Section 1
1. Executive Product Architecture
High-level overview of the Mints Global ERP operating platform.
Mints Global ERP is a cloud-native enterprise resource planning system engineered specifically for modern distributed digital agencies and high-velocity technology teams. The platform unifies HR, CRM pipelines, project roadmaps, financial treasury, automated workflows, and compliance tooling into a single serverless command center.
- ✓Single Data Model: Zero third-party sync lag; all modules read and write to Firestore.
- ✓Sub-250ms Telemetry: Live Firestore state listeners deliver instant UI updates.
- ✓Server-Side Token Hardening: Firebase Admin SDK v14 validates every incoming bearer token.
- ✓SOC 2 Type I Readiness: Comprehensive technical controls across CC6.1 - CC8.1 criteria.
- ✓Dual-Theme Accessibility: Precision dark and light palettes conforming to WCAG 2.1 AA.
Section 2
2. Technical Stack & Infrastructure
Core engineering frameworks, database pipelines, and styling tokens.
The frontend application runs on Next.js 16 (App Router) with React 19 and Turbopack compiler. Data persistence is managed via Google Cloud Firestore with real-time multi-collection subscriptions. Authentication utilizes Firebase Auth backed by Firebase Admin SDK v14 and secure HttpOnly edge session cookies.
| Layer | Technology | Version | Key Functionality |
|---|
| Framework | Next.js (App Router) | 16.3.4 | Server & Client Components, Turbopack |
| UI Engine | React | 19.2.8 | Streaming SSR, Concurrent Transitions |
| Language | TypeScript | 5.x | Strict type contracts and schema enforcement |
| Database | Google Cloud Firestore | Latest NoSQL | Distributed real-time snapshot listeners |
| Security | Firebase Admin SDK & Edge Proxy | v14.x | Cryptographic session token validation & rate limiting |
| Styling | Tailwind CSS & CSS Vars | v4.x | Semantic tokens with dual-theme engine & mobile bottom nav |
Section 3
3. SOC 2 Type I Controls & Security Architecture
Technical safeguards across boundary protection, rate limiting, and input sanitization.
The platform implements comprehensive SOC 2 Common Criteria security controls: sliding-window rate limiters defend all /api/* routes (CC7.2), enterprise HTTP security headers enforce Content-Security-Policy and HSTS (CC6.7), Web Crypto API (crypto.getRandomValues) ensures cryptographic password entropy, and CSV exports neutralize formula execution (CC6.7). Outbound webhooks strictly validate URLs to prevent SSRF (CC6.6).
Section 4
4. The Dual-Theme Design Architecture
Semantic color tokens, surface elevations, and contrast ratios.
The dual-theme architecture uses semantic CSS custom properties declared in globals.css. The Signature Forest Dark theme utilizes an obsidian base (#0a0e0b) with elevated surfaces (#121813) and pale sage text (#f0f4ee). The High-Contrast Sage Light theme utilizes a warm cream base (#f5f7f4) with pure white cards (#ffffff) and high-legibility dark olive text (#182012) passing WCAG 2.1 AA contrast requirements.
Section 5
5. Role-Based Access Control (RBAC) Matrix
5-Tier clearance hierarchy and document-level Firestore security rules.
Access is governed by five clearance tiers: Tier 1 (Founders & Executive), Tier 2 (C-Suite & Operations), Tier 3 (Department Managers), Tier 4 (Team Members), and Tier 5 (External Clients). Each document query is verified against custom Firebase security rules.
| Role | Dashboard | Attendance | HR / Org | CRM / Deals | Finance | Audit Log |
|---|
| Founder / Admin | Full | Full | Full | Full | Full Control | Full Read/Write |
| Operations Lead | Full | Full | Full | Full | Read / Write | Read-Only |
| Dept Manager | Department | Department | Department | Assigned | Department | None |
| Employee | Personal | Personal | Read-Only | Assigned | None | None |
| Client | Scoped | None | None | Scoped | Invoices Only | None |
Section 6
6. Comprehensive 18-Module Catalog
Catalog of all production modules and internal service directories.
The platform encompasses 18 synchronized modules: 1. Command Center, 2. Attendance & Live Shift Tracker, 3. HR Hub & Org Tree, 4. Specialization Badging, 5. CRM Sales Pipeline, 6. Projects & Gantt Roadmap, 7. Automated Workflow Builder, 8. Finance Treasury, 9. Leaves & PTO Planner, 10. Corporate Chat, 11. Cloud Drive Vault, 12. Helpdesk Kanban, 13. Mail Room, 14. Announcements Hub, 15. Reports & BI Analytics, 16. Security Audit Trail, 17. External Client Portal, 18. Discord Integrations & Settings.