IMS Documentation
IMS Build 9.4.4.0 • IMS Global 1.4.0

IMS Global

Central IMS administration for companies and database provisioning, global users/company access, Business API clients/keys, workstations, cross-company tools and system version control.

Administration boundaryIMS Global is a separate administration application. It is not the screen used for normal company transactions or company-local operational permissions.

Access and Security Guard

IMS Global validates the workstation through IMS.Api, authenticates the global user, enforces required password changes and then requests a Global Administrator session. The main window identifies the session as Global Administrator • Security Guard. Each administration module revalidates the session before opening.

Administration modules

ModulePurpose
CompaniesMaintain company identity/regional data and the company database profile; create a new company database through Create DB.
UsersMaintain global users, account state, password reset, Global Administrator flag, company access and exactly one default company.
Clone PoliciesCopy selected Group Policy definitions between company databases after validating compatible policy schemas.
Clone SuppliersCopy a supplier and its brands between companies; optionally clone related item master data and dependent merchandise data.
API AdministrationManage External Business API clients, company/scoped access, API keys, rate limits, request monitoring and the API-administration audit trail.
WorkstationsReview registered workstations and approve/block authorization. The workstation currently running IMS Global cannot block itself.
System VersionMaintain the global IMS Assembly Version, Loader Version and Critical-update flag through IMS.Api.
Operations LogDisplay administration progress/success/warning/error messages for the current IMS Global session.

Companies and database profiles

The Companies screen stores Company Code, Company Name, Country Code, Calling Code, Currency Code, Time Zone and active status. The database profile contains Description, Host / Server, Port, Database Name, Username, Database Password, SSL Mode and Database Active.

The saved database password is not repopulated into the password field. The screen shows whether a password is already stored; leaving the field blank retains the current secret when editing an existing profile.

Create a company database

  1. Create or select the company and complete its database profile.
  2. Enter the intended company database password.
  3. Click Create DB.
  4. Confirm the company, Database and target Server.
  5. Enter PostgreSQL administrator credentials when IMS Global prompts for them.
  6. Wait for the Create Company Database operation to complete.

IMS Global creates and initializes the company database. Database creation is an IMS Global administration task, not a manual PostgreSQL setup procedure. After the operation succeeds, the company database password is secured through IMS.Api.

Use IMS GlobalDo not create, clone or initialize a company database manually. The supported workflow is IMS Global → Companies → Create DB.

Change a company database login or password

The Company database profile keeps the IMS Client database login separate from the stored password. A saved password is never repopulated into the password field; leave the field blank to keep the current secret.

When an administrator changes the database password for an existing company, IMS Global prompts for a privileged PostgreSQL account. IMS Global uses that temporary privileged session to change the operational IMS Client role, validates the new login and only then asks IMS.Api to secure the updated password in the company profile.

If the database Username is changed, IMS Global again requests a privileged PostgreSQL account. The target login role is created when missing (or reused when it already exists), configured with the permissions required by the IMS Client, validated against the company database and then saved into the company profile.

Privileged PostgreSQL credentials are temporaryThe administrator credentials entered in the prompt are used for the current role/database operation. They are not the company runtime login and are not stored as the company database password.

API Administration

IMS Global 1.4 adds the API Administration center for the External Business API v1. It is the supported interface for creating API clients, assigning company access/scopes, controlling request limits and managing API-key lifecycle.

TabPurpose
DashboardSummary of API clients, active keys, recent requests/failures and request timing.
ClientsCreate/edit API clients, Active state, Valid From/Until and Requests per minute/day.
Companies & ScopesAssign the companies a client may call and the approved read scopes.
API KeysGenerate, rotate and revoke API keys. The complete key is displayed once when generated/rotated; existing keys cannot be recovered.
Request LogReview client/company, endpoint, HTTP status, duration, rows returned, remote IP and controlled error code. Times are presented in local workstation time.
Admin AuditReview API administration actions such as client/access changes and key create/rotate/revoke operations. Times are presented in local workstation time.

Business API v1 scopes

The current API v1 scope set is stores.read, items.read, sales.read, inventory.read, purchases.read, transfers.read, adjustments.read and promotions.read. Assign only the scopes and companies required by the external integration.

  1. Create or select the API client.
  2. Assign the permitted companies and scopes.
  3. Set client validity and request limits.
  4. Generate an API key and securely transfer the one-time displayed key to the integration owner.
  5. Use Request Log and Admin Audit to verify activity. Rotate/revoke keys when required.

For the consumer-facing contract and request examples, see Business API v1 Developer Guide.

Global Users and company access

The Users screen maintains Login Name, User Name, Email, Cell Phone, Disabled state, password-reset state and Global Administrator status. A user must have at least one company, and exactly one company is marked Default. Company rows separately record whether the user has access and whether that company is the default.

Saving a Global user writes the global identity/company assignment through IMS.Api and synchronizes the user's local profile into the assigned company databases. IMS Global requires at least one company assignment and exactly one Default company.

The Default company is also used as the policy source when IMS Global synchronizes an existing user's Group Policy assignments into other assigned companies. Matching policies are reused where available; detailed Store, Supplier, transfer and transaction rights remain company-local and are maintained from the normal IMS System → Users Accounts screen inside that company.

Self-protectionThe account currently running IMS Global cannot remove its own Global Administrator access, disable itself or reset its own password from Global Users.

Workstations

The Workstations administration screen lists registered workstation identity, machine name, authorization state, first/last seen times, fingerprint-change time, hardware fingerprint and notes. Authorized workstations can be blocked and blocked workstations can be approved. The workstation currently running IMS Global cannot block itself.

System Version

System Version maintains the global IMS Assembly Version, Loader Version and Critical-update flag through IMS.Api.

Cross-company setup tools

Clone Policies is intended for reusing selected Group Policy definitions across companies without manually rebuilding every permission set. Clone Suppliers can reuse Supplier/Brand setup and, when selected, related item master data. These are controlled setup tools; they are not a mechanism for cloning an entire company database.