Tathven
Tathven ERP Security Approvals Tathven HRMS Careers Pricing Contact Request a demo
Inside the product

One hub for every module

The Tathven ERP home screen — open Inventory, Production, Sales, Payroll and the rest from one place, each writing to the same authoritative record.

Tathven ERP

Six modules,
one ledger underneath

Tathven ERP gives Indian businesses a single, authoritative record of finance, inventory, sales, purchase, production and GST. Every module writes to the same record. Post a sale and the stock, the ledger and the GST return move together.

Finance

General ledger, receivables and payables, bank reconciliation, finance books per unit and year, and posting rules an accountant can read.

Ledger · Vouchers · Reconciliation

Inventory

Multi-unit, multi-department stock with every movement documented — the count on screen is the count on the shelf.

Godowns · Movements · Valuation

Sales

Quotations to orders to dispatch and invoice, with per-channel pipelines and outstanding tracked against every customer.

Orders · Dispatch · Outstanding

Purchase

Purchase orders, supplier mapping and goods receipts that carry the vendor's bill — the payable is what you were actually charged.

Orders · Receipts · Settlement

Production

Bills of material to production orders to job orders, costed at every step, received back into stock.

BOM · Job orders · Costing

CRM

Tickets with a lifecycle, an owner and an SLA clock, raised against the same customer you invoice.

Tickets · Queues · SLA
Also on the foundation

Stakeholder, GST and the rest

One master for everyone you trade with, and Indian tax built into the model rather than added on top.

Stakeholder

Customers, suppliers and agents in one master with one code — so a name is never spelled two ways in two modules.

One record · One code

GST

HSN catalogue, place of supply resolved from the two GSTINs, and return sheets prepared from the transactions you posted.

1,657 HSN codes · Per GSTIN

Add-ons

Subscriptions and distribution, multi-channel sales, the government e-Marketplace connector, and publishing configured as the trade's own workflow.

Shipped · Optional
Security and access control

Rights you can
actually prove

A permission in Tathven is not a checkbox that hides a menu. It is one named operation, granted at one of four levels, checked by the server on every request. Around sixty of them ship across the modules.

Level 0
None

The operation does not exist for this user.

Level 1
Read

See the screen and its records. Nothing more.

Level 2
Modify

Create and change, within the module's own rules.

Level 3
Execute

Act on it — post, approve, run the process.

What a user cannot see, a user cannot do

Permissions are enforced at the server, not just hidden in the interface. The same declaration that removes a button refuses the request behind it. A scoped identity with no grant is refused by default.

Server-enforced · Default-deny

Your data is in your databases

Not your rows in a shared table. Each customer gets its own databases with its own credentials, minted when the tenant is provisioned. The tenant is resolved before any user is identified, and there is no fallback to a default database.

Per-tenant · No shared fallback

Secrets kept properly

Passwords hashed with PBKDF2-SHA256, salted, over 210,000 iterations. Stored SMTP and SMS credentials encrypted with AES-256-GCM, the key held outside the database. Machine secrets are shown once and stored only as a digest — we cannot recover one, only replace it.

PBKDF2 · AES-256-GCM

Nobody can delegate more than they hold

A scoped identity can never exceed the rights of the person who sponsors it. The clamp is applied when rights are written, and re-applied if the identity moves to a different sponsor.

Sponsor clamp

Attribution that survives churn

People are deactivated, never deleted, and keys are revoked, never removed. Every business write carries who made it, so a row written years ago still resolves to a name.

Deactivate, never delete

One switch, everything closes

Deactivating a person ends their sign-in, invalidates their access keys and drops their live sessions within about a minute — while every row they wrote still carries their name. Deactivating a sponsor cascades to the identities beneath them.

Offboarding in ~60 seconds
RolesSuper Admin, Standard User and Read-Only Auditor are built in. Role templates ship for sales, finance, inventory, production and CRM, so you start from a working matrix rather than a blank one. Per-user overrides sit on top, so one person's exception never needs a bespoke role.
FinanceCarries a second, book-level lock of its own. A user must be provisioned against a finance book to see it at all, and granting the finance role provisions the book access in the same act. Cash, bank and journal vouchers are separately grantable — separation of duties by design.
IdentitiesOrganisation users sign in with email. Scoped IAM users are sponsored by one of them and carry their own keys. Service accounts cannot sign in at all. All three resolve to one audit identity, so a row written by an integration is attributable as precisely as one written by a person.
Delegation of authority

The right approver,
in the right order, by when

Tathven routes a document to approvers by its value. A ₹40,000 purchase order takes one signature; the same order at ₹4,00,000 takes two, in sequence, each within its own deadline. The bands are yours to set, per document type.

Five things the server refuses

Checked server-side, not in the interface — which is where most systems are weaker than they sound.

  1. Acting without authority. You must hold the current level's role, the named assignment, or a valid delegation.
  2. Skipping a level. Level 2 cannot approve until level 1 has cleared.
  3. A rejection with no reason. Blank remarks are refused.
  4. Clearing a tripped floor rule. When one fires, only the top level may approve, whatever the amount.
  5. Acting without a record. Every action appends to the timeline. There is no path that does not.

Escalation is visibility, not surrender. A missed deadline notifies the pending approver and makes the request visible to the level above. It never auto-approves and it never transfers authority.

Banded approvals govern purchasing, stock and production documents, and are switched on per document type — deliberately, so a new authority schedule can be written and reviewed before it takes effect.

Goods receipt · two levels ₹2,11,780
  • Requested
    Measured at ₹2,11,780

    Matches level 2. One request opens, needing both levels in sequence. The header moves to waiting — stock does not move yet.

  • Level 1 · 24 hour deadline
    Store manager approved

    Recorded with the band that matched. The clock resets to 12 hours for the next level.

  • Anyone else
    Refused

    Acting out of turn is rejected at the server, whoever is signed in.

  • Level 2 · 12 hour deadline
    Finance controller approved

    The request completes, the header consolidates to approved, and stock is received exactly once.

Corrections are recorded, not overwritten. Requests, approvals, rejections, delegations, escalations and missed deadlines all append to a log with no update or delete path.

Request a demo

See Tathven ERP running on
your own numbers

Tell us what you run today. We will show Tathven ERP working on a sample of your own data, then send a written scope and quotation — not a brochure.