Quasar HQ /Administration

Users and Access

Accounts, access and security
Access System Quasar AI Document Control

Users

UserEmailAccess GroupLast login2FAStatus
Loading...

Access Groups set ordinary visibility and work access. Choose a group on the left, then rename it, manage its users and set its modules on the right. Refunds, approvals, case closure and other controlled actions stay under Special Permissions. An Access Group is not a People Department: the names may be similar, but changing one never creates, assigns or changes the other.

2Edit the selected group

Loading...

Team Chat Channels

ChannelWho can open it
Loading...

All Chat remains available to everyone. Create only the private or open channels you need, then choose their members. Access Groups and departments never create channels automatically.

People Departments

Directory organisation only
DepartmentMembersPeople
Loading...

Directory only. Departments organise where people sit in the company. They never grant modules, functions, approvals or Team Chat channels, even when a department and an Access Group have the same name.

Special Permissions do not control which modules a person can see. Operational assignments decide who is offered in controlled workflow fields. Protected actions decide who may see a restricted queue, close, approve or change a controlled value. Neither grants ordinary module access or Administrator.

Operational assignments

Choose who appears in a specific workflow picker. This changes the available names, never what those people can open or approve.

Sales reps

Who is offered as Sold by on an order, in the Orders list's Sales Rep filter, and when assigning a Lead. Being listed here grants no Sales access, pricing authority or approval.

Loading...

With nobody selected, every team member is offered. Existing orders and leads keep the recorded attribution for somebody outside this list; this only controls the names offered for new changes.

Protected people authorities

Manage named job functions and work-location eligibility here. These settings are separate from Access Groups and never make a module visible.

Protected job functions

Choose who holds each server-enforced job function. A person can hold several. Removing every protected function returns them to the Baseline job authority without changing their Access Group. Each function below saves on its own.

Loading...

Work-from-home eligibility

Choose who may clock a work-from-home day. The clock-in location gate enforces this setting server-side.

Loading...

Assigned WFH days

Assign weekly recurring days or specific dates for the people selected above. Applies to phone and desktop clocking.

Named access and workflow authorities

Choose the people for each authority below. Each authority below saves on its own, with its own required change reason - saving one can never carry an unrelated, still-being-explored tick on another authority through with it.

Loading...

Controlled actions

These rules answer one question: who may perform a protected action? They never make a module visible and never grant Administrator.

Money approval layers

app_settings 'approvals.money_rules' - admin-only, audited

Loading...

These layers are server-enforced only on the RMA money-intent path (G-R3). RMA decision approvers control who may choose the case outcome; Refund authorisers separately control the primary Finance > Refunds & credits flow. On the RMA money-intent path, the named unlimited-RMA approver authority bypasses the amount limit but not a required named-person gate. A saved change applies from the next authorisation attempt, with no deploy needed. When an amount exceeds every layer the requester holds, HQ notifies the roles named in the covering layer.

Money approval layers are real and server-enforced in the card above for legacy RMA money intents (HQ-470), including chargeable warranty, replacement and fallback refund or account-credit outcomes. The primary Refunds & credits flow instead uses the named Refund authorisers setting above. The rule builder below is still a preview: nothing there is wired to a server table or gate.

Manufacturing settings

app_settings 'manufacturing.lines' / 'manufacturing.proposal_snooze_days' / 'manufacturing.sla' - admin-only, audited

One production line per line, in any order. Shown on the Line View wall, each line's own tablet, and the scheduling line picker. Leave blank to keep deriving names from recent orders.

How long a dismissed stock-shortfall suggestion stays snoozed before the 30-minute proposal rule may raise it again. Default 7 days.

A build using more than this percentage of its target time shows red on the order page, the orders board, the line screens and the leadership report. Between 100% and this line shows amber; at or under target shows green. Default 120%.

How long after release a unit should start before its Started badge turns red (amber past half this time). Default 24 hours.

How long after completion a finished order should reach the warehouse before its Received badge turns red (amber past half this time). Default 24 hours.

Other approval rules (preview - wired to no server table or gate; collapsed by default)

Other approval rules

Preview - not yet wired to a server table or gate
RuleApproversThreshold / ConditionsEnforced inAction

Rule details

Select a rule to view its approvers and notes.

System Settings apply company-wide. They change defaults or service behaviour, but never grant a person module access or approval authority. Use Access Groups for ordinary access and Special Permissions for protected actions.

General settings

Security defaults

Require 2FA for all staffEnforced at sign-in: staff with no authenticator get a setup step instead of a session
Enforce access server-sideAlways on (data-layer gate)
AI drafts replies automaticallyOff: the email agent only drafts when somebody presses "Check inbox now", Re-draft or Refine. On: it also drafts every 15 minutes for each connected mailbox, which is where the AI spend goes. Saves as soon as you switch it.
Conversations AI drafts repliesOff (default): the Conversations inbox gets no AI drafts. On: it drafts a suggested reply for a human to review and send - this switch alone never sends anything automatically. Saves as soon as you switch it.
Auto-send ramp - once drafting is on, tick a reply type below only after watching its suggested replies get accepted unedited for a while. Refunds, discounts, complaints and "talk to a human" can never auto-send and are not offered here - the agent forces those to a human regardless of this setting.
Lock accounts over their credit limit or overdueOff (default): a quote/order can be started and first issued to Xero whatever the account's standing. On: an authorised sales, finance or admin user must add an audited override comment to start a NEW quote/order or first issue it to Xero while the account is over its limit or overdue. Existing Xero-linked invoice updates and shipping authority are unaffected. Saves as soon as you switch it.
Auto-send: Tracking
Auto-send: Order status
Auto-send: Product questions
Auto-send: Stock and price
Auto-send: B2B account enquiries
Auto-send: Other

Support workflow default

After an approved RMA refund is executed, HQ assigns the case to this person for final review and closure. This controls workflow routing only; it grants no Support access or approval authority.

Refund authorisers

Who may approve or decline an order refund. Tick people here and only they can authorise a refund - this applies even to admins. With nobody ticked, refunds fall back to today's rule: Finance, and any admin.

Loading...

Changes to this list are recorded in the audit log. This only controls who may authorise a refund - it does not grant admin access or change anyone's role.

RMA decision approvers

After testing is complete, the RMA waits at Pending Decision. Only the people ticked here can approve the assessment and choose refund, credit, replacement, chargeable, not-covered or customer-pickup. This applies even to admins. With nobody ticked, the existing Support Manager/admin fallback stays active. Any later movement of money remains a separate approval, including the Refund authorisers list above.

Loading...

Changes to this list are recorded in the audit log. This only controls who may sign off an assessment and raise a refund or credit - it does not grant admin access or change anyone's role.

Booking return shipping label authorisers

Safiery pays to get a unit returned only by exception. Only the people ticked here can attach or replace a Booking Return Shipping Label on an RMA - this applies even to admins. With nobody ticked, this falls back to today's rule: Support Managers, and any admin.

Loading...

Changes to this list are recorded in the audit log. This only controls who may attach or replace a Booking Return Shipping Label - it does not grant admin access or change anyone's role.

Remote assessment authorisers

Who may record a remote assessment on an RMA - the warranty decision made when no unit came back. Tick people here and only they can record one - this applies even to admins. With nobody ticked, this falls back to today's rule, which for this action is wide: any Support, Warehouse, Sales or Finance role, plus any admin.

Loading...

Changes to this list are recorded in the audit log. This is the list for recording an assessment only. Signing one off is a separate door with its own list - RMA decision approvers, above - because the person who reviews an assessment must not be the person who wrote it. Neither list grants admin access or changes anyone's role.

Tick at least two people, or make sure the people here are not the same single person on the RMA decision approvers list. A remote assessment cannot be signed off by whoever recorded it, so one shared name means nothing can be reviewed and the refund behind it stays blocked.

Packaging boxes

The cartons and satchels the warehouse actually stocks, with measured internal size, outer size, empty weight and cost. Combined shipping needs a complete measured carton and a stated maximum gross weight.

CodeNameInternal size (mm)Outer size (mm)Empty weightMax gross weightCostStatus
Loading...

Whether a box's cost is ever charged to the customer is a separate pricing decision, not made here - this catalogue only records what a box costs us.

Notifications

In-app notifications
Email notifications (saves immediately)
Google Chat alerts
New trade account alerts

This person gets the red-bell alert for every new trade account request. With Email notifications on, the same alert is emailed by the existing scheduled mirror. If the selected account becomes unavailable, Sales and then management remain the fallback.

sales@safiery.comBranded notification sender
Design company-wide notification email (subject, wording and colour)

This subject, wording and colour are shared by every notification email across the company.

Keep {{headline}} in the subject so every inbox shows which alert arrived.

Enter a six-digit hex colour, for example #2f7fc4.

Merge fields can be used in the subject, brand, header, intro, button or footer. The live alert headline, record title, details and link always remain in the email.

Available merge fields: {{headline}}, {{title}}, {{body}}, {{actor_name}}, {{company_name}}, {{link}}, {{notification_kind}}.

This company-wide design saves separately from both the on/off switch and the page's Save changes button. Send test to me always uses the last saved design.

Live content preview
Subject

[Quasar HQ] Sameera Jeffrey mentioned you

BrandQuasar HQ
HeaderTeam notification
Why you received this

Sameera Jeffrey mentioned you

AreaConversations
RegardingYou were mentioned: Quote timing - Avida Motorhomes
DetailsCan you confirm the quote timing before we reply to Avida Motorhomes?

Open in Quasar HQ

Email notifications mirror the in-app feed (HQ-880): with this on, every alert that reaches your bell is also emailed to whoever can see it - your own mentions to you, team-wide alerts to management. A scheduled sweep sends them within a few minutes from sales@safiery.com, and never sends the same one twice. Turning it off stops them immediately. Customer emails (quotes, invoices, shipping notices) are separate and unaffected.

In-app notifications are always on - the bell cannot currently be switched off, so this toggle records a preference only. Google Chat alerts still need their webhook secret set on the site before they can fire.

Monitoring & records

Support caseCASE-####
RMA (return, continuous)RMA-#####
CAPA (operations)CAPA-OPS-####
Form / SOP / recordFRM- / SOP- / REG-

Numbering format is fixed server-side (DB triggers) and shown for reference. RMA numbering is continuous and never reused (mirrors _support-numbering.cjs).

Data & backups

DatabaseNeon Postgres (Netlify DB)
Soft-deleteEnabled
Last config backupToday 08:30
Pending HQ-276 - "Run backup now" / export config. Backups are managed by Netlify/Neon; a self-serve trigger needs a server function.

Left sidebar

app_settings 'nav.layout' - admin-only, audited

Connected below means a key is present in the site env - a presence check, not a live health check. For the carriers, a second pill says whether bookings are actually live: a carrier can be Connected and still return a dry-run preview, or book against the vendor's staging account, in which case a click on Book shipment produces a tracking number but no parcel is ever collected. Use Test connection on a card to confirm it can actually reach that provider right now; Inbound health further down checks something no single integration's key can - whether a customer message is actually arriving at all.

Inbound health

admin-only

A Connected pill above only proves a key is set - not that any customer message is actually arriving. That gap is exactly what stayed invisible for 13 days while the Intercom webhook silently 401'd on every delivery. This reads the one watermark every inbound path bumps and warns when it has gone quiet.

Last inbound customer messageLoading...
StatusChecking...

Shared mailboxes

Gmail sends as the mailbox that authorised it, so a company address such as sales@safiery.com can only be chosen as the From address on a document once that mailbox itself is connected here. An alias is not enough. Connecting one never affects your own personal Gmail connection.

MailboxStatusConnected byLast updated
Loading...

Customer comms rail

app_settings 'comms.*' - admin-only, audited

Where a customer conversation travels while Safiery moves off Intercom. Turning a half off here never deletes anything: the imported Intercom history lives in HQ's own tables and stays exactly where it is.

Off means a reply leaves through Gmail instead, from the mailbox chosen on the case. This half is safe to switch off today.

Check every mailbox you rely on is being polled. With the incoming half off, HQ collects customer email by reading the shared mailboxes listed in CONVERSATION_INBOXES - by default sales@ and support@ only. A mailbox can be Connected above and still not be polled: connecting it stores a token, the env var decides what the ingest reads. Any address a customer writes to that is not on that list now goes uncollected. The last run's Mailboxes polled count in Shared mailbox ingest below tells you how many are actually being read.

Intercom import

admin-only, audited

Pulls every Intercom conversation - including internal notes - into HQ's own tables, so the history is here before Intercom is switched off. Preview first: nothing is written until you apply. Safe to re-run - an already-imported conversation is matched and skipped, never duplicated.

Read before running. There is no date filter - Apply re-walks Intercom's entire history every time, not just what changed, and it bumps the version on every request it touches. Run it when nobody else is editing the inbox.

Contact name backfill

admin-only, audited

Some contacts have their name stuck as their own email address, even though a real name later arrived via billing or shipping details. Preview first: nothing is written until you apply. Safe to re-run - a contact renamed by a person since the preview is left alone.

Shared mailbox ingest

admin-only, audited

Polls the connected company mailboxes (sales@ and support@) for new customer email, and turns a genuinely new enquiry into an unassigned request in the Inbox. Runs automatically every 5 minutes; this button runs it once, now. Safe to re-run - a message already pulled in is matched and skipped, never duplicated.

Email signatures

app_settings 'signature.company_html' - admin-only, audited

One signature for every outgoing email, personal or from a shared mailbox like sales@ - built once here and reused everywhere. Each person's own name and role fill in automatically from their People record, so nobody edits their own signature and a job title is corrected in exactly one place.

Press Use the standard block for the house signature, or paste your own straight out of Gmail's signature editor - there is no HTML to type by hand either way. Use the Bold and Link buttons above the editor for that formatting; only http, https and email addresses are allowed in a link, the same rule the Email Templates editor uses.

Each person's own details fill in automatically from the staff directory on the People page: {{USER_NAME}}, {{USER_ROLE}}, {{USER_PHONE}} and {{USER_EMAIL}}. So nobody builds a signature of their own, and a job title is only ever corrected in one place. Anything with nothing to fill in disappears cleanly. A reply sent from a shared mailbox like sales@ shows the name and role of whoever is actually signed in and sending it - the same as any other email.

Add {{USER_NOTE}} anywhere you want a person's own note to appear underneath their name and role - e.g. Jean's rostered work days. It fills from the "Signature note" field on that person's Directory profile (People page), and always renders smaller and in light grey since it is a note, not a signature line - you do not need to style it yourself. Leave it blank for someone and their line disappears cleanly; today that is everyone except Jean.

Use {{signature}} instead if you would rather each person paste their own block and this template only wrap it.

Text beats a logo here. Outlook and most company mail systems block images by default, so a logo shows for some recipients and leaves a hole for the rest - the standard block uses the word SAFIERY set bold instead, which nothing can block. If you do add a logo it must be PNG; SVG is refused.

SKU convention

app_settings 'sku.*' - admin-only, audited

Own (Safiery-made) products get a dotted code, checked as it is entered on Inventory's + New item; resale products keep the supplier SKU untouched. A format issue prompts the person entering it and they can still consciously save (flag, don't block); a duplicate SKU is always refused outright. Existing codes are never re-checked or regenerated.

Prompt on new product SKUsOff = no format prompt; the duplicate-SKU refusal always stays on

Shipping email templates

app_settings 'shipping.*' - admin-only, audited

{{order_number}}, {{items}}, {{ship_to}} and {{tracking}} are substituted from the real order - never an invented promise or a guessed ETA. Leave a template blank to use the built-in default text.

Automatically email the customer when a tracking number is recorded (e.g. Donovan marks an order shipped)Off by default - review the "Shipped" template below and confirm the sender mailbox is connected before turning this on

AI providers

Assistants work only when the system-level keys are configured. Provider keys are held server-side, never in the browser.

Pending HQ-274 - per-provider enable toggles. Provider keys live in server env / a secret store (no front-end secrets); a toggle needs an admin settings write + a server read of which keys are present. Shown read-only.

Data access

Assistants work only when system-level keys are setOn
Sensitive data excluded by defaultAddresses, finance, ACNs
Provider keys held server-sideEnforced
Per-staff connect under own profileAllowed

Admin sets the policy here; each staff member connects their own AI account under their own profile. WooCommerce is retired per CLAUDE.md v2.0 (Xero is the order-of-record); the Woo card is reference-only.

Audit log

WhenUserActionModule / RecordDetail
Loading...

Deleted records

Loading...

Deleting through HQ hides a record but never destroys it. All deletes are soft (deleted_at) and remain in the audit trail for ISO traceability; permanent removal needs a 14-day retention window and a privileged gate (pending HQ-275).

Warranty fault categories

app_settings 'support.fault_categories' - admin-only, audited

Loading...

The controlled dropdown a no-return RMA's remote assessment picks a fault category from (Support > RMA > Remote assessment), and the list a monthly warranty report will group by. Retiring a category removes it from the pick-list for NEW assessments only - an assessment that already recorded it keeps working unchanged. The key is generated from the label and cannot be changed once saved.

Status

Server kill switch (env)-
Company AI key-
Model-
Hourly cap per visitor-
Chatbot enabledBoth this AND the server env switch must be on
Allow "Talk to a human"Creates a Conversations case (needs_human)

The bot answers ONLY from the knowledge sources below. The env switch and API key are server-side facts (read-only here); flipping the toggle alone cannot enable the bot.

Settings are admin-only; knowledge and review are open to support managers.

Knowledge sources

Reference documents (store)Titles and links only - cited, not quoted. See Reference library below to let the bot read the full text.
Product cataloguePublic fields only - never cost, stock or margins

Source toggles are saved with Save settings. The curated knowledge list below is always on.

Knowledge

Curated entries
Enabled
Documents

Each document is converted to plain text on the server and split into knowledge entries by heading, added to the curated list above. The original file is never stored, and re-ingesting a document with the same title disables its previous entries first.

Reference library

Refresh

The library of manuals, datasheets, wiring guides and certificates is created and tagged on the Reference Docs page. Link one below to let the bot read its full text - split into entries above, exactly like an upload - instead of only citing its title and link.

Unlink disables that document's entries; re-link to pull in a newer version.

Review queue

Show all recent

Test console

Test questions run the REAL engine (logged as mode "test", capped 30/hr per user) but skip the public visitor cap. Works before the public kill switch is on.

Embed on the website

Optional attributes: data-accent takes your brand colour; data-title renames the launcher. The widget fails to a friendly offline note whenever the bot is disabled.

One server prerequisite: the website's origin (e.g. https://safiery.com) must be listed in the CORS_ALLOW_ORIGIN environment variable on this site, or the browser will block the widget's calls. Ask whoever manages the Netlify environment before embedding.

The bot answers only from the knowledge allow-listed here. Money matters (discounts, refunds, pricing promises) are hard-locked to humans server-side; the public endpoint is rate-capped per visitor and fails closed without its env switch and key.

Email templates

email_templates - support_manager/admin, audited

Reusable subject/body pairs used when Support and RMA screens send mail (e.g. the "matching order not found" reply on an RMA request). Placeholders like {{first_name}} are substituted at send-time - keep the key stable once a screen refers to it.

These are your own templates - this table is owner-scoped server-side, so a template a colleague created does not appear here (and vice versa). Before adding a key a screen already refers to, check with whoever set it up: a screen that sends by key finds a template owned by anyone, so a duplicate key means two rival rows, of which only the most recently edited one is used.

Loading...

Office kiosk location

Lock mobile and desktop clock-in and clock-out near the office to the site kiosk for WHS. TAFE and WFH attendance require this location to be saved and enabled. Location is captured when staff start and finish; there is no background tracking.

Safiery: 45/8 Distribution Court, Arundel QLD 4214. Check the site address on Google Maps. Use this device location only while at this site. Review the accuracy and coordinates before saving.

Load the current setting before editing.

On site now

Visitors and contractors signed in and not yet signed out
NameKindCompanyHostSigned inInduction version
Loading...
This is the non-staff half of the muster list. Staff presence comes from the clock register (the kiosk's own roster screen shows both together) - in an evacuation read the tablet, which counts staff and visitors in one list. A visitor who walks out without signing out stays on this list until someone closes them off, which is the safe failure: the warden looks for a person who has left, never the reverse. If the tiles above show ? the read FAILED - that is not an empty site, so press Refresh rather than trusting it; and if the count says the list was clipped, more people may be on site than are shown here.

Visitor and contractor record

NameKindCompanyHostSigned inSigned outInduction acknowledgedSignature
Loading...
The induction version column is the retained safety record: it names the exact document version the person agreed to, stamped by the server at sign-in, never taken from the tablet. Re-publishing the induction below does not rewrite these rows.

Paired tablets

TabletPaired byPairedLast activityStateAction
Loading...
Pairing mints a long-lived device token and shows it once. It is not stored anywhere you can read it back and it is never shown again - paste it into the tablet straight away, and if it is lost, revoke the tablet and pair it again. The token authenticates the tablet only: it can never sign in to HQ, and revoking bumps the device's token version so every outstanding copy dies on its next request.

Contact site admin

Where a tablet's "Contact site admin" report is emailed

Site reports go to adamd@safiery.com unless an administrator saves a different recipient here. Reports use the Quasar HQ notification email service.

Manager sign-out

Whether a manager can sign staff out of the site clock

ON when never set - matches the Operations board's existing Sign out. Untick to block manager sign-outs everywhere (People and Operations). Stored in app_settings under kiosk.manager_signout_enabled, admin-only server-side.

WHS and Emergency induction

Shown on the tablet to every visitor and contractor before they can sign in
Publishing bumps the version. Everyone currently on site acknowledged the previous version and will not be asked again until they next sign in. Existing records keep the version they agreed to - that is the point of the version, so never edit wording to "correct" an old acknowledgement. Publish a new version instead.

The wording and the version are one record: this editor only ever writes them together, so the text can never change under acknowledgements already recorded against a version. Stored in app_settings under kiosk.whs_induction, which is admin-only server-side (the kiosk. prefix lock in the db function) - a hidden button is not the control.

Work type vocabulary

Read-only here

Loading...

Not signed in on this address - open the main app to sign in, then return.
Checking your session...
The first load after a deploy can take a few seconds while the server wakes up. If this message never goes away, the page script failed to start - press F12, open the Console tab, and photograph what it shows.
Administration failed to load.