Employee workspace

Settings

Owner/Admin

Settings control panel

Review operational defaults by control surface instead of scanning one long wall of disabled fields. Pricing, tax, templates, access, delivery, and material taxonomy all stay versioned and audit-ready.

Control state

API defaults Write workflow locked

Defaults connected, stored read pending. Sensitive changes stay non-retroactive and require reason, version, and audit capture before writes unlock.

Showing API defaults while stored setting overrides are unavailable.

API defaults

26

Defaults endpoint connected

Groups

12

Operational sections

High risk

32

Require reason when writable

Stored overrides

0

13 fields connected to live defaults/read path

Selected control surface

Roles and permissions

Employee role baselines, approval authority, sensitive visibility, and portal scope.

13 default 13 fields Section-level audit required 8 high risk

Review posture

This section is intentionally presented as a read-only control surface until the FastAPI reason, version, effective-date, and audit save workflow is wired. Secret values remain key references only.

Owner decision queue

0

Pending configuration items still need an explicit owner decision.

Stored overrides

0

Active settings already diverging from defaults in this surface.

Secret-backed setup

0

Fields that should resolve by secret-key reference only.

Read-only actions

See prior versions and effective dates once the audit endpoint is wired.

Review before/after payloads for high-risk changes before activation.

Bundle reason, version, and rollout timing before writes unlock.

Confirm owner-review and non-retroactive rules for this surface.

Employee role baselines

Default employee roles and the admin responsibilities tied to them.

2 high-risk fields Reason and versioning apply

Employee roles

Default
Owner/AdminSalesProcurementOperationsFinanceSupportMarketing
permissions:employee_role_matrix

Owner/Admin control baseline

Default High risk
manage settingsmanage users rolesapprove quote thresholdsapprove po thresholdsoverride payment verification
permissions:owner_admin_control_baseline Reason required when writable

Operational role boundaries

Default
Sales drafts and sends quotesFinance verifies payment proofProcurement manages vendor costOperations manages shipments
permissions:operational_role_boundaries

Settings audience boundary

Default High risk

Owner/Admin can edit; authorized reviewers can read scoped summaries only.

Reason required when writable

Sensitive visibility

Sensitive visibility rules that keep supplier cost and finance fields scoped.

2 high-risk fields Reason and versioning apply

Supplier cost visibility

Default High risk

Supplier cost visible to Owner/Admin and Procurement only by default

permissions:supplier_cost_visibility_rule Reason required when writable

Finance visibility rule

Default High risk

Finance records visible to Owner/Admin and Finance only by default

permissions:finance_visibility_rule Reason required when writable

Client-safe quote visibility

Default

Client quotes exclude supplier identity, cost, competing offers, and internal margin

permissions:client_safe_quote_visibility_rule

Portal and approval scope

Portal and approval boundaries for clients, vendors, and owner review.

4 high-risk fields Reason and versioning apply

Client portal scope

Default High risk

Client OTP access is limited; full portal access starts after verified payment

permissions:client_portal_scope_rule Reason required when writable

Client portal access states

Default
otp limited: quotesapprovalsproof uploadmessaging; payment verified member: add ordersshipmentsand document access.

Vendor portal scope

Default High risk

Vendor users see assigned RFQs, own quotes, own POs, and own documents only

permissions:vendor_portal_scope_rule Reason required when writable

Vendor portal access states

Default
registered or under review: no scoped record access; active authorized: RFQssupplier quotesPOsdocumentsstatus updatesand messaging.

Approval authority baseline

Default High risk

Owner/Admin is the default approver for quote, PO, discount, low-margin, and payment overrides

permissions:approval_authority_baseline Reason required when writable

Approval rule coverage

Default High risk
Owner/Admin approves quote threshold overridesPO thresholdsdiscountslow marginpayment overridesand settings changes.
Reason required when writable

Quick help

What to review first

1. Start with pricing, tax, and payments because they change approvals and issued-document snapshots.

2. Check communications and templates next so sender readiness, secret references, and live-send gates are obvious.

3. Finish with permissions, legal, and material taxonomy because they shape safe access and public-facing content.