Administration
The System Settings module (reserved for administrators) covers user management, application settings and backups.
Users and roles
In System Settings → Users and permissions, you:
- create accounts for your team members;
- assign each one or more roles;
- enable / disable an account when someone joins or leaves.
The available roles and their scope are described in Navigation & roles. In short:
| Role | Purpose |
|---|---|
| Administrator | Manages the whole app and the other users |
| Vendor | Commercial operations (sales, purchases, POS, finance) |
| Warehouseman | Stock and purchase management |
| Cashier | Checkout at the point of sale |
| Accountant | Finance and reports |
| Auditor | Read-only view of finance and reports |
Identity and sign-in management relies on Keycloak. Depending on the setup, passwords, two-factor authentication and security policies are managed centrally there.
Access best practices
- Give each person the least privilege they need.
- Reserve the Administrator role for a very small number of people.
- Immediately disable the accounts of people who leave the company.
Settings
System Settings → Global settings centralizes the app configuration: company identity, currency, taxes, default language, integrations. See Configuration for detail.
Backups
System Settings → Backups manages the backups made by the application itself:
- an automatic full backup every night (01:30 by default), kept for 14 days by default;
- the Create Full Backup button to run one at any time;
- for each backup: status, size, checksum and download;
- restore, when enabled: it requires Maintenance Mode, which blocks writes, and first creates a Safety Backup.
These backups contain the business data and the application files. They contain neither user accounts nor the server configuration: for a complete copy of the installation, also use the server backup script. See Upgrades and backups.
A backup is only worth something if it can be restored and is kept off the server. Download them or copy them elsewhere, and test a restore from time to time.
Audit log
Sensitive actions are recorded in an audit log, useful for compliance tracking and investigation in case of an anomaly.