Employee workspace

Settings

Owner/Admin

Settings control panel

Review operational defaults by control surface instead of scanning one long wall of disabled fields. Pricing, tax, templates, access, delivery, and material taxonomy all stay versioned and audit-ready.

Control state

API defaults Write workflow locked

Defaults connected, stored read pending. Sensitive changes stay non-retroactive and require reason, version, and audit capture before writes unlock.

Showing API defaults while stored setting overrides are unavailable.

API defaults

26

Defaults endpoint connected

Groups

12

Operational sections

High risk

32

Require reason when writable

Stored overrides

0

13 fields connected to live defaults/read path

Selected control surface

Security and MFA

OTP channel, passkeys, TOTP fallback, access gates, and high-risk step-up.

2 API / 4 default 6 fields Section-level audit required 5 high risk

Review posture

This section is intentionally presented as a read-only control surface until the FastAPI reason, version, effective-date, and audit save workflow is wired. Secret values remain key references only.

Owner decision queue

0

Pending configuration items still need an explicit owner decision.

Stored overrides

0

Active settings already diverging from defaults in this surface.

Secret-backed setup

0

Fields that should resolve by secret-key reference only.

Read-only actions

See prior versions and effective dates once the audit endpoint is wired.

Review before/after payloads for high-risk changes before activation.

Bundle reason, version, and rollout timing before writes unlock.

Confirm owner-review and non-retroactive rules for this surface.

Authentication defaults

Default authentication channels and employee factor policy.

3 high-risk fields 1 API Reason and versioning apply

Default client OTP channel

API default High risk

whatsapp

security:default_otp_channel Reason required when writable

Employee passkeys

Default High risk
Enabled
Reason required when writable

Employee TOTP fallback

Default High risk
Enabled
Reason required when writable

Recovery and control

Recovery and step-up controls for higher-risk account changes.

2 high-risk fields 1 API Reason and versioning apply

Employee MFA recovery

API default High risk

owner admin or self whatsapp otp

security:employee_mfa_recovery Reason required when writable

High-risk settings step-up

Default High risk
Enabled
Reason required when writable

Client full access after payment verification

Default
Enabled

Quick help

What to review first

1. Start with pricing, tax, and payments because they change approvals and issued-document snapshots.

2. Check communications and templates next so sender readiness, secret references, and live-send gates are obvious.

3. Finish with permissions, legal, and material taxonomy because they shape safe access and public-facing content.