Liferay and DXP5 minute read

Governance, Access, and Compliance for a Liferay Manufacturing Portal

Digitus Team, Digitus Business Solutions

Published

Design access and the audit trail together, in the Architecture phase. On a manufacturing supplier or employee portal they are one requirement from two angles: tiered access decides who sees what, audit logging proves who did what. Any portal under a quality or regulatory standard needs both, and bolting either on after go-live means reopening the data model. This guide stays on governance, access, and compliance, for manufacturing IT, quality, and compliance owners across discrete, process, and automotive manufacturers.

What you will learn

  • Why role-based access and the audit trail are one Architecture-phase decision
  • What a manufacturing quality standard requires from a supplier portal, with IATF 16949 as the worked example
  • The scope freeze that protects the budget, and why it works
  • The five roles that make portal governance stick
At a glance
Who this is for
Teams building customer, supplier or employee portals on Liferay DXP.
What you get
Role-based access and the audit trail are one Architecture-phase decision for a regulated manufacturing supplier portal.
In this piece
6 sections, 5 minute read
Published
Filed under
Liferay and DXP

Access and the audit trail are one architecture-phase decision

Treat them as the same deliverable. A portal that carries regulated records proves both from day one, built into the data model, not switched on after go-live.

Liferay supplies the building blocks. Role-based access control handles tiered supplier visibility, so a Tier-1 supplier sees full forecast data while a Tier-3 supplier is held to purchase-order acknowledgment. Audit-event logging records transactions; a site-and-organisation model separates multiple brands or plants. None satisfy an auditor alone. They satisfy one when configured against the standard from the start, an Architecture-phase choice, not a Phase 5 patch. Where regulators audit the supply chain, the portal joins the audit surface, so OAuth2-secured APIs, TLS 1.2 or higher, and field-level encryption belong there too.

Compliance need The Liferay control that meets it Where it gets decided
Who sees what (tiered supplier visibility) Role-based access control with supplier tiering Architecture phase, against the access model
Who did what (immutable evidence) Audit-event logging on portal transactions Architecture phase, against the audit schema
Multi-brand or multi-plant separation Site-and-organisation model Architecture phase
Data in transit and at rest OAuth2 APIs, TLS 1.2+, field-level encryption Architecture phase, security sign-off

What does a manufacturing quality standard require from a supplier portal?

An immutable trail of the transactions an auditor will ask to see, plus the access controls that prove only the right people touched them. The standard changes with the sector; the obligations rhyme.

Which standard applies depends on what the plant makes. A discrete or automotive supplier answers to IATF 16949, a general manufacturer to ISO 9001, a medical-device maker to ISO 13485 and FDA 21 CFR Part 11, an aerospace or defense supplier to AS9100 or export-control rules. Each asks the portal for the same pair: immutable records and provable access.

Take the automotive case as the worked example. IATF 16949:2016 is the current standard, and the IATF Rules 6th Edition, mandatory since 1 January 2025, changed how certification audits are planned and how audit days are calculated (TÜV Rheinland, 2024). Under any of these standards, that becomes concrete data obligations: immutable records of purchase-order acknowledgments, compliance-document uploads, quality-score submissions, and certification evidence, each a schema decision cheaper to design in than bolt on later.

The scope freeze is the rule that protects the budget

Budget by integration surface and portal count, not by page count. The cost drivers are the connector work, the Frontend Client Extension hours, and the supplier-onboarding change management, and none of them track the number of screens.

The rule that protects it is the scope freeze at the start of Build. The request that breaks a timeline is never large on its face. "Can we also add one workflow?" arrives mid-build, sounds minor, then cascades through integration and testing. We log every post-freeze request to the Phase 5 backlog for the steering committee to weigh. The freeze holds the line; the backlog keeps the good ideas.

Who owns the governance that makes the freeze stick?

A small, accountable group, not a committee. The freeze only holds when someone can say no, and that structure is five roles: an executive sponsor who can defer scope, a portal product owner who holds the requirements, a back-end technical lead who owns the integration boundary, a Liferay architect who owns the platform decisions, and a security and compliance owner who signs off the audit surface. That back-end technical lead is the dividing line between a Liferay specialist and a Liferay-plus-integration one: holding the build timeline is one thing, holding the integration timeline needs someone on both sides.


Building a portal an auditor will open?

Digitus configures tiered access, audit logging, and the compliance schema as Architecture-phase deliverables for regulated manufacturing supplier and employee portals, so the first compliance audit is a report, not a remediation project. See the Supplier Management System for our pre-built supplier portal, or get in touch to scope the governance and compliance design.

Sources

  1. TÜV Rheinland (2024). "IATF 16949 Rules: the main changes in the 6th edition." https://www.tuv.com/press/en/press-releases/iatf-16949-main-changes-6th-edition.html
  2. Digitus Business Solutions. "Supplier Management System." https://www.digitusbiz.com/supplier-management
  3. Digitus Business Solutions. "eXceed Framework." https://www.digitusbiz.com/eXceed

Frequently asked questions

Does a manufacturing supplier portal have to meet a quality standard?
If it holds the records a quality or regulatory audit examines, then yes, it becomes part of the audit surface. The exact standard depends on the sector, but each asks for the same thing: immutable records, and access controls that prove who could see and change them. Designing that in from the Architecture phase is far cheaper than retrofitting it before the first audit.
What changed with the IATF Rules 6th Edition?
The IATF Rules 6th Edition became mandatory for all audits from 1 January 2025 and changed how certification audits are planned and how audit days are calculated. A portal that holds clean, immutable, well-scoped audit records makes that audit shorter and smoother. IATF 16949:2016 remains the underlying quality-management standard.
Can you add compliance and audit logging after go-live?
You can, but it is the expensive path. Audit logging and tiered access are schema and data-model decisions, so adding them later reopens the data model and forces a replay of the integration tests. Configuring them in the Architecture phase, signed off against the standard, avoids that rework entirely.

Who wrote this

Digitus Team

Digitus Business Solutions