────────────────────────┐  │
│  │              EXTERNAL SERVICES                           │  │
│  │                                                           │  │
│  │  • Hostinger SMTP (Email/OTP Delivery)                  │  │
│  │  • Okta / Azure AD / Google (OIDC SSO)                  │  │
│  │  • ESC/POS Thermal Printer (Label Printing)             │  │
│  │  • Cloud VPS Storage (Backups)                          │  │
│  └──────────────────────────────────────────────────────────┘  │
└─────────────────────────────────────────────────────────────────┘

5.3 Enterprise Alignment

✅ Enterprise-Ready Features

  • Multi-Tenancy: Company/Country/State/Plant/Department hierarchy supports multiple organizations
  • Role-Based Access: 8-level granular permission system
  • Scalability: Database connection pooling, stateless architecture ready
  • Security: Industry-standard authentication, encryption, audit trails
  • Reliability: Transaction support, referential integrity, automated backups
  • Compliance: Complete audit logging, data retention controls
  • Integration: REST API, Excel export, email notifications

5.4 Scalability & Performance

Component Current Capacity Upgrade Path
Concurrent Users~50-100 usersAdd Redis session store, horizontal scaling
Database Size~10-50GBIncrease VPS storage, database partitioning
File Storage100GB SSDS3-compatible object storage (MinIO, AWS S3)
API Performance~100 req/secLoad balancer, CDN for static assets, caching
Backup SizeWeekly backupsIncremental backups, cloud backup service

5.5 Future Roadmap

📅 Planned Enhancements

✅ Already Completed: Redis session store, OIDC/SSO (Okta, Azure AD, Google), PDF report engine (QCPdfEngine), Pest Control module, Quality Walkabouts module, Thermal label printing.

🔜 Short Term (3-6 months)

  • Database encryption at rest
  • Automated daily backups (currently weekly)
  • Advanced search and filtering across modules
  • Mobile-responsive UI improvements

🎯 Medium Term (6-12 months)

  • SAML 2.0 SSO support (in addition to OIDC)
  • Real-time notifications (WebSockets / push)
  • Advanced analytics dashboard with trends
  • API rate limiting and throttling
  • Multi-language support (i18n)

🚀 Long Term (12+ months)

  • Native mobile app (iOS / Android)
  • Microservices architecture migration
  • Machine learning for predictive calibration and pest trends
  • IoT sensor integration for real-time readings
  • Cloud-native deployment (Kubernetes / Docker Swarm)

5.6 Known Technical Debt

⚠️ Items for Consideration

  • Monolithic Code: server.js is ~12,400 lines — a single file for all routes. Future refactor into separate route files is recommended as the app grows.
  • Large Frontend File: index.html is ~1.5MB with embedded JavaScript. Consider splitting into modular JS files or using a frontend framework (Vue/React) for easier maintenance.
  • API Versioning: No formal API versioning — implementing /api/v1/ structure would help future compatibility.
  • Automated Testing: No automated test suite — unit and integration tests are recommended as features grow.
  • Monitoring: No APM (Application Performance Monitoring) — consider New Relic, DataDog, or open-source Prometheus/Grafana for production visibility.
  • Error Tracking: Basic console logging — consider Sentry or similar for production error alerting.

SFM v1.11.0
© STARENGTS - All Rights Reserved
For support: info@starengts.com

Document generated:
This document contains confidential and proprietary information.

Enter New Sample

Please fill in all required fields!

Label Size Configuration

Label Preview (100mm × 40mm)

Transfer Samples Between Bins

Equipment Calibration

Calibration Register

Status Equipment ID Model Number Equipment Name Equipment used for Location Verification Method Certification Last Calibration Date Calibration Interval (Days) Next Calibration Date Alert Status Action

Calibration Update History

Status Equipment ID Equipment Name Old Next Calibration Date New Next Calibration Date Updated On Updated By

Search Samples

Status Batch Number Product Name Mfg Date Expiry Entered By Storage Created On Action

Log Sample Transactions

Log Take Out

Log Return

Retrieval History (One Row per Cycle)

Batch Number Product Name Take Out Date Take Out By Return Date Return By

Expiry Date Modification History

Status Batch Number Product Name Original Expiry New Expiry Modified By Modified On Reason

Retrieval History

Batch Number Product Name Take Out Date Take Out By Return Date Return By

📊 Sampling Management Analytics

Sample tracking, expiry analysis, and storage utilization insights

📦
0
Total Active Samples
⚠️
0
Critical (<15 days)
0
Expired Samples
0
Pending Transactions

Expiry Status Distribution

Top 10 Products by Sample Count

Storage Location Utilization

Sample Transaction Status

Sample Age Distribution

🔧 Equipment Calibration Analytics

Calibration status, overdue tracking, and equipment compliance insights

⚙️
0
Total Equipment
🚨
0
Overdue Calibration
0
Due in 7 Days
0
Due in 15 Days

Calibration Status Overview

Equipment Status

Calibration Frequency Distribution

Monthly Calibration Trends

📋 Quality Walkabout Analytics

Walkabout status, action tracking, and quality observation insights

🔵
0
Open
🚨
0
Overdue
0
Due in 7 Days
0
Closed
🔴
0
Critical Open
Avg Close (days)
🔁
0
Repeat Issues
📝
0
Draft Pending

Status Distribution

Due Date Status

By Observation Location

Monthly Trends — Raised vs Closed

Severity Breakdown

By Category (Open)

Action Person Workload

Severity Trend (6 months)

🦟 Pest Control Analytics

Pest activity trends, device monitoring, and treatment effectiveness insights

📅 Year
📍
0
Active Devices
🪰
0
Fly Catcher Alerts
🔴 Critical 0
🟡 Non-Critical 0
🐀
0
Rodent Alerts
Devices with EB / M / S / G status
💨
0
Treatments (2026)
✅ Done 0
📋 Planned 0
⚠️ Delayed 0
🦎
0
Lizard Plan (2026)
✅ Done 0
📋 Planned 0
⚠️ Delayed 0
📝
0
Readings (2026)
🪰 FC - Internal 0
🪰 FC - External 0
🐀 Rodent (Cake) 0
🐀 Rodent (Pad) 0
🕷 Spider Pad 0

Device Status Distribution

Pest Activity by Location

Treatment Effectiveness

📊 Deep Dive Analytics

Device Type Distribution

Pest Types Detected

Weekly Activity Pattern

Inspection Compliance Rate

📈 Performance Metrics

Activity Severity Index

Top Risk Areas

Device Monitoring Activity

📊 Monthly Pest Count Comparison

Monthly Pest Count 2025-26

MOM % Reduction vs Previous Year

--- Target 2% reduction

🕐 Pest Control Activity Log

Complete audit trail of all pest control actions — devices, readings, spray, meetings, and MOM action items.

Time Category Action By Details
Loading...

💾 Master Data Analytics

System-wide overview of plants, storage capacity, and user management

🏭
0
Total Plants
📚
0
Total Racks
🗄️
0
Total Bins
📋
0
Total Products

Storage Capacity by Plant

Bin Occupancy Rate

Products by Category

User Role Distribution

🎛️ Admin Dashboard - Master Data Analytics

System-wide overview of plants, storage capacity, and user management

📊 Sampling Management Analytics

📦
0
Total Active Samples
⚠️
0
Critical (<15 days)
0
Expired Samples
0
Pending Transactions

Expiry Status Distribution

Top 10 Products by Sample Count

Storage Location Utilization

Sample Transaction Status

Sample Age Distribution

🔧 Equipment Calibration Analytics

⚙️
0
Total Equipment
🚨
0
Overdue Calibration
0
Due in 7 Days
0
Due in 15 Days

Calibration Status Overview

Equipment Status

Calibration Frequency Distribution

Monthly Calibration Trends

📋 Quality Walkabout Analytics

0
Open
0
Overdue
0
Due in 7 Days
0
Closed

Status Distribution

Due Date Status

By Observation Location

💾 Master Data Analytics

🏭
0
Total Plants
📚
0
Total Racks
🗄️
0
Total Bins
📋
0
Total Products

Storage Capacity by Plant

Bin Occupancy Rate

Products by Category

User Role Distribution

Storage Configuration

Storage Configuration

Note: Plant selection is based on your access permissions

Add Rack

Add Bin

View & Edit Configuration

Quality Walkabout Register

📝 Create New Quality Walkabout

📋 Open Walkabouts

UID Date Raised Reporter Location Category Subject Action Person Due Date Status Actions

Quality Walkabout History

UID Date Raised Reporter Location Category Subject Action Person Due Date Status Closed By Closed At Actions

My Walkabout Actions

Walkabouts where you are the assigned Action Person - please review and take action before the due date.

UID Date Raised Reporter Location Category Subject Description Due Date Status Actions

Walkabout Activity Log

Complete audit trail of all walkabout actions — created, submitted, updated, closed, reopened, comments and attachments.

Time Walkabout UID Action By Prev Status Current Status Details

👥 Pest Control Team

Name Email Department Function Actions
Loading...

Pest Control Master Plan

Plan Done Delayed
S.No Activities Owner JAN FEB MAR APR MAY JUN JUL AUG SEP OCT NOV DEC Actions
Loading annual plan...
Doc Ref: - Version: - Review Date: - Effective Date: - SOP No: -

Pest Control Layout

🗺️ Pest Control Device Layout

No layout image uploaded. Click "Upload Layout" to add one.

📋 Layout Revision Control

Track changes and updates to the pest control layout map

Rev No Date Reason of Review Actions
Loading revision history...

Pest Control Device Master

0 Active  |  0 Inactive | 0 Maintenance
Device ID Type Location Area Placement Status Actions
Loading...

🧪 Pest Master

➕ Add New Chemical

Pest Chemical List

# Chemical Name Default Dosage Category Status Added By Actions
Loading...

Pest Control Readings Entry

Flycatcher - Internal

Click count cell to enter species-wise breakdown

0-5 Low 6-10 Medium >10 High
Device ID Location Area 1st Fortnight (1-15) 2nd Fortnight (16-31)
Count Remarks Count Remarks
Select month, then click Load Data

Spray Tracking Plan

📅 Year
Plan Done Delayed
S.No Activity Owner JAN FEB MAR APR MAY JUN JUL AUG SEP OCT NOV DEC Actions
Loading spray plan...

Pest Control Spray Tracking

💨 Log Spray Activity

Spray History

Date Type Spray Type Chemical Done By Verified By Areas Actions
Loading...

🦎 Lizard Management Plan

📅 Year
Plan Done Delayed
S.No Activity Owner JAN FEB MAR APR MAY JUN JUL AUG SEP OCT NOV DEC Actions
Loading lizard plan...

🦎 Lizard Management Service

Service History

Date Type Chemical Service By Verified By Next Service
Loading...

Pest Control Documents

📄 Upload New Document
Document Name Category Current Ver. File Uploaded By Uploaded At Expiry Date Actions
Loading...

Pest Control Meetings

👥 Schedule New Meeting

📋 Meeting History

DateTypeTitleCreated ByActions
Loading...

📊 MOM Action Items

Total YTD
Closed On Time
Delayed
Repeated
On-Time Closure %
# B. Date C. Observation / Recommendation D. Root Cause E. Device / Area F. Action Decided G. Responsibility H. Target Date I. Completion Date J. Revised Target K. Repeated L. Status M. Verified On N. Verified By O. Remark Actions
Loading action items...

Pest Control Reports

0-5 Low 6-10 Med >10 High

Flycatcher Tracking - Internal

Monthly insect count data by device (internal). Green = Low (0-5), Yellow = Medium (6-10), Red = High (>10)

Loading heatmap data...

📋 Custom Report Generator

Report Preview

Select report type and parameters, then click Generate Report

Blue Cards

0

My Blue Cards

0

Admin View

0

🟦 Blue Cards — Data Visualization

Submission momentum, lifecycle health, savings impact and recognition insights

📅 Range

Momentum — cards submitted
Actual vs 3-period moving average, with trend projection
Status Breakdown
Where cards sit in the lifecycle
Cards by Category (4C)
A card can carry more than one category
Cards by Zone
Where improvements are being raised
Lifecycle funnel
Conversion and drop-off at each stage — where cards die
Velocity — how fast we act
Average days spent waiting at each stage
Aging backlog
Open cards by age — the oldest need chasing
🏆 Top Performers
Top 3 in every category — most implemented, most rewarded, biggest savings
Contributors — who is raising cards
Cards submitted per person, with the status of their cards
Zone performance
Volume, implementation rate and savings by zone
Working places by zone
Cards, implementation rate and savings for each working place, grouped by zone

Activity Log

0

Full create / update / delete trail for Blue Cards in your scope, with before→after values. Isolated by your access level.

Loading…

Blue Cards Settings

Checklist Templates

0
NameCategoryScopeStatusVersionModifiedActions

Run a Checklist

Pick a checklist to start a new run.

Checklist History

ChecklistWhereWhoWhenDueProgressSign-offResultStatus