Security and Trust Built for Facility Operations
CannaVue is designed so users see only the records, tools, and AI features appropriate for their role and facility. AI-prepared actions require authorized human confirmation before records change.
Security by Design
CannaVue is built with security and data integrity at each layer — from tenant isolation and role-based access to AI confirmation workflows.
Role-Based Access Control
Users access only the modules, records, and features appropriate for their assigned role and permissions. Administrators configure access granularly — including module-level, action-level, and team-level controls.
Tenant-Scoped Data
All records, assets, work orders, and operational data are isolated to each facility's tenant. Users cannot see, search, or infer data from other tenants.
Human Confirmation for AI Actions
Agentic proposed actions require authorized human confirmation before any records change. No write action executes automatically.
Developer-Only Platform Controls
Platform administration, AI configuration, and developer tools are gated to the platform operator and are never visible to facility users, customer administrators, or any customer-facing role.
Audit Activity Logging
Critical operational events and access activity are logged with role context and tenant isolation. Logs are accessible to authorized users appropriate to their role.
AI Permission Scoping
AI reviews only authorized operational data — respecting tenant boundaries, role permissions, team access, and location assignments. AI cannot access data outside its authorized scope.
Role-Based Access in CannaVue
CannaVue supports a structured set of customer-facing user roles, each with appropriate access to the modules and records their work requires.
Customer Administrator
Full tenant managementManages the facility tenant, users, roles, configuration, and onboarding. Full access to tenant settings and all modules within the facility.
Maintenance Manager
Maintenance operationsManages work orders, assets, PM schedules, teams, and maintenance operations across the facility.
Cultivation Manager
Cultivation workflowsManages cultivation-specific workflows, room and zone operations, and cultivation-related maintenance activities.
Custom Manager
Configured by adminConfigured by the Customer Administrator with specific module permissions, team access, and location scope to fit the facility's structure.
Technician
Assigned work scopeWorks on assigned work orders and maintenance tasks. Access is scoped to their team assignments and assigned work scope.
Limited Technician
Limited assigned scopeAccess is limited to their specifically assigned work scope. Cannot access broader maintenance records or management features.
Requester
Request submission onlySubmits and tracks maintenance requests. Visibility is limited to their own submitted requests and status updates.
Strict Tenant and Data Separation
CannaVue maintains strict separation between facility tenants. Customer data is never shared across facilities, and public website visitors cannot access any tenant data, user records, or operational information.
Each facility operates within its own isolated tenant environment. Users are scoped to their facility, their team, and their assigned locations — with no path to access records outside that boundary.
Data Boundary Guarantees
- Each facility tenant's data is isolated from all other tenants.
- Users cannot access, view, or search records outside their facility.
- AI reviews only data within the authorized tenant and role scope.
- Platform administration tools are not accessible to facility users.
- Public website visitors cannot access any tenant or operational data.
- AI configuration and developer tools are gated to platform operators.
Learn more about CannaVue
Explore CannaVue Agentic CMMS — industry-specific maintenance management for cannabis and hemp facilities with role-based access, tenant isolation, and Agentic operational guidance.