Users and Roles
Accounts, access and securityUsers
| User | Role | Access | Last login | 2FA | Status | |
|---|---|---|---|---|---|---|
| Loading... | ||||||
Departments
app_settings 'roles.departments' - admin-only, audited| Department | Members | People | |
|---|---|---|---|
| Loading... | |||
Click a department's People chips to change who is in it (HR or admin only; audited). Renaming or removing a department here does not touch anyone's existing People directory record - it only changes the list offered when assigning someone, and on the People page. Removing a department that still has members does not unassign them. An account tagged "no People record" has a login but no directory record yet (so roles alone can never place it in a department) - assign it to one to create the record.
Team chat channels
| Room | Access |
|---|---|
| Loading... | |
Department rooms follow the Departments card above - renaming a department there renames its chat room in the same save, and a new department gets a room the moment it saves. A custom channel is any extra room added here; "members" on a custom channel means administrators only until per-channel membership exists. All Chat stays open to every signed-in person and a direct message is its two participants only; neither is set here. Applies immediately to every send, read, unread count and the room list itself, and a restricted room stops mirroring to Google Chat while it stays restricted.
Functional roles
These are the roles you assign to a person on Users and Roles (tick them on their record or when creating the login). This page defines what each role reaches - it does not assign anybody. Pick a role to see and edit every module it reaches: left tick = View (the module appears in their menu), right tick = Edit.
Which Edit ticks actually do something
Edit now drives the role's in-module ACTION buttons (HQ-542): on invite or re-sync, a module's action keys are granted only where the role holds Edit there - View alone shows the tab and nothing else - so the Edit column here and the Action column on a user record describe the same thing. Money and other gated actions additionally stay locked to their named roles whatever Edit says. Server-side WRITE enforcement of Edit exists today for Manufacturing (boms / bom_lines / bom_operations / test_equipment) only; B2B edit stays code-locked to sales + sales_manager (HQ-456) - the B2B Edit tick is a display of that code constant, so unticking it removes nothing. Widening server write enforcement to the other modules is tracked as HQ-539. Built-in roles: module grants editable, key and label locked. Custom roles: label, description and grants editable; Archive is soft (grants kept, the role stops being grantable or effective).
Loading...
Full matrix - every role side by side (wide; scrolls sideways)
| Loading... |
What cannot be changed here (locked in code) (collapsed by default)
Loading...
Money approval layers
app_settings 'approvals.money_rules' - admin-only, auditedLoading...
Enforced server-side in the RMA money authorisation (G-R3) - management (Administrator or Money authorised) always passes, at any amount, whatever is configured below. A saved change applies from the very next authorisation attempt - no deploy needed. When someone attempts an amount above every layer they hold, the people named in the covering layer get an in-app notification, and the requester is told the attempt needs a higher approval.
Other approval rules (preview - wired to no server table or gate; collapsed by default)
Other approval rules
Preview - not yet wired to a server table or gate| Rule | Approvers | Threshold / Conditions | Enforced in | Action |
|---|
Rule details
Select a rule to view its approvers and notes.
General settings
Security & access policies
Workflow defaults
Notifications
Monitoring & records
Numbering format is fixed server-side (DB triggers) and shown for reference. RMA numbering is continuous and never reused (mirrors _support-numbering.cjs).
Data & backups
Configuration summary
Recent changes
View allLoading...
Shared mailboxes
Gmail sends as the mailbox that authorised it, so a company address such as sales@safiery.com can only be chosen as the From address on a document once that mailbox itself is connected here. An alias is not enough. Connecting one never affects your own personal Gmail connection.
| Mailbox | Status | Connected by | Last updated | |
|---|---|---|---|---|
| Loading... | ||||
Customer comms rail
app_settings 'comms.*' - admin-only, auditedWhere a customer conversation travels while Safiery moves off Intercom. Turning a half off here never deletes anything: the imported Intercom history lives in HQ's own tables and stays exactly where it is.
Off means a reply leaves through Gmail instead, from the mailbox chosen on the case. This half is safe to switch off today.
Email signatures
app_settings 'signature.*' - admin-only, auditedWhat gets appended when mail leaves through a compose From choice. A person's own signature is theirs to edit (Profile > Email signature); sending as yourself wraps it in the company template below. Sending as a role mailbox uses that mailbox's block. Empty means an honest name-only default, never an invented title or number.
SKU convention
app_settings 'sku.*' - admin-only, auditedOwn (Safiery-made) products get a dotted code, checked as it is entered on Inventory's + New item; resale products keep the supplier SKU untouched. A format issue prompts the person entering it and they can still consciously save (flag, don't block); a duplicate SKU is always refused outright. Existing codes are never re-checked or regenerated.
AI providers
Assistants work only when the system-level keys are configured. Provider keys are held server-side, never in the browser.
Data access
Admin sets the policy here; each staff member connects their own AI account under their own profile. WooCommerce is retired per CLAUDE.md v2.0 (Xero is the order-of-record); the Woo card is reference-only.
Audit log
| When | User | Action | Module / Record | Detail |
|---|---|---|---|---|
| Loading... | ||||
Deleted records
Loading...
Status
The bot answers ONLY from the knowledge sources below. The env switch and API key are server-side facts (read-only here); flipping the toggle alone cannot enable the bot.
Knowledge sources
Source toggles are saved with Save settings. The curated knowledge list below is always on.
Knowledge
Each document is converted to plain text on the server and split into knowledge entries by heading, added to the curated list above. The original file is never stored, and re-ingesting a document with the same title disables its previous entries first.
Reference library
RefreshThe library of manuals, datasheets, wiring guides and certificates is created and tagged on the Reference Docs page. Link one below to let the bot read its full text - split into entries above, exactly like an upload - instead of only citing its title and link.
Unlink disables that document's entries; re-link to pull in a newer version.
Review queue
Show all recentTest console
Test questions run the REAL engine (logged as mode "test", capped 30/hr per user) but skip the public visitor cap. Works before the public kill switch is on.
Embed on the website
Optional attributes: data-accent takes your brand colour; data-title renames the launcher. The widget fails to a friendly offline note whenever the bot is disabled.
One server prerequisite: the website's origin (e.g. https://safiery.com) must be listed in the CORS_ALLOW_ORIGIN environment variable on this site, or the browser will block the widget's calls. Ask whoever manages the Netlify environment before embedding.
On site now
Visitors and contractors signed in and not yet signed out| Name | Kind | Company | Host | Signed in | Induction version |
|---|---|---|---|---|---|
| Loading... | |||||
Visitor and contractor record
| Name | Kind | Company | Host | Signed in | Signed out | Induction acknowledged |
|---|---|---|---|---|---|---|
| Loading... | ||||||
Paired tablets
| Tablet | Paired by | Paired | Last activity | State | Action |
|---|---|---|---|---|---|
| Loading... | |||||
WHS and Emergency induction
Shown on the tablet to every visitor and contractor before they can sign inThe wording and the version are one record: this editor only ever writes them together, so the text can never change under acknowledgements already recorded against a version. Stored in app_settings under kiosk.whs_induction, which is admin-only server-side (the kiosk. prefix lock in the db function) - a hidden button is not the control.
Work type vocabulary
Read-only hereLoading...