Employee workspace

Settings

Owner/Admin

Settings control panel

Review operational defaults by control surface instead of scanning one long wall of disabled fields. Pricing, tax, templates, access, delivery, and material taxonomy all stay versioned and audit-ready.

Control state

API defaults Write workflow locked

Defaults connected, stored read pending. Sensitive changes stay non-retroactive and require reason, version, and audit capture before writes unlock.

Showing API defaults while stored setting overrides are unavailable.

API defaults

26

Defaults endpoint connected

Groups

12

Operational sections

High risk

32

Require reason when writable

Stored overrides

0

13 fields connected to live defaults/read path

Selected control surface

Communications

Email senders, WAHA sessions, dry-run gates, and transport readiness.

15 default / 2 pending 17 fields Section-level audit required 2 high risk

Review posture

This section is intentionally presented as a read-only control surface until the FastAPI reason, version, effective-date, and audit save workflow is wired. Secret values remain key references only.

Owner decision queue

2

Pending configuration items still need an explicit owner decision.

Stored overrides

0

Active settings already diverging from defaults in this surface.

Secret-backed setup

2

Fields that should resolve by secret-key reference only.

Read-only actions

See prior versions and effective dates once the audit endpoint is wired.

Review before/after payloads for high-risk changes before activation.

Bundle reason, version, and rollout timing before writes unlock.

Confirm owner-review and non-retroactive rules for this surface.

Email senders

Sender identities reserved for customer, finance, and support flows.

10 fields 2 pending

Sales sender

Default

sales@diamondstonex.com

Accounts sender

Default

accounts@diamondstonex.com

Support sender

Default

support@diamondstonex.com

OTP sender

Default

otp@diamondstonex.com

Procurement sender

Default

procurement@diamondstonex.com

No-reply sender

Default

no-reply@diamondstonex.com

Reply-to policy

Default

support@diamondstonex.com by default

communications:email_reply_to_defaults

Email provider auth status

Default

Pending Gmail sender authorization review

communications:email_provider_auth_status

Email DNS authentication status

Not configured

DNS authentication readiness is not configured.

communications:email_dns_authentication_status

OAuth callback placeholder

Not configured

OAuth callback placeholder is not configured.

communications:email_oauth_callback_placeholder

WhatsApp control

WAHA session assignment and transport mode for dry-run messaging.

3 fields

Default WAHA session

Default

diamondstone-main

WAHA webhook secret reference

Default

Secret key reference required before webhook verification.

communications:whatsapp_webhook_secret_ref Secret reference only

WAHA edge shared-secret reference

Default

Secret key reference required before edge message transport.

communications:whatsapp_edge_shared_secret_ref Secret reference only

Delivery gates

Operational gates that keep external messaging disabled until approved.

2 high-risk fields Reason and versioning apply

Message dry-run mode

Default
Enabled
communications:whatsapp_dry_run_enabled

Live external sends

Default High risk
Disabled
communications:whatsapp_live_send_approved Reason required when writable

Message job live delivery

Default High risk
Disabled
communications:message_job_live_delivery_enabled Reason required when writable

Dispatch categories

Which outbound message families are reserved before transport goes live.

1 field

Reserved message families

Default

Portal invite, WhatsApp OTP, email OTP fallback, quote sent, RFQ sent, invoice issued, payment verified, shipment update, delivery follow-up.

Quick help

What to review first

1. Start with pricing, tax, and payments because they change approvals and issued-document snapshots.

2. Check communications and templates next so sender readiness, secret references, and live-send gates are obvious.

3. Finish with permissions, legal, and material taxonomy because they shape safe access and public-facing content.