Skip to main content

System admin guide

System admin is the highest operational role. It can configure product sandboxes, tenant groups, client profiles, users, roles, security settings, billing, integrations, and product-level governance.

System admin access must be treated as privileged access. In production, global system access should require a reason, time limit, 2FA, and complete audit logging.

Product entry points

ProductMain menu areasPrimary outcome
Accounting WorkspaceAccounting setup, Intake, Documents, Clients, Lists, Field rules, Hierarchy, Integrations, ERP exports, Reports, Audit, BillingConfigure a full AP automation flow.
Enterprise IDP / OCR OperationsIntake, Documents, Verification, AI Learning, Quality guarantee, Integrations, Reports, AuditConfigure and govern a high-volume OCR operation.
E-document ArchiveE-document archive, Clients, Lists, Hierarchy, Integrations, Reports, Audit, BillingConfigure retention-aware archive operations.

Accounting sandbox administration

Daily tasks

TaskWhere to do itExpected result
Configure customer onboardingAccounting setup or ClientsCompany, product profile, document fields, OCR profile, and ERP profile are saved.
Configure document fieldsClientsRequired fields, list bindings, visibility, and ERP mappings are ready for verification.
Configure listsListsReference lists are synced from manual, CSV, Rivile, SQL, custom API, or Bank of Lithuania source.
Configure field processingField rulesRules normalize and validate OCR/AI output before verification.
Configure approval governanceHierarchyDocument and line-level approval rules, thresholds, delegations, and roles are active.
Monitor audit evidenceAuditAdmin, document, intake, export, and demo events can be filtered and exported.
Manage archive policiesE-document archiveRetention, legal hold, disposition, and evidence package behavior is product scoped.

Key screens

Client profile fields

Use the client profile screen to decide which fields appear in the document card, which are required, and which values are bound to dictionaries or ERP mappings.

Reference data lists

Use Lists for suppliers, ERP vendor codes, cost centers, VAT classes, currency rates, departments, and other selectable values.

Field processing rule profile

Use Field rules to trim, normalize, lookup, validate, publish, and rollback post-OCR processing logic.

Archive sandbox administration

Archive administration must stay inside archive product scope. It should not expose accounting-only or AI Learning work unless the system admin deliberately switches product context.

Security expectations

  • 2FA should be enabled.
  • Break-glass access should require reason and time limit.
  • All admin actions should write audit events with tenant, product, user, IP, and subject id.
  • Development role override must be impossible in production.
  • Client admin and tenant admin actions must be scoped below system admin privileges.

What this role must not do by accident

  • It must not change another product sandbox while working inside a selected demo sandbox.
  • It must not expose AI Learning to archive-only users.
  • It must not allow production secrets to be visible in normal UI.
  • It must not bypass per-company access rules without an audited reason.

Demo test path

  1. Open the demo picker and choose a product.
  2. Enter as Sandbox admin.
  3. Confirm the left menu matches the selected product.
  4. Open Clients, Lists, Field rules, Hierarchy, Integrations, Reports, Audit, and Billing.
  5. Confirm each click changes state or opens the expected screen, not a static placeholder.