Access model

Different users get different levels of access

MLA does not treat every signed-in user as the same. Access is determined by account role, lab and branch context.

OWNER

Owner protection

Owner access has a dedicated security setup and recovery path. Owner controls are separated from normal operational Staff access.

ADMIN

Admin controls

Admin access manages lab/branch operations, Staff setup and sensitive accounting actions. Device-aware controls are used for protected administrative workflows.

MAIN

Main Staff

Main Staff receive the operational modules assigned to their role and branch, such as registration, daily expenses and approved vendor/stock bill workflows.

SUB

Sub Staff

Sub Staff are intentionally limited to the smaller set of functions allowed for their role and assigned branch.

Security controls

Practical controls for real lab operations

Security is built around day-to-day business access rather than broad marketing claims.

Authenticated accessAuthorized Owner, Admin and Staff accounts sign in before protected data is loaded.
Lab and branch scopingOperational records are associated with the relevant lab and branch context.
Role permissionsStaff access is restricted by role instead of exposing every module to every user.
Device-aware Admin accessAdministrative requests can include a trusted device identity for protected workflows.
Audit attributionImportant actions retain user, role, branch and time context where the workflow records audit history.
Non-persistent Firestore browser cacheMLA keeps Firestore data in memory rather than enabling persistent browser IndexedDB cache for sensitive tenant data.
Cloud & application protection
AuthenticationFirebase Authentication
Operational dataCloud Firestore / Storage
Protected backend actionsCloud Functions
Abuse protectionFirebase App Check / reCAPTCHA support
MLA does not claim that any internet-connected system can guarantee absolute security. Customers must also protect their passwords, devices and authorized account access.
Clear security boundary

What customers should never send to support

PasswordOTPRecovery codeKeystore password

Support may ask for screenshots, an error message, branch name or the time an issue occurred. Authentication secrets should remain private.