Access for a front line that changes constantly, across sites and systems you cannot reach.
Retail and hospitality run on inventory, supply chain and logistics, vendor management, payment processing and the point of sale, plus the property management system if you run rooms and the storefront if you sell online. The people using all that are the newest in the business and the most likely to leave, they work at sites with no IT presence, and a good number of them do not work for you at all.

Front-line turnover runs high and seasonal hiring adds a cohort on top of it. Provisioning from role means a new starter gets exactly what that role carries and the tenth matches the first. Deprovisioning removes them from every connected system in one action, which matters most in a business where the person leaving may never have met anyone from head office. Self-service password reset takes the largest single category of ticket off your team without an administrator in the loop.

Distributors, shipping partners, suppliers and franchise operators need into inventory, vendor management and logistics. They are not on your payroll, nobody offboards them, and their access usually outlives the arrangement that created it. Federation lets them authenticate against their own identity provider rather than an account you create and forget, and where an account is unavoidable it comes from a role with a defined window and an expiry.

Shared terminals at a counter need the access decision at sign-in, and they need it fast, which is what single sign-on with a passwordless factor is for. Around that, store and front-desk work runs to a roster at a known location, so access to the point of sale, the property management system or the loyalty platform can be restricted to the hours that role works and to the site's own network.

Devices at stores and properties enrol under policy and stay under it: passcode standards enforced, camera and screenshot governed, USB and Bluetooth transfer controlled, and installable applications restricted to a list you approve. Policies assign by organisational unit, so a region, a format or a single site gets its own treatment without anyone visiting. A lost device is blocked and wiped remotely.

A store manager emails a customer list to sort out a complaint. A marketing coordinator exports the loyalty database to a spreadsheet. Akku indexes your own records as fingerprints and detects them wherever they move: an email attachment, a browser upload, a USB stick, a cloud folder shared with a link. What happens on a match is yours to set, and it starts in monitor-only so you see the traffic before anything is blocked.

The DPDP Act governs everything you collect from a customer, and consent is the authorisation for it. Akku captures consent per purpose against a versioned notice, honours withdrawal in a single action, and propagates that signal downstream. Data principal requests, correction and erasure are recorded with what changed and when it completed.

Merchandising, supply chain, finance and HR run the applications every business runs, and they hold the supplier terms, the margins and the payroll. Same treatment as the stores: entitlements from role, MFA that escalates on an unusual request, and provisioning that reaches the ERP rather than stopping at the directory.

Where you take card payments, PCI-DSS requires multi-factor authentication on every entry into the cardholder data environment and logging reviewed daily. Those are access controls with a deadline attached, and the evidence for them is a record written when the access happened. The DPDP Act applies alongside it to everything else you hold.
