Why Inventra
What makes it better
than the alternatives
- 01
Multi-company tenancy
Run several legal entities or branches in one system; each company's data, users, and settings are completely isolated with separate audit logs.
- 02
GCC-ready compliance
UAE VAT with reverse charge for imports, 15-digit TRN validation, multi-currency documents that lock exchange rates at approval, and fiscal year configuration.
- 03
Proof-of-delivery workflow
Goods-out requests reserve stock by bin, generate pick lists and delivery notes, capture receiver signature/photo on mobile, and handle returns with inspection (restock/quarantine/scrap).
- 04
Approval chains with delegation
Amount-based and conditional rules (e.g. invoice 3-way match tolerance) trigger multi-step approvals; users can delegate authority while away, recorded in audit log.
- 05
Bin-level inventory control
Warehouses divided into zones and bins with blocking, printable bin labels (Code 128), batch/serial tracking, expiry alerts, and FIFO/FEFO picking order; every movement is an immutable ledger row.
Inventory Management
- Multi-warehouse stock with zones
- bins
- and bin blocking; printable Code 128 bin labels
- Items with batch or serial tracking
- expiry dates
- purchase units (e.g. box of 50)
- reorder points
- Stock ledger: every movement is an immutable row; weighted-average or FIFO costing (switchable)
- Adjustments with approval workflow; inter-warehouse transfers with stock-in-transit status
- Stock counts: cycle
- full
- or spot; blind counting option; zone freeze; recounts; tolerance checks
- Barcode scanning via USB/Bluetooth scanner or phone camera; Code 128 item label generation
- Excel import for items
- suppliers
- and opening stock (app/Domain/Masters/Excel/
- app/Domain/Inventory/Excel/)
- Valuation reports (current or any month-end)
- ageing
- expiry alerts
- slow-stock analysis
Goods Out & Delivery
- Requests for site delivery
- internal issue
- customer dispatch
- write-off; approval limits by amount
- Stock reservation bin-by-bin on approval (earliest expiry first for FEFO)
- Pick lists with bin locations; delivery notes; truck trips with multiple stops
- Proof of delivery: receiver name
- signature capture
- photo upload
- shortage notes (stored in storage/app/private/companies/{id}/pod/)
- Returns from site with inspection workflow (restock
- quarantine
- scrap); returns to supplier with credit notes
- Visibility rules: requesters see only their own requests unless granted wider access (app/Domain/GoodsOut/Visibility.php)
Purchasing
- Full cycle: Purchase Request → RFQ → Purchase Order → Goods Receipt → Supplier Invoice → Payment
- Approval rules by amount and condition (e.g. invoice mismatch)
- per document type; delegation while away (approval_delegations table)
- RFQ comparison side-by-side in base currency; award to draft PO with one click
- Purchase orders emailed as PDF; exchange rate locked at approval (stored per document)
- Goods receipts at landed cost (freight and customs spread over lines); 3-way match of PO/receipt/invoice with tolerances
- Invoices on hold when they don't match; payment workflow with advances and bank accounts
- Reorder suggestions based on stock levels; optional automatic draft PRs at reorder point (inventory.auto_reorder_pr setting)
- Purchase register
- spend analysis
- supplier performance reports (app/Domain/Reports/)
Finance & Compliance
- UAE VAT: standard rate for local suppliers
- reverse charge for imports
- TRN validation (15 digits)
- Multi-currency: daily rate feed (open.er-api.com by default
- configurable); each document stores its own currency and rate
- Fiscal year configuration per company; month-end stock valuation snapshots
- Audit log of sign-ins
- settings changes
- document approvals; 7-year retention (activities table with is_alert flag)
- Security alerts for failed sign-ins (5 attempts lock account)
- suspended users
- approval rule changes
- Budget tracking per cost center (planned feature: budgets table exists
- not yet enforced in UI)
Access & Security
- Multi-company: one sign-in
- switch between companies; data separated by company_id with CompanyScope
- Roles with 5 permission levels per area (None
- View
- Create
- Edit
- Admin); 7 built-in roles plus custom (app/Support/Access/Permissions.php)
- Two-factor authentication (TOTP via pragmarx/google2fa); optional enforcement per company (security.require_2fa setting)
- Single sign-on: Microsoft Entra ID (Azure AD) and Google Workspace (app/Http/Controllers/Auth/SsoController.php)
- API tokens (Laravel Sanctum) with scoped abilities and expiry; rate limiting (app/Http/Controllers/Api/V1/)
- Session timeout (120 minutes default); HTTPS-only cookies in production; security headers (app/Http/Middleware/SecurityHeaders.php)
- Warehouse access control: users assigned to specific warehouses; store staff see only their warehouse (app/Domain/Inventory/WarehouseAccess.php)
Reports & Notifications
- Dashboard by role: stock value
- low stock
- open POs
- approvals waiting (resources/views/dashboard.blade.php)
- Stock valuation (today or any month-end)
- ageing
- expiry
- purchase register
- spend analysis
- supplier performance
- Excel and PDF export (maatwebsite/excel
- barryvdh/laravel-dompdf); reports emailed on schedule (app/Domain/Reports/Export/)
- In-app notifications (notifications table) and email (app/Mail/); user chooses which events to receive (user_preferences.notifications JSON)
- Scheduled reports: daily/weekly/monthly delivery to chosen recipients (scheduled_reports table
- app/Console/Commands/SendScheduledReports.php)
Master Data
- Items: code
- name
- category
- unit
- purchase unit (conversion factor)
- batch/serial tracking
- expiry
- reorder point
- multiple suppliers
- Suppliers: name
- TRN
- country
- currency
- contact details
- payment terms
- documents (stored in storage/app/private/companies/{id}/suppliers/)
- Warehouses: name
- code
- zones (with freeze for counts)
- bins (with blocking); bin labels printable as Code 128 barcodes
- Currencies: 170 currencies (currencies table seeded from database/seeders/CurrencySeeder.php); company picks active set
- Excel import/export for items and suppliers (app/Domain/Masters/Excel/ItemsSheet.php
- SuppliersSheet.php)
Administration
- Company settings: legal name
- TRN
- address
- logo (printed on POs/delivery notes)
- fiscal year
- timezone
- working week
- User management: invite by email
- assign roles
- warehouse access
- suspend/reactivate; invitation links expire in 7 days
- Approval rules: define amount bands and conditions per document type; simulator shows who approves a given amount
- Document numbering: configurable prefix/suffix per type; gap-free sequences (app/Support/Numbering/DocumentNumbers.php)
- Audit log viewer: filter by category
- user
- date range
- alerts; CSV export (app/Http/Controllers/Admin/AuditLogController.php)
- Health check command: config
- database
- queue worker
- scheduler
- storage
- mail (php artisan stockroom:check)
| Language | Version | Framework | Used for | Share of code |
|---|---|---|---|---|
| PHP | — | — | Web, API | 83.7% |
| SQL | — | — | Database | 12% |
| CSS | — | — | Styling | 2.2% |
| JavaScript | — | — | Front-end | 1.9% |
| Shell | — | — | Scripts | 0.1% |
- Primary language
- PHP 8.2
- Framework
- Laravel 12.69
- Database
- Microsoft SQL Server 2017+ (primary), MySQL 8 / MariaDB 10.3+
- Authentication
- Session-based with 2FA (TOTP), SSO (Microsoft Entra ID, Google), password reset, invitation links
- Licence
- Single-site
- Screens
- 85
- Database tables
- 63
- Supported languages
- English (en), extensible via Laravel lang files
- Browser support
- Modern browsers (Chrome, Firefox, Safari, Edge); IE not supported
| Minimum | Recommended | |
|---|---|---|
| CPU | 2 vCPU | 4 vCPU |
| RAM | 4 GB RAM / 20 GB storage | 8 GB RAM / 50 GB storage |
| OS | PHP 8.2+, Node.js 20.19+ or 22.12+, SQL Server 2017+ with ODBC Driver 18 or MySQL 8+ | PHP 8.2+, Node.js 20.19+ or 22.12+, SQL Server 2017+ with ODBC Driver 18 or MySQL 8+ |
| Est. monthly hosting | $50 | $50 |
```bash cp .env.docker .env # Edit .env: set APP_KEY, DB_PASSWORD, MSSQL_SA_PASSWORD docker-compose up -d docker-compose exec app php artisan key:generate docker-compose exec app php artisan migrate --force docker-compose exec app php artisan stockroom:install --demo ```
```bash # Install PHP 8.2, Composer, Node.js 20+, SQL Server or MySQL cp .env.example .env # Edit .env: APP_URL, DB_* credentials composer install --no-dev --optimize-autoloader php artisan key:generate npm ci && npm run build php artisan migrate --force php artisan stockroom:install php artisan optimize # Configure Nginx/Apache (see docs/deployment.md) # Set up supervisor for queue:work and schedule:run ```
```bash # Upload files, extract to public_html/stockroom cp .env.xampp .env # Edit .env via File Manager: DB_HOST, DB_DATABASE, DB_USERNAME, DB_PASSWORD php artisan key:generate php artisan migrate --force php artisan stockroom:install php artisan optimize # Set document root to public_html/stockroom/public # Add cron: * * * * * cd /home/user/public_html/stockroom && php artisan schedule:run ```
```bash # Provision VM (Ubuntu 22.04, 4 vCPU / 8 GB) # Install PHP 8.2, Composer, Node.js, SQL Server or RDS MySQL cp .env.production.example .env # Edit .env: APP_URL, DB_* (RDS endpoint), MAIL_*, SESSION_SECURE_COOKIE=true composer install --no-dev --optimize-autoloader php artisan key:generate npm ci && npm run build php artisan migrate --force php artisan stockroom:install php artisan optimize # Configure load balancer, SSL (Let's Encrypt), S3 for storage # Set up systemd for queue:work, schedule:run ```
```bash # Open repository in Claude Code (claude.ai/code) cp .env.example .env php artisan key:generate php artisan migrate --seed php artisan serve # Open http://127.0.0.1:8000 in browser # Demo login: ahmed@alnoor.example / (see STOCKROOM_DEMO_PASSWORD in .env) ```
Quality report
Manually reviewedHow to read the quality report
What this is. Every project on Vibe96 goes through an automated audit of its source code before a reviewer in Dubai checks it by hand. The score is out of 100; 75 is the minimum to be listed, and any single failing check blocks a listing regardless of the score.
- Security
- No real credentials in the code, every data-changing route protected, admin areas role-gated, no SQL built from user input.
- Code structure
- A developer can navigate and extend it: clear module boundaries, no giant files, little copy-paste.
- Docs & completeness
- The setup guide, example config, schema and required files the builder committed to are actually in the archive.
- Dependency health
- Packages pinned, no known critical vulnerabilities, no abandoned libraries in production paths.
- Build & deploy
- A clean machine can restore, build and start it by following the shipped instructions.
Warnings are problems that didn't block the listing; they stay visible here until a later version clears them. The audit reads the code — it does not run it — so always try the live demo before you buy. Lines of code are counted from the same audited archive.
Reviewer notes (4 minor)
Database access mostly safe; a few missing indexes and one unscoped delete risk; weak demo password generation and empty db_password default in templates; strong authentication and authorization with minor ownership check gaps on read endpoints; good module structure with some duplication and oversized files in workflows. None of these stop the software from working; the developer has been told and improvements come in a future update.
Versions & updates
No updates yet. New versions appear here with a changelog.
Buyers receive updates free for 1 year.
What you get
- </>Full source codeThe complete audited source, delivered as a download from your account. No obfuscation.
- ▤DocumentationSetup guide, architecture notes, CLAUDE.md and AGENTS.md.
- ↻One year of updatesEvery new version the builder publishes, free for 12 months.
- ♧30 days of supportInstallation and defect support through Vibe96 tickets.