IMS Global
Central IMS administration for companies and database provisioning, global users/company access, Business API clients/keys, workstations, cross-company tools and system version control.
Access and Security Guard
IMS Global validates the workstation through IMS.Api, authenticates the global user, enforces required password changes and then requests a Global Administrator session. The main window identifies the session as Global Administrator • Security Guard. Each administration module revalidates the session before opening.
Administration modules
| Module | Purpose |
|---|---|
| Companies | Maintain company identity/regional data and the company database profile; create a new company database through Create DB. |
| Users | Maintain global users, account state, password reset, Global Administrator flag, company access and exactly one default company. |
| Clone Policies | Copy selected Group Policy definitions between company databases after validating compatible policy schemas. |
| Clone Suppliers | Copy a supplier and its brands between companies; optionally clone related item master data and dependent merchandise data. |
| API Administration | Manage External Business API clients, company/scoped access, API keys, rate limits, request monitoring and the API-administration audit trail. |
| Workstations | Review registered workstations and approve/block authorization. The workstation currently running IMS Global cannot block itself. |
| System Version | Maintain the global IMS Assembly Version, Loader Version and Critical-update flag through IMS.Api. |
| Operations Log | Display administration progress/success/warning/error messages for the current IMS Global session. |
Companies and database profiles
The Companies screen stores Company Code, Company Name, Country Code, Calling Code, Currency Code, Time Zone and active status. The database profile contains Description, Host / Server, Port, Database Name, Username, Database Password, SSL Mode and Database Active.
The saved database password is not repopulated into the password field. The screen shows whether a password is already stored; leaving the field blank retains the current secret when editing an existing profile.
Create a company database
- Create or select the company and complete its database profile.
- Enter the intended company database password.
- Click Create DB.
- Confirm the company, Database and target Server.
- Enter PostgreSQL administrator credentials when IMS Global prompts for them.
- Wait for the Create Company Database operation to complete.
IMS Global creates and initializes the company database. Database creation is an IMS Global administration task, not a manual PostgreSQL setup procedure. After the operation succeeds, the company database password is secured through IMS.Api.
Change a company database login or password
The Company database profile keeps the IMS Client database login separate from the stored password. A saved password is never repopulated into the password field; leave the field blank to keep the current secret.
When an administrator changes the database password for an existing company, IMS Global prompts for a privileged PostgreSQL account. IMS Global uses that temporary privileged session to change the operational IMS Client role, validates the new login and only then asks IMS.Api to secure the updated password in the company profile.
If the database Username is changed, IMS Global again requests a privileged PostgreSQL account. The target login role is created when missing (or reused when it already exists), configured with the permissions required by the IMS Client, validated against the company database and then saved into the company profile.
API Administration
IMS Global 1.4 adds the API Administration center for the External Business API v1. It is the supported interface for creating API clients, assigning company access/scopes, controlling request limits and managing API-key lifecycle.
| Tab | Purpose |
|---|---|
| Dashboard | Summary of API clients, active keys, recent requests/failures and request timing. |
| Clients | Create/edit API clients, Active state, Valid From/Until and Requests per minute/day. |
| Companies & Scopes | Assign the companies a client may call and the approved read scopes. |
| API Keys | Generate, rotate and revoke API keys. The complete key is displayed once when generated/rotated; existing keys cannot be recovered. |
| Request Log | Review client/company, endpoint, HTTP status, duration, rows returned, remote IP and controlled error code. Times are presented in local workstation time. |
| Admin Audit | Review API administration actions such as client/access changes and key create/rotate/revoke operations. Times are presented in local workstation time. |
Business API v1 scopes
The current API v1 scope set is stores.read, items.read, sales.read, inventory.read, purchases.read, transfers.read, adjustments.read and promotions.read. Assign only the scopes and companies required by the external integration.
- Create or select the API client.
- Assign the permitted companies and scopes.
- Set client validity and request limits.
- Generate an API key and securely transfer the one-time displayed key to the integration owner.
- Use Request Log and Admin Audit to verify activity. Rotate/revoke keys when required.
For the consumer-facing contract and request examples, see Business API v1 Developer Guide.
Global Users and company access
The Users screen maintains Login Name, User Name, Email, Cell Phone, Disabled state, password-reset state and Global Administrator status. A user must have at least one company, and exactly one company is marked Default. Company rows separately record whether the user has access and whether that company is the default.
Saving a Global user writes the global identity/company assignment through IMS.Api and synchronizes the user's local profile into the assigned company databases. IMS Global requires at least one company assignment and exactly one Default company.
The Default company is also used as the policy source when IMS Global synchronizes an existing user's Group Policy assignments into other assigned companies. Matching policies are reused where available; detailed Store, Supplier, transfer and transaction rights remain company-local and are maintained from the normal IMS System → Users Accounts screen inside that company.
Workstations
The Workstations administration screen lists registered workstation identity, machine name, authorization state, first/last seen times, fingerprint-change time, hardware fingerprint and notes. Authorized workstations can be blocked and blocked workstations can be approved. The workstation currently running IMS Global cannot block itself.
System Version
System Version maintains the global IMS Assembly Version, Loader Version and Critical-update flag through IMS.Api.
Cross-company setup tools
Clone Policies is intended for reusing selected Group Policy definitions across companies without manually rebuilding every permission set. Clone Suppliers can reuse Supplier/Brand setup and, when selected, related item master data. These are controlled setup tools; they are not a mechanism for cloning an entire company database.