Platform overview

One place for the people, the kit and the money

OpsOne is SilverPush's internal operations platform. It holds the employee directory, the hardware inventory and every vendor payment — and it keeps those records true by talking to the systems they came from, rather than asking somebody to type them in twice.

Sign-in
Google SSO
Invite-only, no separate password
Access
Per action
Roles carry the permissions
Record
Audit logged
Who changed what, and when
Connectors
Six live
Kept in step on a timer

What it does

Four modules. What you see of them depends on what your role allows.

People Ops

Directory & lifecycle

The employee record, and everything that follows from it — the accounts somebody gets on day one, the kit they hold, and what happens to all of it on the day they leave.

Directory

Every employee across all entities, with org placement, work location, employment type and status. Filter it, export the whole result, open anybody's full profile.

Joining

A joiner's Google account, Microsoft licences, Slack invite and Gmail signature are created from the record at a time you book — not by hand, and not on a checklist.

Exit

Exit tasks run at a scheduled time: sign-out, licence release, asset return, mailbox handling. Each step reports what it actually did.

Access & licences

Who holds which paid seat, kept level with Snipe-IT. Assign or release a seat from the person's profile and the change reaches the vendor's console.

Org chart

The reporting line as it is recorded, drawn from the same directory data.

Attendance

Punches pulled from Keka, per employee and per day, with the daily attendance mail going out on its own schedule.

Assets

Hardware inventory

Laptops, phones, monitors and the small things — what exists, who has it, what condition it is in, and what it cost.

Inventory

Tag, serial, model, warranty, supplier and cost per device, filterable by status, category and location. Exports cover every matching row, not the page on screen.

Assignment

Check a device out to somebody and back in again. Returning it frees the device and updates its status without a second step.

Handover agreement

The signed handover-and-return document is generated per assignment from the record itself.

Stock & consumables

Accessories, components and consumables tracked separately from serialised kit.

Maintenance

Repairs and services logged against the device, with cost and downtime.

Snipe-IT

OpsOne and Snipe-IT are kept in step continuously — people, assets and assignments, in one direction, on a timer.

Spends Ops

Vendor payments

A vendor payment from the moment somebody raises it to the moment it is paid — including the approval mail, the reply that approves it, and the receipt.

Raise

Prepaid or postpaid, with vendor, entity, category, currency, card and attachments. Each spend gets a number that runs by financial year.

Approval by email

The approval mail goes from the raiser's own mailbox on the platform template. Replies are read back automatically — an approval marks it approved, a payment confirmation marks it paid with its transaction reference.

Vendors

Vendor master data with entity, category, country and payment terms — no bank details anywhere near the API.

Multi-currency

Amounts are converted at the rate in force on the date of the expense, refreshed daily, so a report does not shift when the rate does.

Reports

Spend by vendor, category, entity and month, with scheduled reports by email.

Alerts

Slack notices when something is raised, approved, held, rejected or paid.

Admin & governance

Platform control

Who can do what, which connectors are live, and a record of everything anybody changed.

Roles & permissions

Access is granted per module and per action. A role is its own set of permissions; people hold roles, not exceptions.

Users

Invite-only. An account must be created here before Google will let it sign in.

Entities

Multiple legal entities in one platform, each with its own approval routing and payer.

Audit log

Every change, with who made it and when. Written by the platform, not optional.

Integrations & services

Every connector's state and every background service's last run, readable without SSH.

External API

Scoped, read-only, field-level keys for other systems.

How access is controlled

Invite-only Google sign-in

There is no self-signup and no password. An administrator creates the account first; Google authenticates it. Sessions are held server-side and can be ended from the admin console.

Permission per action

Viewing, editing and managing are separate permissions on every module. A role is a set of them, and what a role cannot do is simply not on screen.

A record that is not optional

Every change is written to the audit log with the person, the time and the before-and-after. Spends and licences additionally keep their own change history.

Systems it keeps in step

OpsOne is not a copy of these systems — it is the place the decision is made, and the connectors carry that decision outward.

Google Workspace

Accounts, groups, signatures, mail

Microsoft 365 / Entra ID

Licences and accounts

Slack

Invites and operational alerts

Snipe-IT

Assets and licence seats

Keka HRIS

Employees and attendance

Frankfurter FX

Daily exchange rates

What runs on its own

Background services, each one recording what it did on every run. Administrators can read that history in the platform.

ServiceWhat it doesModuleRuns
keka-syncPulls employees and attendance punches from Keka into the directory.Peoplehourly
gw-provisionCreates and reconciles Google Workspace accounts, and locks them at exit.Peopleevery 5 min
ms-provisionMirrors Microsoft 365 licence assignments into Entra ID.Peopleevery 5 min
slack-provisionSends the Slack invite and notices when somebody has joined.Peopleevery minute
signature-renderWrites each Gmail signature from the managed template and the person's record.Peopledaily 07:00
joiner-provisionRuns the joining kit at the time it was booked for.Peopleevery minute
joiner-activationMoves an upcoming joiner to Active on their joining day.Peopledaily 01:05
exit-runnerRuns each exit task when its scheduled moment arrives.Peopleevery minute
attendance-emailSends the attendance report to each employee and the team summary to managers.Peopleweekdays 11:00
snipe-syncPushes people, assets and assignments to Snipe-IT.Assetsevery 15 min
spend-email-sendSends approval and payment mail from the raiser's mailbox.Spendscontinuous
spend-email-pollReads replies and moves a spend to approved, held, rejected or paid.Spendscontinuous
fx-refreshRefreshes exchange rates so historical conversions stay fixed.Spendsdaily 06:00
report-schedulerSends scheduled reports at the cron each one carries.Spendsper schedule
usage-purgeTrims API usage rows past their retention window.Admindaily 02:30

Built in-house

OpsOne runs on SilverPush's own infrastructure. Nothing about our people, hardware or payments leaves it except through the connectors named above and the scoped API keys an administrator issues.

Next.jsPostgreSQLPrismaBackground workerGoogle OAuth 2.0Self-hosted

Need access, or something changed?

Accounts, roles and API keys are issued by the IT team. If a record looks wrong, say so — the fix belongs in OpsOne, not in a spreadsheet beside it.