AJAX Browser Devices and Security

Run AJAX OES on practical browser devices without making the device the permission.

AJAX OES is designed for modern browser access from phones, tablets, laptops, desktops, and browser-capable scanners. Device flexibility reduces hardware lock-in, while tenant, user, role, location, application, session, and device rules control what each person is permitted to see and do.

Browser-Based Operational Access

Start with practical devices, then standardize where the operation proves it is necessary.

AJAX OES is intended to reduce the requirement for one proprietary handheld across every process. Customers can choose devices based on durability, scanning, battery, camera, screen, printer, environmental, support, and cost requirements.

Phones

Use camera, touch, and mobile browser workflows.

Suitable for approved receiving, inspection, image, signature, messaging, delivery, lookup, and light scanning processes where the device is appropriate.

Tablets

Give mobile users more screen and workflow context.

Useful for quality, receiving, production, dock, supervisor review, customer proof, training, and shared-station scenarios.

Laptops and Desktops

Support administration, review, and detailed work.

Use the full browser experience for tenant setup, Business Central connections, queues, reporting, approvals, diagnostics, and operational control.

Browser-Capable Scanners

Use dedicated scan hardware where speed and durability matter.

Support scanner-style browser sessions for high-volume receiving, movement, picking, counting, putback, labeling, and shipping workflows.

Shared Stations

Control kiosks, docks, printers, and work areas.

Assign station identity, location, purpose, device mode, default printer, and permitted workflow while preserving user-level authentication.

Printing Stations

Route labels and documents to approved destinations.

Use tenant, location, station, user, role, workflow, item, label, or task context to select configured printers and print queues.

Camera and Proof

Capture operational evidence from permitted devices.

Use supported cameras for quality images, damage, labels, documents, delivery proof, temperature, signatures, and exception evidence.

Hardware Choice

Match the device to the work.

Standardize rugged scanners where required, but avoid purchasing specialized hardware for every user before the workflow and operating need are proven.

Device Lifecycle

One controlled path from first connection to retirement.

Device identity, approval, configuration, activity, user, location, sessions, status, and retirement history can remain connected throughout the device lifecycle.

Step 1 Identify

Record the station or device name, tenant, location, mode, intended use, browser context, and assigned owner or shared purpose.

Step 2 Approve

Confirm whether the device may be used for mobile, desktop, scanner, kiosk, proof, printing, or another configured access mode.

Step 3 Configure

Apply location, workflow, printer, session, application, camera, scanner, and supported browser settings.

Step 4 Monitor

Review last activity, current status, user, location, sessions, failed access, printer use, and applicable audit events.

Step 5 Disable or Retire

Revoke approval, sign out active sessions, remove assignments, clear sensitive configuration, and preserve the required audit history.

Layered Access Control

A supported browser is only the entry point. Permission still determines the work.

AJAX OES access is intended to be evaluated using multiple layers rather than assuming that possession of a device grants operational authority.

Tenant Access

Keep every company’s data separated.

Users must have active membership in the selected tenant before viewing its private pages, devices, applications, records, settings, or connections.

User and Role

Match authority to responsibility.

Separate platform administration, tenant administration, warehouse execution, supervisor, quality, transportation, approval, and support roles.

Application and Workflow

Show only enabled and permitted work.

Control access to WMS, QMS, Logistics, EDI, Messaging, Training, Grower Management, Profitability, administration, and configured extensions.

Access Evaluation

Evaluate the active tenant, user, device, location, module, workflow, and record state together.

Access Layer Evaluation Context
Tenant Active membership, tenant status, selected company, and strict separation from other tenants.
User Identity, sign-in status, active state, scanner-user designation, assigned role, and permitted actions.
Location Facility, warehouse, cooler, yard, dock, production area, route, office, or other configured scope.
Device Mode Mobile, desktop, scanner, shared station, printer station, kiosk, proof-capture, or another approved usage mode.
Application Enabled module, page, workflow, product area, and transaction authority assigned to the user.
Record State Ownership, status, hold, approval, assignment, customer, item, lot, location, or workflow condition.
Browser Access and Security Administration

Give administrators visibility without exposing sensitive credentials to ordinary users.

AJAX OES running on phone tablet laptop desktop and browser scanner One Application Across Device Types

Match responsive workflows to the approved device.

Use workflows designed for the screen, scanning method, camera, keyboard, touch input, and operational purpose of the approved device.

AJAX OES device approval role session and audit administration Device, User, Session, and Audit Visibility

Review the complete access context.

Review approved devices, assigned users, location, access mode, last activity, active status, permission, printer configuration, and relevant security events.

Session and Shared-Device Controls

Treat shared warehouse devices differently from personal office computers.

Operational environments may use shared scanners, tablets, kiosks, and print stations. AJAX OES is intended to support controlled shared-device workflows without removing individual accountability.

Individual Sign-In

Keep actions tied to the acting user.

Even on a shared device, operational transactions should be associated with the authenticated user and active tenant context.

Session Timeout

Reduce unattended-session exposure.

Use configured inactivity, sign-out, reauthentication, and session rules appropriate to the workflow and customer security requirements.

Tenant Switching

Require deliberate tenant selection.

Where one identity belongs to more than one tenant, require an explicit active-tenant choice before private operational access.

Saved Credentials

Avoid uncontrolled browser password storage.

Customer policy should address saved passwords, shared accounts, browser profiles, device lock, autofill, and local credential storage.

Sign-Out and Revocation

End access when a user or device should stop working.

Disable the user or device, revoke permitted access, terminate applicable sessions, and preserve the audit history required for investigation.

Shared Printer Control

Prevent labels from being routed to the wrong area.

Use configured station, tenant, location, workflow, printer, and label permissions with visible queue and failure status.

Browser Updates

Keep supported clients maintained.

Customer device management should keep browsers, operating systems, scanner services, certificates, and required security updates current.

Local Data

Limit sensitive information stored on the device.

Avoid exposing secrets in page content, local files, browser storage, screenshots, downloads, logs, or shared-device configuration.

Connected Across AJAX OES

Use the same controlled browser access across warehouse, quality, logistics, messaging, training, and administration.

Device context should support the workflow without replacing tenant, user, role, application, and record-level authorization.

WMS Support barcode-first warehouse execution.

Receiving, serialization, movement, allocation, picking, staging, shipping, cycle counting, putback, and correction can use approved browser devices.

View WMS
QMS Capture inspections where work happens.

Phones and tablets can support measurements, photos, grading, holds, releases, signatures, and corrective actions when the device is suitable.

View QMS
Logistics Connect docks, loads, carriers, and delivery proof.

Approved devices can support check-in, appointments, loading, temperature evidence, signatures, exceptions, and proof of delivery.

View Logistics
Messaging and Training Keep guidance and communication beside the work.

Users can receive assignments, ask questions, review procedures, acknowledge updates, and complete readiness checks from the permitted device.

View Messaging
AJAX OES Application Responsibility
  • Tenant separation and active-membership checks
  • Role-, application-, page-, and workflow-level authorization
  • Device and station records where enabled
  • Session, sign-in, status, and audit behaviour implemented by the application
  • Protection of application secrets and sensitive configuration
  • Operational records tied to authorized user and tenant context
Customer Environment Responsibility
  • Device ownership, operating system, browser, and security updates
  • Network, firewall, wireless, VPN, proxy, and internet configuration
  • Physical control, screen lock, local accounts, and shared-device policy
  • Scanner, camera, printer, certificate, and peripheral configuration
  • Employee policy, access review, offboarding, and incident response
  • Compliance validation for legal and industry obligations

Security Responsibilities

Application controls and customer device management must work together. Browser access alone does not transfer device, network, physical-security, or compliance responsibilities to AJAX OES.

Device Validation Before Rollout

Test the actual browser, scanner, camera, printer, and network combination before standardizing the device.

Browser-capable does not automatically mean warehouse-ready. Each proposed device should be tested against the workflows, peripherals, environmental conditions, and support model required by the customer.

Scan Testing

Confirm barcode input behaves consistently.

Test symbologies, prefixes, suffixes, focus behaviour, keyboard emulation, rapid scans, duplicate scans, camera scanning, and error recovery.

Camera and Media

Confirm evidence can be captured and uploaded.

Test permissions, image quality, orientation, file size, low-light conditions, upload reliability, and customer retention requirements.

Printing

Validate label and document routing.

Confirm printer selection, station defaults, queue status, label dimensions, barcode quality, reprints, and failure recovery.

Screen and Input

Make the workflow usable with gloves and movement.

Review screen size, touch targets, physical keyboard, trigger placement, brightness, readability, and one-handed use.

Network Reliability

Test the real operating environment.

Confirm wireless coverage, roaming, reconnect behaviour, latency, proxy or VPN requirements, certificates, and expected outage handling.

Physical Fitness

Match durability to the environment.

Evaluate drops, moisture, dust, temperature, battery, charging, mounting, cleaning, vehicle use, and any applicable hazardous-location requirements.

Go-Live Hardening

Remove test shortcuts before production users and real customer data depend on the system.

Credentials

Remove plaintext and test credentials.

Review configuration, source, deployment settings, browser storage, logs, documents, screenshots, and support notes for exposed passwords, tokens, keys, or connection strings.

Access Review

Confirm who can reach private functions.

Review platform admins, tenant admins, warehouse users, scanner users, disabled accounts, inactive memberships, support access, and high-authority permissions.

Environment Review

Separate development, sandbox, and production.

Confirm active endpoints, tenant selection, Business Central profiles, Stripe mode, email settings, storage, domains, certificates, and production-data boundaries.

Device Approval

Confirm production stations and printers.

Review device names, locations, modes, users, shared purpose, browser support, scanner behaviour, printers, and queue routing.

Session Behaviour

Test sign-in, timeout, sign-out, and tenant switching.

Confirm that users cannot reach private pages after sign-out, membership removal, account disablement, or loss of required authorization.

Operational Audit

Confirm critical actions leave usable history.

Test user, tenant, time, device or station, record, action, approval, correction, integration, and error references for supported workflows.

Executive Value

Reduce rollout friction and hardware lock-in without treating browser access as permission.

Validate the workflow first, keep device context visible, and standardize rugged hardware only where the proven operating need justifies it.

Faster Pilot Test the workflow before buying a full hardware fleet.

Use approved existing devices for signup, setup, training, receiving, movement, picking, quality, transport, messaging, and administration where suitable.

Lower Support Complexity Keep device identity and configuration visible.

Station, user, location, mode, printer, activity, status, and permission context can give support a clearer starting point.

Controlled Scale Standardize based on proven operational need.

Move high-volume or harsh-environment workflows to rugged equipment while keeping lower-intensity tasks on practical browser-capable devices.

Start with a controlled browser-device rollout.

Estimate AJAX OES pricing, create a tenant, and validate the devices, browsers, scanners, cameras, printers, sessions, permissions, and locations required by the operation.

Device Fitness Is Customer-Specific

Capabilities shown on this page describe the intended AJAX OES browser-device and application-security model and may include planned features.

Final device compatibility and security depend on the customer’s hardware, browser, operating system, scanner, printer, camera, network, identity, endpoint management, policies, configuration, enabled AJAX applications, and implementation requirements. Browser access alone does not make a device secure or suitable for warehouse, safety-critical, regulated, outdoor, refrigerated, or hazardous environments. Customers remain responsible for validating device fitness, physical protection, network security, legal obligations, and operational policy.