01 — The Problem
Every movement had to be attributable
Stock that moves without a name against it is stock you cannot reconcile. And the staff moving it already had directory credentials — a second account per person is one more thing to provision, rotate, and forget to disable.
- Every transaction traceable to a person and a time.
- Three roles with genuinely different reach over the same data.
- No second identity store to maintain alongside the directory.
02 — What I Built
Directory sign-on, and the audit row in the same write
LDAP authenticates against the organisation's own directory and the session carries the role. Stock movement and audit record are written by one code path, so no route can move a quantity quietly.
- LDAP single sign-on, issuing role-carrying JWT sessions.
- Dynamic role and permission models for Admin, Manager and Operator.
- 169 endpoints across 26 Mongoose models, validated in middleware.
- An audit row with user and timestamp on every stock transaction.
03 — What Changed
Reconciliation has something to read
The ledger answers who moved this and when, directly, instead of that question being reconstructed from quantities. Access follows the directory: when a person leaves it, they leave the system.
- Discrepancies are traced through the audit trail rather than inferred.
- Joiners and leavers are handled once, in the directory.
- A role's reach changes in the permission model, not in a controller.