Admin-only screens
| Screen | Where it lives | What it does |
|---|---|---|
| Users & Roles | Settings → Users & Roles | Invite, deactivate, change role, link to HR record |
| Security Policy | Settings → Security | MFA enforcement, IP allowlist, session timeout, password complexity |
| Audit Log | Settings → Audit Log | Append-only log of every user action for compliance |
| AI Caps | Settings → AI → Caps | Per-user daily / per-request credit limits |
| Subscription | Settings → Subscription & Billing | Upgrade, downgrade, cancel, view invoices |
| Integrations | Settings → Integrations | All third-party connections |
| Channels | Settings → Sales Channels | Sales channel definitions for cross-channel reporting |
| Data Export | Settings → Data → Export | Full workspace export in CSV |
| Tenant Profile | Settings → Company Profile | Branding, currency, fiscal year |
What only Admins can see
- Billing data and Stripe invoices
- Audit log entries (Managers can see entries on records they own; only Admins see all)
- All users’ AI usage on Reports → AI Usage
- API keys and webhook secrets stored in the Vault
- Other admins’ MFA status
Audit log
Every state-changing action in the ERP writes a row to the audit log: who, what, when, before/after values, source IP. The log is append-only — entries cannot be edited or deleted, even by Admins. Retention follows your plan: 1 year on Standard, 3 years on Plus, 7 years on Pro. Filter the log by user, by entity (e.g. only finance.invoice events), by date range, or by source IP. Export to CSV for compliance audits. The audit log surfaces operator impersonation events too (see Operator Console) so customers always have a record of when Softbooq staff entered their workspace.Promote, demote, and suspend users
Change role
Pick from Admin / Manager / Employee / Viewer / Client. The change applies on next page load.
Security Policy
The Security tab consolidates workspace-wide security controls:- MFA enforcement — require MFA for all users with a configurable grace period before lockout
- Session timeout — set how long an inactive session stays valid (default 8 hours)
- IP allowlist — only allow sign-in from listed CIDR ranges
- Password complexity — minimum length and character mix
- SSO restrictions — restrict sign-in to specific identity providers (e.g. only Microsoft 365 for your domain)
See also
Settings
All admin controls live under Settings.
Accounts
User identity and per-account security.
Subscription
Plan tiers, upgrades, downgrades.