Frequently asked questions
Clear answers about setup, governance, security and the platform’s deterministic intelligence capabilities.
General
What is Operater360?
Operater360 is a configurable operations platform that connects organizational structure, policy, approvals, procurement, projects, people operations and finance in one tenant-isolated workspace. Link to this answer
Which organizations can use it?
NGOs, businesses, public institutions, projects and other structured organizations can configure the platform around their own roles, terminology, controls and enabled modules. Link to this answer
Is it cloud-based and available on mobile?
Yes. Authorized users can work through a modern browser on desktop, tablet or mobile. Responsive workflows are designed so essential actions do not require a desktop device. Link to this answer
Accounts and organizations
How does an organization create an account?
An organization registers an administrator, verifies the email address and completes guided organization setup before operational modules are released. Link to this answer
Can one user belong to multiple organizations?
The data model supports organization-scoped membership. Access to each workspace depends on an explicit membership and role for that organization. Link to this answer
How does tenant isolation work?
Authenticated PHP services derive the active tenant from the server-side session. Database operations, files, policies and intelligence jobs are scoped to that tenant and permissions are checked server-side. Link to this answer
Can each organization customize its setup?
Yes. Organizations can configure departments, positions, approval stages, terminology, policy rules, branding, notification preferences and enabled modules. Link to this answer
Modules
Which modules are available?
Current operating areas include procurement, projects, human resources, finance, vendors, approvals, documents, reports, policies, compliance, notifications and administration. Link to this answer
Can organizations activate only the modules they need?
Yes. Enabled modules are stored with the organization and navigation is filtered by both module availability and user permission. Link to this answer
Can modules be customized or added later?
Terminology, workflow controls and policies can be customized. Additional modules can be introduced through versioned migrations and the shared component architecture. Link to this answer
Procurement and finance
How are approval thresholds configured?
Tenant administrators create structured rules in plain language, review them, approve them and activate them. Active rules are evaluated deterministically against transaction facts. Link to this answer
Can quotation requirements vary by amount?
Yes. Separate amount-band rules can require different quotation counts, evidence, committees, approver roles or exception handling. Link to this answer
Can donor-specific rules be added?
Yes. Donor requirements have a defined policy priority and can be scoped to the applicable project or process. Conflicts are explained for human review. Link to this answer
Can the system flag missing documents?
Yes. Structured policy rules and deterministic intelligence checks can identify missing evidence. Workflow enforcement remains in PHP and cannot be bypassed by the intelligence service. Link to this answer
Policies and compliance
How are policies entered?
Organizations upload the source PDF or DOCX for reference, then use guided questions and editable templates to create machine-readable rules. A summary is reference-only and is not enforceable. Link to this answer
Can policies be enforced automatically?
Approved and active structured rules can block, warn, require evidence, add approval, escalate or record an exception. Draft or imported suggestions never activate automatically. Link to this answer
Does Operater360 replace human approval?
No. The platform supports and records authorized decisions. It never delegates expenditure, award, policy activation, permission or irreversible decisions to Python. Link to this answer
Can policy versions be maintained?
Yes. Approved rules are not silently overwritten. A linked draft version is created, reviewed and activated, while historical transactions retain the rule snapshot applied at the time. Link to this answer
Python intelligence
Does Operater360 use external AI services?
No external AI API is required by the private intelligence service. Current analysis uses deterministic extraction, comparison, classification and controlled drafting. Link to this answer
What functions are powered by Python?
Document classification, entity extraction, duplicate checks, missing-information checks, variance flags, overdue milestone checks and structured drafts are processed by a private loopback-only service. Link to this answer
Does Python make final decisions?
No. Every result is marked for human review. PHP remains responsible for authentication, permissions, workflows, approvals, database transactions and audit logs. Link to this answer
What happens when Python is unavailable?
Core workflows continue. Users receive a clear availability message and may return to analysis later; no saved transaction is lost or blocked solely because Python is offline. Link to this answer
Will a self-hosted language model be added later?
The architecture provides a separate service boundary for a future self-hosted model, but none is bundled on the current 1 GB server and deterministic enforcement will remain authoritative. Link to this answer
Internal communication
Which internal conversations are supported?
Authorized staff can use direct conversations, team, department and project channels with threads, mentions, reactions, pins, secure files and follow-ups. Link to this answer
Can a message become operational work?
Yes. An authorized message can create a draft task, decision, issue, approval, procurement request, risk, meeting, document or follow-up for human review. Link to this answer
What happens to organizational knowledge when staff leave?
Organization-owned channels, approved decisions, files, meeting records and action points remain within the governed workspace. Private conversations retain their separate privacy controls. Link to this answer
Inter-organizational collaboration
How does organization discovery work?
Only verified organizations that opt into the directory are discoverable. Each organization controls visibility, contact policy and which staff may communicate externally. Link to this answer
What is a Collaboration Room?
It is an explicitly governed cross-organization workspace with named participants, purpose, data-sharing permissions, messages, files, tasks, milestones, meetings, retention and exit rules. Link to this answer
Does the Trust Passport assign a trust score?
No. It shares factual, permission-controlled and reviewable due-diligence information. Operater360 does not calculate an automated score that determines access. Link to this answer
Can organizations publish partnership opportunities?
Verified organizations may publish permitted partnership, consortium, research, vendor, funding, geographic or technical-assistance opportunities and move accepted interest into a private room. Link to this answer
Email integration
Can external people participate by email?
Yes. Authorized users can send from a governed conversation, and a signed webhook or configured shared inbox can return replies to the correct Operater360 channel. Link to this answer
Which sending-domain controls are recommended?
Organizations should configure SPF, DKIM and DMARC with their email provider. Delivery and failure events remain visible to authorized administrators. Link to this answer
Security and privacy
Can an organization disable external communication?
Yes. External messaging, files and calls are default-deny controls. Blocking and explicit channel membership override broader visibility settings. Link to this answer
Can another tenant guess a collaboration-file URL?
A URL alone is insufficient. Every download revalidates the signed-in user, active organization and channel membership, then verifies the stored file checksum. Link to this answer
Can calls bypass organizational communication restrictions?
No. A recipient must be an approved channel member and cross-organization calls require both the applicable external-call policy and relationship controls. Link to this answer
How are mailbox credentials stored?
Mailbox secrets are encrypted with a dedicated application key and are never returned to the browser after saving. OAuth or app passwords with narrow permissions are recommended. Link to this answer
Security
How is customer data separated?
Every tenant-owned record and query must include the active organization. Policy documents and intelligence jobs use protected tenant-specific storage and database scope. Link to this answer
Are user permissions configurable?
Yes. Roles, approval stages, module visibility and administrative capabilities are validated by the PHP backend. Hiding a control in the interface is never the only security check. Link to this answer
Are actions logged?
Critical workflow, policy, administration and intelligence review events are recorded with tenant, actor, time and relevant record context. Link to this answer
How are uploaded documents protected?
Uploads use file-size limits, MIME validation, random server names and protected storage. Downloads are served through authenticated, tenant-scoped controllers. Link to this answer
Billing and support
Is there a free version?
A beta evaluation may be offered during product validation. Commercial scope depends on enabled modules, users, implementation support and governance complexity. Link to this answer
How will subscriptions work?
Plans are intended to reflect operational depth and support needs. Final commercial terms will be communicated transparently before paid activation. Link to this answer
How can organizations receive support?
Authorized users can use the in-app support desk. Institutional onboarding and business enquiries can be sent to official@a2wg.org during the current product phase. Link to this answer
