Skip to content

Admin Portal (Super Admin)

Module: Admin Portal  |  Audience: Super Admin Only


Table of Contents


Overview

The Admin Portal is a separate application accessible only to Super Administrators. It provides platform-level management capabilities for organizations and tenants. Data created here forms the top-level structure that all other modules operate within.

Access: Only users with the Super Admin role can access the Admin Portal. Regular users will see an "Unauthorized" page.


Accessing the Admin Portal

The Admin Portal is accessed through a separate URL (configured during deployment). After authentication, Super Admins see the admin sidebar with:

├── Dashboard
├── Organization
│   ├── Organizations
│   └── Organization Admin Users
├── Global Configuration
└── Profile

Admin Dashboard

Path: Dashboard  |  URL: /dashboard

Overview of all organizations and tenants managed by the platform, including: - Total organizations - Active / Inactive organizations - Total tenants - System health metrics


Organization Management

Path: Organizations  |  URL: /admin/organization

Organization List

Paginated list of all organizations with name, status, SSO configuration, and creation date.

Creating an Organization

Path: Organizations → + Create  |  URL: /admin/create-organization

Field Type Required Validation Depends On
Name Text Yes Max 100 characters; unique —
Description Text Area No — —
Parent Company Dropdown No For subsidiary relationships Organizations (self-referencing)
SSO Enabled Toggle No Default: Off —
SSO Provider Text No Identity provider name (e.g., "Okta", "Azure AD") SSO Enabled
SSO Connection ID Text No Auth0 connection identifier SSO Enabled

Conditional Fields: - SSO Provider and SSO Connection ID are only relevant when SSO Enabled = On.

Organization Detail View

Path: Organizations → Click a row  |  URL: /admin/organization/:id

Section Content
Details Name, description, parent company, SSO settings
Status Active / Inactive
Tenants List of tenants within this organization
Admin Users Users with admin access to this organization

Editing an Organization

Path: Organization Detail → Edit  |  URL: /admin/organization/:id/edit

All creation fields are available for editing.


Organization Admin Users

Path: Organization Admin Users  |  URL: /admin/organization-admin-users

Manage users who have administrative access to specific organizations. This is the bridge between the platform-level Super Admin and organization-level Admins.

Action Description
Assign Admin Grant a user admin access to an organization
Remove Admin Revoke admin access from a user
View Assignments See which users are admins for which organizations

Global Configuration

Path: Global Configuration  |  URL: /admin/global-config

Platform-wide settings. Currently this covers the Email Sender Configuration used for all outgoing system email (invitations, notifications, password resets, etc.).

Email Sender Configuration

Select one active provider at a time:

Provider Notes
SMTP Direct SMTP server credentials
SendGrid SendGrid API key
Mailchimp (Mandrill) Mandrill/Mailchimp API key
SMTP with OAuth2 (Microsoft) Microsoft 365 mailbox via OAuth2; requires a one-time "Connect with Microsoft" authorization
Microsoft Graph API Sends via the Microsoft Graph API; no OAuth2 authorization step required

SMTP fields:

Field Type Required Notes
Host Text Yes e.g. smtp.gmail.com
Port Number Yes 1–65535
Username Text Yes —
Password Password Yes Masked after saving; leave as *** to keep the existing value
From Email Text Yes Must be a valid email
From Name Text No —
Use TLS Toggle No Default: On

SendGrid / Mailchimp fields:

Field Type Required Notes
API Key Password Yes Masked after saving
From Email Text Yes Must be a valid email
From Name Text No —

SMTP OAuth2 (Microsoft) / Microsoft Graph API fields:

Field Type Required Notes
Application (Client) ID Text Yes From the Azure app registration
Directory (Tenant) ID Text Yes Azure tenant ID
Client Secret Password Yes Masked after saving
From Email Text Yes Must be a valid email
From Name Text No —
Redirect URI Text SMTP OAuth2 only Must be registered as an allowed redirect URI in the Azure app registration; not used by Microsoft Graph API

For SMTP with OAuth2 (Microsoft), save the Azure credentials first, then click Connect with Microsoft to complete the OAuth2 authorization and grant the app access to send mail from the configured mailbox. A status chip shows Connected / Not Connected.

Testing the Configuration

Enter an address under Send Test Email and click Send Test to send a test message through the currently selected provider.


Tenant Management

Path: Tenants  |  URL: /tenants

Note: Tenant management pages exist but are not yet linked from the sidebar navigation — they're reached directly by URL. Organization detail currently shows tenant provisioning as in progress.

Tenants represent isolated data partitions within the multi-tenant platform. Each organization can have one or more tenants.

Creating a Tenant

Path: Tenants → + Create  |  URL: /tenants/create

Field Type Required Validation Depends On
Tenant Name Text Yes Unique —
Organization Dropdown Yes — Organizations
Configuration JSON No Tenant-specific settings —

Tenant Detail View

Path: Tenants → Click a row  |  URL: /tenants/:id

Section Content
Details Name, organization, configuration
Status Active / Inactive

Editing a Tenant

Path: Tenant Detail → Edit  |  URL: /tenants/:id/edit


Related: User & Role Management · Getting Started