Boostio Business OS

Settings & Roles

Team, permissions, the full audit log and business settings. Admin-only — every change is logged with your name.

Sample data

Team & users

Everyone who can sign in to the Business OS. Invites go by email with a signed join link — no passwords are ever created or shown here. Click a row to manage the member.

Roles & permissions

Two roles today: Admin (full access) and Staff (only customers and grievance tickets assigned to them). Finer permissions can be added here if the team grows.

Permission matrix — what each role can see and do
CapabilityAdminStaff
Business Health dashboard FullWhole-org KPIs ScopedOwn book KPIs + feed
Customers — directory & 360° Full ScopedAssigned customers only
Customer actions — plan · pause · reassign Full None
Payments & Revenue ledger Full None
Refunds & payment links Full None
Reports Full None
Grievance desk FullAll tickets ScopedAssigned tickets only
Grievance reply & status moves Full ScopedOwn tickets
Reassign grievances Full None
Settings & Roles (this page) Full None
Full audit log Full None
CSV exports Full ScopedScoped views only

Enforced server-side on every API — a staff request only ever returns rows assigned to that member. What this UI hides or disables is convenience, not the security boundary.

Staff assignments

Staff work only what is assigned to them. Move customers and open grievances between staff here — the same reassign actions as the Customers and Grievances drawers, logged the same way.

Assigned customers

    Assigned grievances (open)

      Open grievances only — resolved tickets keep their history with whoever closed them.

      Audit log

      Append-only — every refund, plan change, role change, invite, removal, settings change and sign-in lands here with its actor. The dashboard previews the latest few; this is the full log. Nothing is ever edited or deleted.

      Company & GST

      Rendered on every GST tax invoice (the customer portal shows the same fields). [Brackets] are launch placeholders — same convention as the legal templates.

      Enter a valid email address.

      15-character GSTIN — prints on every invoice.

      998311 — confirm with your CA (portal invoice note).

      Invoice series

      The BST/<FY>/NNNN numbering the ledger and the customer portal share.

      1–6 letters or digits.

      Financial year
      Next invoice

      The series continues from the ledger — a prefix change starts at the next number, never 0001, and numbers are never reused. Pre-Apr-2026 invoices stay in the BST/2025-26 series.

      Razorpay keys

      Payments run through Razorpay (UPI · cards · netbanking, INR). Keys are shown masked — secrets never reach the browser.

      Mode
      Test mode
      Key ID
      rzp_test_••••••••ME
      Key secret
      •••••••••••• server only
      Webhook secret
      •••••••••••• server only

      Rotate keys in the Razorpay dashboard, update the server environment and redeploy — this screen never holds or reveals a secret, so there is nothing to leak.

      Grievance SLA targets

      The clocks behind the Grievance desk. Timers, queue KPIs and the dashboard needs-attention feed recompute from these the moment you save.

      Whole number between 1 and 336 hours.

      Whole number between 1 and 90 days.

      The published “acknowledge in 48 h · resolve in 15 days” wording on the desk, the customer portal and the grievance pages is policy copy — keep it in step if you change these for real.

      Customer data sync

      How follower numbers reach the OS. Read-only — the cadence is set server-side.

      Connected accounts
      Every ~6 hours
      Source
      Read-only Instagram Graph API
      Manual accounts
      On customer upload
      Manual “Refresh now”
      15-min cooldown

      The cooldown is Meta rate-limit courtesy. We never log into customer accounts — connected mode is a read-only token the customer granted; accounts with neither source show no numbers, never estimates.

      WhatsApp templates

      Template IDs used for customer notifications — managed in the BSP console, IDs live server-side. [Sample list.]

      • Onboarding welcome boostio_welcome_v2 Approved
      • Strategy drop ready boostio_drop_ready_v1 Approved
      • Payment receipt + invoice boostio_invoice_v1 Approved

      Active sessions

      Everyone signed in right now, org-wide. Signing a session out kills its cookie on the next request.

      Active sessions
      MemberLocation Last seen Actions

      Two-factor authentication

      TOTP (authenticator-app) 2FA lands with the admin backend — sign-in will then require a 6-digit code.

      Not enrolled

        Available once the backend ships — enrolment needs the server to issue the TOTP secret. Password resets and session sign-outs are already logged (kind: sign-in & security).

        Boostio Business OS · internal tool · Business Health · UI kit