Innovative Integration. Expert Consulting.

Consulting, system integration and application development

We are a senior team that does three things: work out how your systems should fit together, make them actually fit, and build the applications that fill what is left. The same people stay with the work from the first assessment to the software running in production.

What we do

Three disciplines, one accountable team.

Most firms sell you one of these and sub-contract the rest. We do all three, which is why our advice tends to survive contact with implementation — we are the ones who have to build it.

01 Consulting

We start with the operating problem, not the software. The output is a decision you can defend to a board or an auditor, with the trade-offs written down rather than glossed over.

  • Current-state assessment and target architecture
  • Build, buy or configure — costed honestly, including the option we do not get paid for
  • Access, control and segregation-of-duties review
  • Data model and reporting strategy
  • Delivery planning, phasing and risk
02 Systems integration

Most of the value in an estate sits in the seams between systems, and so does most of the risk. We work in those seams: the interfaces, the identity, the reconciliation, and the evidence trail that has to hold up afterwards.

  • API and file-based integration across ERP, finance, warehouse and third-party operator systems
  • Identity, access federation and single sign-on
  • Ingestion and reconciliation pipelines, with variance surfaced rather than silently absorbed
  • Migration from legacy schemas without losing history
  • Audit trails designed to be read by someone who was not there
03 Application development

When nothing off the shelf fits, we build it — on our own platform, so a new application starts with authentication, permissions, approvals and auditing already working rather than as year-one scope.

  • React and TypeScript front ends, desktop and mobile built separately rather than scaled down
  • PostgreSQL data models with access enforced in the database, not just the interface
  • Role-based permissions, approval workflow and field-level audit as standard
  • Bulk import, document handling, email and content modules inherited from the platform
  • Hosted and operated by us, or handed over — your choice, decided up front

The platform underneath

Every application we build starts on the same foundation.

BaseApp is our application platform. A new product inherits authentication, role-based access enforced at the database row level, multi-company scoping, a field-level audit trail on every table, an approvals engine, content and email modules, bulk import and a database-driven menu — before a line of product code is written. Tenancy is a first-class dimension of the platform itself, not something each product re-implements.

Tenancy as a first-class dimension

A tenant identifier on every registered table, with one reusable, restrictive row-level security predicate. Isolation is enforced by the database itself rather than trusted to application code.

One engine, two topologies

A dedicated deployment is simply a shared stack containing exactly one tenant. There is no second engine to build or maintain, and a customer can move from shared to dedicated later without changing product.

Cryptographic entitlement

Each instance verifies a signed licence token minted by a central authority — module catalogue, seat bands, named companies, subscription state and server binding, all signed rather than asserted.

Governed provisioning

Licence and capacity changes route through the approvals engine, and a runner on each host pulls its own work — so the central console never holds credentials for customer infrastructure.

Our products

What we have built on it.

Each product exists because a client had a problem that nothing on the market solved properly. They share one platform, so they share one identity model, one permission model and one audit trail.

SOFSEK

Access governance & segregation of duties

Product

SOFSEK governs who can do what across every application you run. It ingests users, roles and entitlements from your connected systems, resolves them into a single access model, and continuously tests that model against your segregation-of-duties policies — flagging conflicts, tracking them to closure, and proving it to an auditor.

  • One cross-application access model — users, roles, actions, duties and groups, normalised from every connected system
  • Policy engine for conflict rules, with severities, mitigating controls and governed exceptions
  • Violations tracker and remediation workspace — every finding mitigated, accepted or resolved, with its history
  • Risk heatmap weighted by the value actually flowing through the conflicted duties
  • Operational bottleneck dashboard — where one person is the only path
  • Scheduled ingestion and reconciliation, with a variance dashboard and an intake queue
  • Sandbox simulation — model an access change before you grant it
  • Audit packs mapped to regulatory frameworks, and a provisioning gateway log

AngelTrace

Cask & spirit inventory management

Product

AngelTrace tracks every cask you own or hold — its wood, its liquid, its volume and strength, its location, its cost and its paperwork — from intake to bottling, sale or write-off. It is built for companies whose stock sits in someone else's bonded warehouse and whose value moves while it stands still.

  • A permanent internal cask key, plus a full ledger of every warehouse reference it has ever carried
  • Dual-volume accounting — bulk litres, strength and litres of pure alcohol held together, with no silent unit conversion
  • Rerack, regauge, blend, sample, transfer and write-off, each recalculating both sides and logging the loss
  • Angels' Share projection — expected against actual between regauges, so evaporation anomalies surface early
  • Dry goods, kitting BOMs and bottling runs measured against expectation
  • Purchase orders, three-way matched supplier invoices, sales orders and shipments
  • Multi-currency with the rate captured at settlement, and a journal export
  • Warehouse reconciliation, variance log, and one-click cask and shipment dossiers

How we work

Four things we do differently enough to mention.

Senior people, start to finish

The people who scope the work are the people who do it. There is no hand-off to a junior delivery team after the contract is signed.

We own the foundation

Because the platform is ours, you are not paying us to rebuild authentication, permissions and auditing for the fourth time. That budget goes to the part of the problem that is actually yours.

Control is default, not a phase

Row-level access enforcement, field-level audit and approval routing are inherited by every screen. Compliance is not a project we schedule for later.

Mobile is built, not squeezed

Our applications ship a separate mobile build with its own layouts and interactions, because a dense desktop grid shrunk to a phone is not a mobile product. This site is built the same way.

Get in touch

Tell us what is not working.

A first conversation is a conversation, not a pitch. If the honest answer is that you do not need us, that is what you will get.

Email
admin@integrytasgroup.com
Products
SOFSEK  ·  AngelTrace

We reply from admin@integrytasgroup.com, usually within a working day.

Products Talk to us