← All Reports

Quotation Tool CRM
Development Updates

Third Party ingredients arrive - ingredients sourced from custom vendors outside Acctivate can now be added, priced, and vendored from a new Settings hub, then pulled straight into formulations and carried through the R&D Lab, Sourcing, and Pricing tabs with color-coded TP markers - laying the foundation for auto-scraped ingredients. Capped by a three-part security hardening push around account activation links, administrative role changes, and profile saves.

July 1 - 7, 2026

Section

New Features &
Enhancements

A full Third Party ingredients system - a dedicated Settings hub to add, price, and vendor custom ingredients that live outside Acctivate, flowing end to end through the R&D Lab, Sourcing, and Pricing tabs.

Major Enhancement

A New Third Party Ingredients Hub

  • Custom-Vendor Ingredients -- Third Party (TP) ingredients are ingredients sourced from custom vendors outside the standard Acctivate catalog, now managed in their own place.
  • New Settings Area -- Admins get a Settings to Third Party screen to add, edit, and manage TP ingredients alongside their vendors and pricing.
  • Full Detail On Add -- Each ingredient captures an SFP name, specification, E Number, and UOM when created.
  • Manual or Scraped Source -- A Source field marks each ingredient as Manual or Auto (Scraped) - the hook for the upcoming online-sourcing feature.
Third Party Ingredients list page (Settings to Third Party) titled 'Manage third party ingredient reference data - pricing, vendor, and specification details', showing one row - E Number E123012, kg, $52.00, Test Vendor Name, a green 'Manual' source badge, SFP name 'Test third party Ingredient' - with a New Ingredient button top-right and a red arrow pointing to the new 'Third Party' item at the bottom of the left Settings nav
Add Third Party Ingredient modal over the same list, with Ingredient Details fields - SFP Ingredient Name, Specification, E Number, UOM - and a Source dropdown open to reveal two options, 'Manual' (selected) and 'Auto (Scraped)', above Cancel and Save buttons
Feature Update

Vendors & Pricing per Ingredient

  • Dedicated Detail Page -- Every TP ingredient has its own page showing its E Number, UOM, source, specification, and record dates.
  • Multiple Vendors -- A Product Vendors table lets admins attach one or more vendors to an ingredient, each with its own unit and price.
  • Best-Price Flag -- The cheapest vendor is tagged Best price, and each vendor row carries price history and edit controls.
Third Party ingredient detail page for 'Test third party Ingredient' (E123012, kilograms, Manual source, created and updated Jul 7 2026) showing an Ingredient Information panel and a Product Vendors table listing Test Vendor Name with a green 'Best price' badge, kg unit, $52.00 price/unit, Jul 7 2026 date, and history/edit/delete actions beside an Add Vendor button
Feature Update

Third Party in the R&D Lab

  • Pulled Into Formulations -- TP ingredients can be added to a formulation straight from the R&D Lab tab, just like standard Active ingredients.
  • Clear Row Details -- The ingredient's Row Details show a Third Party pill and a Switch to Acctivate option, with its target label claim and connected vendor.
  • Marked At A Glance -- Each tab uses a distinct color and a TP badge to flag Third Party rows, so users can instantly tell them apart from Active ingredients.
Row Details Item #2 modal inside a Quote Request, with a blue 'Third Party' pill circled in red and a 'Switch to Acctivate' link, showing the Third Party product E123012 - Test third party Ingredient, its SFP name and specification, a Target Label Claim of 2.0000 mg, and a Vendor Details row for Test Vendor Name (Best) at $52.00/kg, above Delete, Cancel, and Save
Capsules Formulation screen in the R&D stage, Ingredients table with two inactive-ingredient (excipient) rows; item 2 is E123012 carrying a small orange 'TP' badge beside the R# with 'Test third party Ingredient' as its SFP name, 2.0000 mg label claim and 100% potency, sitting next to a standard Active ingredient (Lemon Peel Extract) - a Third Party ingredient pulled into a live formulation
Feature Update

Carried Through Sourcing & Pricing

  • Vendors in Sourcing -- Vendors for a TP ingredient are selected in the Sourcing and Pricing tabs, keeping the whole quote on one workflow.
  • Color-Coded Everywhere -- The Ingredient Pricing table marks TP rows with the same orange TP badge, so Third Party entries stand out from Acctivate items at every stage.
  • Foundation For Scraping -- This system is the groundwork for an upcoming feature that pulls ingredient data from online sources directly into formulations as Third Party entries.
Sales Quote Request - Pricing screen (QR-260612-002, Version 1, assigned to Darin McOwen) with an Ingredient Pricing table; item 2 is E123012 marked with an orange 'TP' badge, 'Test third party Ingredient', Specification, 50% share, 0.0002 kg and a $0.00 price with an info icon, next to the standard Lemon Peel Extract row at $28.00 - the Third Party ingredient flowing through to the Pricing tab
Section

Security Hardening

Three server-side patches tighten the account lifecycle: activation links are confined to internal logs, administrative role changes are validated at the database layer, and profile saves are separated from core system settings.

Security Patch

Data Minimization on Account Activation

  • The Risk -- Single-use invitation and activation links could, in rare background delivery-failure states, surface where a browser session or client-side log might capture them.
  • The Fix -- Extra server-side filtering now confines those links strictly to internal delivery logs, even when a send fails.
  • The Result -- Activation links can never reach browser sessions or client-side logs, keeping every invitation truly single-use.
Users management screen with an Invite User modal open, offering Email Invitation versus Manual Creation account-creation methods and First Name, Last Name, Email, Role, and Department fields with an Invite button - the invitation flow whose single-use activation links are now confined to internal delivery logs
Security Patch

Server-Side Validation for Admin Roles

  • The Risk -- Without a backend guard, a crafted request could in theory push a role or permission change without going through an administrator.
  • The Fix -- Permanent, hard-coded permission checks now sit directly in the database routing layer, so admin-level changes only process for a verified Administrator account.
  • Defense In Depth -- Role changes can no longer bypass official administrative channels, even if a front-end check were ever circumvented.
Edit User modal showing a Full Name field (Josiah Quiambao), an Email field, a Role dropdown set to Member, and a Department dropdown set to r&d, with Cancel and Save buttons - the role-change path now guarded by hard-coded permission checks in the database routing layer
Security Patch

Profile Layer Protection

  • The Risk -- A routine profile save could, without separation, be used to smuggle in a change to sensitive fields like account status or permissions.
  • The Fix -- Save-time validation logic now programmatically separates ordinary profile edits from core system settings.
  • The Result -- Standard profile updates stay verified and self-contained, keeping user data and account controls secure at the code level.
User Profile page for Josiah Quiambao (editable first and last name fields and an account ID) showing Email, a Role row reading 'member' underlined in red, and a Department row reading 'r&d', with Back, Cancel, and Save controls - the profile save whose validation now separates ordinary edits from core system settings

What We Shipped

1 Major Feature
3 Security Patches

Third Party ingredients now flow end to end - added and priced from a new Settings hub, then pulled into formulations and carried through the R&D Lab, Sourcing, and Pricing tabs with color-coded TP markers, laying the groundwork for auto-scraped ingredients - while a three-part security push confined activation links to internal logs, validated admin role changes at the database layer, and separated profile saves from core system settings.