Your commercial data — protected, and in your control.
Vyntworks holds your estimates, costs, margins and client positions — and it runs AI against them. That's exactly why access, approvals, AI autonomy limits and integrations are built so the right people see the right things, and every committing action leaves a trail.
Due diligence welcome. Bring your IT team — we'll walk them through access, approvals, integrations and data handling.
Nine controls, each one enforced — not promised.
Tenant isolation
Every company's data is scoped to its own tenant. Modules such as Vyntworks Intelligence are opt-in per company, so your commercial figures are never visible outside your organisation.
Role-based access
Regular users, client admins and a restricted super-admin tier. Sensitive areas — PO/SCO admin, authorisation tiers, default quote items — are locked to the top tier, and per-user permissions (like Can Approve Invoices) gate who can do what.
Least-privilege portals
Freelancers and subcontractors get their own login that exposes only the quotes, projects and snag lists you grant — never the whole company. A per-person gross-profit toggle keeps your margins hidden, and clearing an access selection revokes it on the spot. More on subcontractor access →
Authorisation tiers
Purchase orders, subcontract orders and internal variations can require sign-off before they commit. A minimum-GP rule refers under-margin quotes to an authoriser, and the authoriser cascades from team to company default.
AI autonomy, enforced server-side
The limits you set on your AI workforce are enforced on the server — not written into a prompt and hoped for. An AI colleague cannot exceed its scope or skip an approval gate, because the platform refuses the action, whatever the model was asked.
Audit trail & undo
Every save on a quote or project is banked as a version you can preview, diff against today and restore. AI Edit operations are reviewed before they apply and can be undone; applying tender prices is audited and reversible; variation approvals are recorded — so you can always see who, or what, changed what, and go back. Version history & recovery →
Secure integrations
Xero and Sage 50 connect over OAuth — Vyntworks never stores your accounting password. Tokens expire and are reconnected in a click, and invoice push is scoped to the contacts you authorise.
AI data handling
Files you drop into AI Edit are processed securely and deleted after the session. You choose the model per task, every AI change is reviewed before it commits, and admins can see organisation-wide AI usage.
Every committing action, accountable
Who raised it, who approved it, when. Reviewable AI operations with one-click undo, audited tender-to-estimate updates, and client-position status tracked on every variation.
Nothing commits — or erodes — without you seeing it.
The same controls that protect your security protect your margin. Approvals gate spend, the overspend report flags drift, and reconciliation keeps the number you quoted and the number you make in view.
- Approval required before a PO or SCO is issued
- Under-margin quotes referred for sign-off automatically
- Internal variations approved by email before they count
- Re-syncing Xero never silently un-matches your invoices
Security here isn't a policy document. It's the same machinery that guards your margin: scopes, approval gates and a ledger — applied to people and AI alike.
One board. Every person, every AI colleague, every rule you actually want.
“Anyone can tick client approval on a variation.” That's a fair complaint about most systems — and it's the reason the Access Board exists. Pick anyone in the business, pick what they're doing, and say what happens: it runs, it needs approval, or it doesn't happen at all.
Same rule, whichever door they come through
A person clicking a button in the app and an AI colleague calling the same capability hit the same rule. There isn't a human rulebook and a separate AI one — there's one board, and everyone stands in front of it.
- Choose who — a whole role, one named person, one AI colleague, or the background jobs it sends out on your behalf. The most specific rule wins.
- Choose what — the actions that commit money or client position (raising a PO or subcontract order, recording client approval on a variation, marking an invoice sent or paid), or whole families of what an AI colleague can touch.
- Choose the outcome — Allow, Needs approval or Deny. Anything you don't set simply inherits.
- Denied means invisible — a capability you've denied an AI colleague isn't refused at the last moment, it's never offered to it in the first place.
- An AI colleague can't out-scope its own boss — work it delegates inherits its limits, and a colleague that can only propose can't hand a background job the write access it doesn't have itself.
Named approvers
Say who signs it off. They're emailed with Approve and Reject in the message — no need to be at a desk. If you name nobody, it falls to your administrators, so work never parks where no one can release it.
Value thresholds
Set a bar in pounds — the same idea as your PO authorisation tiers, applied to anything. Below it, the team gets on with the job. At or above it, the action parks for sign-off. If the value can't be read, it parks anyway.
Evidence required
Not everything needs a second signature — some things just need a reason on record. Ask for a document reference and any supporting files before the action goes through: “Client email 21 Jul — go-ahead”, attached and kept.
Parked work waits intact — and every decision is on the record
When something needs approval, Vyntworks holds the exact submission. Approve it and the platform runs what was actually submitted — not a fresh guess at it — under the name of the person who asked. Reject it and nothing happened.
- The person who asked sees plain English: sent for approval, it'll run automatically once released
- An AI colleague parks the job, tells you it's parked, and picks it up again on the decision — and only an identical retry can use that approval
- One searchable trail — who asked, for what, how much, what they cited, who decided and when — filterable by status, person, action and date, and linked straight to the record it changed
- Uploaded evidence stays scoped to your company, opened through short-lived links
See the whole machine — every step, who runs it, where it stops for a person
A rule at a time keeps you honest; the Production Line lets you stand back and read the entire workflow at a glance. Pick a part of the business — quoting, procurement, valuations — and Vyntworks lays out its real sequence of steps as one board, each step showing who's cleared to run it and exactly where it parks for a human.
- The real sequence, not a diagram — the steps are the platform's actual operations, in the order the work happens, from opening a quote to winning it
- Who runs each step — a person, a named AI colleague, or both, shown against the step so there's never a question of who's holding the pen
- The gates in plain sight — the points that wait for sign-off — a quote over your value bar, the authoriser on a win — are marked on the line, so the human checkpoints aren't buried in settings
- A read-only overview — it reflects the live rulebook rather than changing it; you read the shape of the machine here and tune individual rules on the board above. Administrators only.
The board only ever narrows. Turn it on and nothing changes until you write your first rule — so you tighten what's actually worrying you, in the order that suits you, without stopping the business to do it. Administrators only.
Every save is a version you can go back to.
Undo isn't just for AI. Every quote and every project keeps its own history — each save banked as a version you can read, compare and restore. A wrong bulk edit, a bad import, a change of mind three weeks on: the work you had is never more than a couple of clicks away.
Open the history. See what changed. Decide.
Version History sits on any quote or project. Each entry shows where it came from — an editor session, an AI edit, an import — the totals captured at that moment, and how far they've drifted from where you are now.
- Preview any past version — read it in full before you touch a thing
- Diff it against today, line by line — new, changed and removed items are colour-coded, so you see exactly what moved
- Restore behind a confirm that shows that diff first — nothing rolls back on a mis-click
- Drop a named restore point before a risky re-price or a big import, and come back to it whenever
- Even a restore has to ask — an AI colleague you've let run freely is still stopped for a fresh, explicit confirm before it rolls anything back
A diff before you decide
Restore is never a leap of faith. The confirm is fed by a server-computed, line-by-line diff of the version against your current state — so you approve a known change, not a guess at one.
Even the undo is undoable
Every restore first banks a snapshot of the state you're leaving. Change your mind and you roll straight back to it — the safety net has its own safety net.
Safe on a live project
Restoring a project never orphans live work. Purchase orders, supplier links and variations raised since that version are carried onto the restored state and dead references cleaned — so recovery is safe even mid-job.
Hosted on enterprise cloud infrastructure.
Vyntworks runs on managed cloud hosting with encrypted connections, regular backups and isolated tenant data. If you have specific requirements around data residency, retention or access policies, we'll work through them with you before you commit.
Bring your security questions.
We're happy to walk your IT and commercial teams through access, approvals, AI autonomy limits, integrations and data handling.