Security and governance

Every change,
in the right hands.

Roles decide who may change what. The audit log shows every change, and version history lets you take one back.

Edit role
Name Product data editor
Permissions
Imports Read imports Create imports Apply imports to the catalog
Categories Read categories Create categories Update categories Delete categories
CancelSave

01Roles and users

Permissions by role, not by person.

Build roles from permissions for products, imports, assets, categories and settings, then give each user one or more roles.

One person, two roles Jan Testowy edits products and now also onboards supplier files. His permissions are both roles together.
Imports Create imports Apply imports to the catalog

Permissions by area

Permissions are grouped by area: products, categories, assets, imports, integrations, administration, settings and API documentation.

Invitation sent.

Invite by email

Invite a colleague with their roles and the language of the email. Open invitations have their own tab.

Inactive Activate

Deactivate, keep the record

A deactivated user can no longer work in openProd, and every change they made stays on the record.

The admin role cannot be changed.

The admin role stays whole

Admin always has every permission and cannot be edited, and the last active administrator keeps it.

02Audit log

Every change, on the record.

The audit log shows who changed what and when, and where the change came from: the app, the API, the MCP server or openProd itself.

Who, what, when and from where A role change in the app, a product update through MCP, a sign-in and a file from a background job, in one list.
UI API MCP System

Source and actor

Filter by source, action, entity type and date, or search for a person or an entity ID.

LoginJan Testowy Failed loginemail, ip

Sign-ins included

Sign-ins, failed sign-ins and password changes are recorded next to data changes.

name Editors → Product editors

Before and after

Open any entry to see each changed field with its value before and after.

Keep all entries forever

Retention you set

Keep entries forever or delete them after the number of days you choose.

03Version history

Any version, restored with care.

Every product save is a version. Restore one field or a whole version, and openProd checks each field before anything changes.

Checked before anything changes Two fields of version 4 will be restored. Description is skipped because its value is already current.
v1 Restore

Field history

Every field on the product card has its own history, with a Restore button on older values.

Will be restored2 Skipped1

Checked before restore

The preview lists the fields that will be restored and the ones skipped, with the reason for each.

This will create a new version.

Nothing is overwritten

A restore is saved as a new version, so the change you undo stays in the history.

Restore product history

Restore is a permission

Only roles with Restore product history see the restore buttons. History keeps as long as you set.

04AI usage

AI inside the same rules.

The assistant works within each user's permissions, nothing it suggests is saved without a person, and the credits it uses are always visible.

Credits and changes, both in view The top bar shows this month’s credits. A value the assistant changed carries a marker and the name of the person who approved it.
Read products

Opens with Read products

The product assistant is available only to roles that can read products.

Update product values

Approved by a person

Approving a suggestion needs Update product values, and the change is saved under that person's name.

398 credits used this month

Credits in the top bar

Everyone sees the AI credits they used this month, from imports and assistants alike.

Whole organization: 1,240 You: 398

The organization total

Roles that can read imports also see what the whole organization used this month.

Questions

Before you hand out access.

Can someone prepare an import without saving it to the catalogue?

Yes. Create imports and Apply imports to the catalog are separate permissions, so one role can prepare imports while another decides what reaches the catalogue.

What does the audit log record?

Changes to products, attributes, attribute groups, families, dictionaries, units, categories, assets, languages, roles, users, invitations and settings, plus sign-ins, failed sign-ins and password changes. Each entry has its time, type, action, source and actor, with the changed fields before and after.

Can the AI assistant change product data on its own?

No. The assistant proposes a change and a person approves or rejects it. Approving needs the Update product values permission, and the change is saved as a normal product update, in version history and the audit log.

How long are history and audit entries kept?

You decide. Product history, asset history and the audit log each keep entries forever or for a number of days between 1 and 3650.

Where can I read about privacy, data processing and sign-in?

In the Trust center. This page covers the controls inside the openProd app.

Trust center

Privacy, data processing and sign-in are in the Trust center.

How openProd and LemonMind handle your data, in one place.

Visit the Trust center

Give every person the right role. Keep every change on record.

In the demo, we set up roles for your team and show the audit log and version history on a demo catalogue.