Multi-tenant isolation
LivetenantId on business rows; e2e isolation scenarios.
Learn more →Loading
Groups · Scale plan
Each location is fully isolated — its own jobs, customers, and numbers, with no data bleed between sites. Group visibility and cross-location KPI rollup expand on the Scale plan without forcing enterprise-DMS complexity on a two-bay owner. Workshop Wrench uses flat AUD pricing with no per-seat charges per location, so adding a second or third site does not trigger a pricing renegotiation.
Primary search intent: multi location shop management software
Buyer problem
Tools either ignore multi-site or bury single shops in enterprise complexity and seat minimums.
Why Workshop Wrench
tenantId-enforced row isolation — confirmed by e2e isolation tests, not just a policy promise.
Role-based access for owner, advisor, tech, parts, and reception roles — scoped to the site they work at.
Scale plan includes multi-location KPI rollup, advanced RBAC, and webhook entitlements in published AUD pricing.
OpenAPI for HQ integration patterns: build Xero/MYOB rollups or HQ dashboards on structured data rather than screen-scraping.
AU GST invoices and ACL written authority workflows operate at every location — compliance does not degrade as you add sites.
Capabilities
Live means in the multi-tenant product/demo. Integrations: Live / Stub / Dry-run / Planned — never Connected for stubs.
tenantId on business rows; e2e isolation scenarios.
Learn more →Server-side roles — least privilege default.
Learn more →Multi-location entitlements on published Scale plan path.
Learn more →Cross-site rollups expand with group design partners.
Learn more →Also ranks for adjacent intent
FAQ
FAQ schema included for search. Updated when ship status changes.
No. Starter/Growth target single-location independents. Choose Scale when multi-shop visibility and advanced API/webhook needs appear.
Architecture · security
Each location is its own tenant with separate data, separate auth tokens, and no cross-location bleed in the standard UI. Cross-location access requires the Scale API — not a setting toggle.
Every repair order, customer, vehicle, invoice, and inventory record carries a tenantId. Database queries are filtered at the repository layer — there is no single ownership guard in the application layer that can be bypassed with a crafted URL. This is confirmed by end-to-end isolation tests in the e2e suite, not just a design-time policy promise.
Each user is issued a JWT scoped to their tenant. A user at Location A cannot present a valid token to access Location B data. Admin roles exist on the platform level only and are separated from shop-operator access entirely.
There is no cross-tenant query shortcut in the standard shop UI. HQ-level KPI rollup, cross-location stock transfers, and multi-site reporting are available on the Scale plan via the REST OpenAPI — your HQ system calls the API with appropriate credentials per location, rather than blending data server-side. This keeps isolation boundaries clean and auditable.
Owner, advisor, technician, parts, accountant, and reception roles are granted per tenant. A technician at one location cannot log in to a sibling location's board without being explicitly provisioned there. No shared login pools across sites.
The seeded multi-tenant demo includes an isolation login that shows a second tenant with zero data bleed from the primary demo tenant. You can verify this before you buy — not just read a policy page.