Layered entitlements
Six layers from tenant to single asset combine into one effective scope per user and per API token.
PIM Gate checks every page, every query and every file against an explicit set of entitlements: per tenant, portal, role, market and category, down to the single asset. Customers see their assortment, suppliers their products, sales reps their customers — and the audit log records who did what.
01 · What it does
Six layers from tenant to single asset combine into one effective scope per user and per API token.
Portals, API responses, exports and downloads are filtered before they are built. There is no "hidden in the UI" — what is not entitled is never sent.
Invitations, role changes, views, downloads and shares are written to an audit log that cannot be edited afterwards.
Entitlements in PIM Gate are not a single list of permissions. They are layers, each answering one question — which company, which door, which role, which market, which part of the assortment, which file. A user's or token's effective scope is the intersection of all six. Markets and categories are defined through catalog views, so the same rule that builds a portal's assortment also limits what its users can reach.
| Layer | Decides | Example | Status |
|---|---|---|---|
| Tenant | Which company's data at all | messara | ISOLATION ✓ · SUBDOMAINS 2026 |
| Portal | Which door: customer, supplier, sales | customer. · sales. | live |
| Role | What a user may do | sales rep · reviewer | 2026 |
| Market | Which countries, prices, languages | CH · de-CH, en-GB | live |
| Category | Which part of the assortment | Druckmesstechnik | live |
| Asset | Which individual files | atex_certificate.pdf | live |
A tenant is an isolated space with its own data, users, tokens and settings — typically one per brand or country company. Inside a tenant, each portal is a door for one audience, with its own catalog view, languages and branding, under a PIM Gate subdomain or your own domain with certificate included. Portal end users are unlimited in every version; you pay for your internal team, not for your customers.
Tenants & portals
One tenant per brand or country. One portal per audience.
04 · Roles
Roles bundle what a person may do — browse the catalog, see prices, download assets, submit supplier data, translate, approve, administer. Combined with the entitlement layers, the same role behaves differently per market or portal: a Swiss sales rep sees CHF prices for the Swiss assortment only. Roles and groups are yours to define; the matrix below is a starting point, not a limit.
| Role | Catalog | Prices | Assets | Submit | Translate | Approve | Admin |
|---|---|---|---|---|---|---|---|
| Sales | ✓ | ✓ | ✓ | — | — | — | — |
| Service / Customer | ✓ | — | ✓ | — | — | — | — |
| Supplier | — | — | ✓ | ✓ | — | — | — |
| Translator | ✓ | — | — | — | ✓ | — | — |
| Reviewer | ✓ | — | ✓ | — | ✓ | ✓ | — |
| Admin | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
In sales, entitlements follow relationships, not just roles. A rep is mapped to the customers they serve; each customer is linked to the agreement that defines their assortment and prices. When the rep opens a customer, the portal shows exactly that customer's catalog — ready to export as PDF or XLSX or to share — and nothing from the next customer's agreement.
Relationship scoping
A sales rep sees their customers. Each customer sees their agreement.
Machines follow the same rules as people. Each API token belongs to one tenant and is filtered by the entitlements attached to it, so a shop token for Switzerland can never read German prices. Every relevant action — invitations, role changes, token rotations, imports, automatic translations, views, downloads, shares — is written to an append-only audit log. Entries cannot be edited or deleted; retention can be extended to ten years.
Tokens & audit
Systems get scoped keys. Every action leaves a trace.
SSO is planned for the higher versions. See the roadmap for sequencing.
Identity roadmap
Enterprise identity, on the roadmap.
08 · Specifications
| Spec | Value | Status |
|---|---|---|
| Entitlement layers | TENANT · PORTAL · ROLE · MARKET · CATEGORY · ASSET | see s3 |
| Enforcement | SERVER-SIDE · PORTAL + API + EXPORT | LIVE |
| Catalog views per portal | MARKETS · LANGUAGES · RULES | LIVE |
| Tenant isolation | DATA LEVEL | — |
| Tenant subdomains · custom domains | {tenant}.pimgate.ai · YOUR DOMAIN + TLS | 2026 |
| White-label per portal | LOGO · COLORS · DOMAIN | 2026 |
| Roles & groups · admin console | CONFIGURABLE PER TENANT | 2026 |
| Relationship scoping (sales) | REP → CUSTOMER → AGREEMENT | 2026 |
| API tokens | PER TENANT · ENTITLEMENT-FILTERED | LIVE |
| Audit log | APPEND-ONLY | — |
| Audit-log UI | FILTER · SEARCH | 2026 |
| Audit retention 10 yrs | €1,200 | — |
| Portal end users | UNLIMITED | — |
| SSO OIDC / SAML · SCIM · MFA | — | ROADMAP |
09 · Works with
Put a gate between your catalog and chaos.