Work Orders
Create, assign, and schedule jobs with checklists and photo evidence
Platform-grade software you can switch on today, at predictable cost and timeline — and extend to fit your organization whenever you need.
Maintenance, made simple.
A cloud-based CMMS built for factories, facilities, and field teams in Thailand — plan preventive maintenance, dispatch work orders, track assets and spare parts, and close every job with compliance-grade e-signatures. Web and mobile, even offline.
Create, assign, and schedule jobs with checklists and photo evidence
Recurring PM schedules generate work orders automatically
Full asset register with a QR code on every asset
Parts catalog with min/reorder thresholds that flag low stock
Tool inventory with inspection and condition-check workflows
Check-out / check-in workflow for shared tools
Reusable inspection templates for walkdowns and audits
Incident logging with a mandatory Job Safety Analysis gate
Track chemicals and hazardous materials across facilities
Supplier directory plus a dedicated contractor portal
Manage stock across multiple storerooms and locations
KPI dashboards and PM compliance reports — PDF and Excel export
An in-app AI assistant answers questions about work orders, assets, and inventory, with AI-written weekly/monthly summaries — self-hostable, so data never leaves your infrastructure.
Multi-stage sign-off with SHA-256 cryptographic signatures modeled on CFR 21 Part 11, plus a full audit trail and print-ready documents.
Technicians keep working with zero signal — jobs, checklists, photos, and signatures store locally and sync automatically.
Every screen, document, and email report in Thai and English — each user picks their own language.
A 30-minute walkthrough with your own asset scenarios — in Thai or English.
Every purchase, one governed lifecycle.
An enterprise procurement workflow platform that takes purchase requisitions from draft to close-out — technical review, budget approval, procurement, receiving & QC, and refund handling — in a single auditable workflow. Everyone always knows what's next and who owns it. In production today.
Non-technical purchases skip straight to budget review; failed QC branches into claim replacement or refund — every branch stays inside the same traceable lifecycle.
Item-level technical approval scoped to each approver's discipline, budget-holder sign-off before any money moves, and PO, payment, and delivery tracking end to end.
Corporate card, expense claim, or direct purchase with proof attached — through the same receiving and QC gate, every step still audit-logged.
The state machine enforces it — not policy documents. Budget review can't start until every technical item clears, and every transition writes the audit trail.
Claims start only from incoming QC after goods arrive. Multi-currency entry with snapshot rates — every screen and approval computes in THB.
A role-aware feed of exactly what each person can act on now, mirrored into a daily email digest
KPI cards and dedicated queues per stage, plus an AI-assisted procurement analysis tile
In-app notification center with automatic email mirroring and deep links back to the PR
FusionAuth OIDC SSO with role- and discipline-based permission checks on every endpoint
Quotes, POs, receipts, and QC reports in object storage, with the approved PR form rendered to PDF
Approvers can delegate; admins can reroute a stuck PR and roll it back with full history
Users, projects, vendors, corporate cards, currencies, and rules managed in-app with Excel import/export
High-value purchases auto-open linked Jira issues at PO and goods-received milestones
Every completed purchase closes with a vendor evaluation, building a real performance record
See the production system in action — and how the workflow adapts to your organization's procurement process.
Access that expires. An audit trail that doesn't.
Replace long-lived SSH keys with short-lived certificates signed by your internal CA and bound to a verified corporate identity. Developers help themselves from the web or CLI; administrators stop signing keys by hand — with every request on the record.
No tickets, no waiting on an administrator — when the certificate expires, request again. Validated end-to-end with FusionAuth SSO.
Mounted read-only from your secret manager at runtime — never in the repository, never uploadable, never visible in the UI.
Set in deployment configuration (4 hours by default) — no client, web or CLI, can request a longer-lived credential.
The certificate's key ID is taken from the verified SSO token, so every certificate is attributable to a real person.
Servers trust one CA public key. Offboarding never means hunting authorized_keys across servers — certificates die on their own within the workday.
Request a certificate, copy or download it in one click, and browse your own request history
A standalone Rust binary for Linux, macOS, and Windows — one command handles login, signing, and file placement
Admins register hosts once; the CLI syncs them into each developer's SSH config, Cloudflare tunnels included
Timestamp, identity, IP, principal, and outcome for every issuance — searchable, streamed as structured JSON
Authentication delegated to FusionAuth over OIDC — disable the account and access ends with the current certificate
A generated installer fetches the CA key, configures sshd, and hardens a new host in minutes
Deployed in an afternoon: generate a CA key pair, point it at your IdP, and bring it up with Docker Compose.
The on-premise cost controller for AWS Bedrock.
A self-hosted Bedrock proxy that gives every developer a personal Claude API key — while finance keeps a hard, real-time cap on the AWS bill. Every prompt, trace, and token stays inside your perimeter.
Every request passes the budget gate before it ever reaches AWS — with Langfuse tracing every token and a self-service portal for keys and budgets.
AWS reports spend 24–48 hours late — a runaway agent loop can burn a month's budget before the first alert. This gateway blocks at the source the instant a cap is hit.
Prompts, responses, and logs never leave your data center — unlike SaaS gateways, where data exits your perimeter and per-call fees stack up.
Every developer gets their own key bound to SSO identity — suspend, rotate, and audit per person, while real AWS credentials exist only at the gateway.
Assembling LiteLLM, SSO, observability, and a portal yourself takes 2–3 engineer-months — this ships as one tested stack, deployed with Docker Compose.
Quota checked on every request at the proxy — overruns return HTTP 429 instantly, with per-user budgets plus a global cap
OIDC SSO into Azure AD / Google Workspace, auto-provisioning on first login, keys hashed at rest and shown once
Bedrock Claude out of the box plus on-premise models via llama.cpp, with role-based model exposure
Langfuse v3 bundled — full per-call traces for tokens, latency, cost, and user attribution on an isolated database
OpenAI-compatible API — drop-in for any SDK, LangChain, or LlamaIndex, with documented IDE configs
GitOps-native: pricing and catalog changes ship in one commit, secrets stay out of git, vendor telemetry disabled
See it stop a runaway loop live, or start a 2-week pilot on your own infrastructure — we deploy it with you.