Docs

Platform Console

The Platform Console is the superadmin surface that operates WorkOSync itself. It sits at /admin, outside the normal app shell, and is used to onboard tenant companies, manage plans and subscription billing, configure gateways and set platform-wide policy. A normal company user never sees it.

Restricted access

Only accounts flagged as superadmin can open the console. Anyone else who visits /admin sees a Superadmin only card with a link back to their workspace, and every crawler or bot gets a 404 for the path. See Security for how that is enforced.

Opening the console

Superadmins see an Admin Center chip in the top bar of the app and an Admin center entry in their account menu. Both open the console. The console has its own dark top bar with the WorkOSync mark, a Back to app link, a red SUPERADMIN tag and your initials, and a left rail with eight sections: Overview, Companies, Users, Packages, Payments, Invoices, Payment Gateways and Platform Settings.

Overview

The Platform Console overview with four KPIs, recent signups and system health
Platform overview: companies, MRR, annualised run-rate and active users, plus recent signups and system health.
TileMeaning
CompaniesNumber of tenants, with how many are on trial.
MRRMonthly recurring revenue: the sum of every tenant's subscription, with the month-on-month trend.
ARR (run-rate)MRR multiplied by twelve.
Active usersUsers across all tenants.

Recent signups lists the five newest companies with their plan and start date. System health shows the API, the ERPNext engine, Stripe webhooks, the last backup time and the number of queue workers, each with a green status dot.

Companies

The Companies section listing tenants with plan, users, MRR, since date, status and an Impersonate button
Every tenant with its org ID, plan, seat count, MRR, start date and status.

The table lists every tenant: Org ID, Company, Plan, Users, MRR, Since and Status. Status is Active (green), Trial (amber) or Past due (red).

Adding a company

  1. Click Add company

    The button sits at the top right of the section.

  2. Fill in the dialog

    Company name (required), Plan (Starter, Growth, Scale or Enterprise), Users and MRR (AED).

  3. Save

    Click Add company. The tenant is created as Active with today's date and appears at the top of the table.

Impersonation

Impersonate opens that company's workspace in a new tab so you can see exactly what the customer sees and resolve a support issue in context. A confirmation appears in the console, and impersonation never exposes the customer's credentials.

Users and the superadmin toggle

The Users and roles section with a table of platform users and a Superadmin switch per row
Users & roles: every user across every tenant, with a switch that grants or revokes console access.

The table shows Name, Email, Company, Role, Last active, Status and a Superadmin switch. Your own row is marked you. Turning the switch on gives that person the Platform Console; turning it off removes the Admin Center from their app immediately. Access is by this assignment only.

Close-up of the users table with the Superadmin switches
The Superadmin switch. Grant it sparingly: it unlocks billing, gateways and every tenant.

Invite user opens a dialog with Full name, Email, Company and Role; Send invite adds the person as Active and confirms the invitation.

Packages and pricing

The Packages section with a card per plan showing price and active tenants
Packages: one card per plan with its monthly price, tenant count and an Edit button.

Each plan card shows its colour, name, monthly price in USD (or Custom when the price is zero) and the number of active tenants. New plan and Edit open the same dialog: Plan name, Price (USD / mo, 0 = Custom), Active tenants and Colour (blue, green, yellow or red). What customers see on the pricing page is described in Billing and plans.

Platform payments

The Platform payments section with KPIs and a table of subscription payments
Platform payments: what tenants paid this month, with a receipt and a Send button on every row.
TileMeaning
Collected (Sep)Sum of succeeded payments this month across Stripe and bank transfer.
FailedPayments that did not go through and are scheduled for retry.
Payout nextThe next Stripe payout date.
Gateway feesFees charged by the gateways this month.

The table lists Reference (for example PLT-PAY-0091), Company, Amount, Method (Stripe with the card brand and last four digits, or Bank transfer), Date and Status (Succeeded or Failed). Receipt opens the branded receipt at /platform/receipt/<ref> in a new tab; Send emails it to the company's billing address with a copy to the superadmin. Export gives the table as Excel, CSV or PDF.

A branded WorkOSync payment receipt
The receipt shows PAYMENT RECEIVED or PAYMENT FAILED, the method, the invoice it settles and the seller's legal details.

Subscription invoices

The Subscription invoices section with a table of monthly tax invoices and PDF and Send buttons
Subscription invoices: one FTA tax invoice per tenant per period, with PDF and Send actions.

Every tenant receives a monthly tax invoice such as PLT-INV-0120. The table shows Invoice, Company, Plan, Amount (VAT inclusive), Period and Status (Paid or Overdue). PDF opens the invoice at /platform/invoice/<id>; Send emails it to the customer and copies the superadmin; Email all customers sends every invoice in one go and reports how many were delivered. On real billing events these emails fire automatically.

A branded WorkOSync subscription tax invoice
The subscription tax invoice: seller TRN, the plan and period, net, VAT at 5 percent and gross, plus bank details for transfer.

Payment gateways

The Payment gateways section with cards for Stripe, Tap Payments, PayPal and Razorpay
Platform-level gateway keys used to bill tenants. Each tenant adds its own keys for its customers under Settings.
GatewayCoversKeys
StripeCards, wallets, SEPAPublishable (live), Secret (live), Webhook secret
Tap PaymentsGCC cards, KNET, madaPublic key, Secret key
PayPalInternational walletsClient ID, Secret
RazorpayIndia, UPI, cardsKey ID, Key secret

Paste each key into its password field and click Save keys. Saved cards show a Connected badge and a masked key (first four and last four characters). Keys never appear in plain text again.

Platform settings

Platform settings hold the configuration for the whole multi-tenant estate. The section is read-only until you click Edit settings; then every value becomes editable and Save changes or Cancel appear in the header. Settings are grouped into ten panels.

The full Platform settings page with all ten panels
All ten settings panels. Click Edit settings to change any value, then Save changes.

Branding & identity

FieldWhat it controls
Platform nameThe product name shown in emails and documents.
Legal entityThe seller on subscription invoices and receipts.
Support emailWhere tenants are told to write for help.
Sales emailContact for plan and enterprise enquiries.
Logo URL (light), Logo URL (dark)Brand marks for light and dark surfaces.
Brand primary colorHex colour used for buttons and accents in emails.
Custom domainThe hostname tenants use to sign in.

Billing & tax

FieldWhat it controls
Default currencyAED, USD, EUR, INR or SAR for subscription billing.
VAT rate (%)Tax applied to every subscription invoice. 5 for the UAE.
Company TRNThe platform's tax registration number printed on invoices.
Invoice number prefix, Next invoice numberThe sequence for subscription tax invoices.
Tax-invoice footerPayment terms text printed at the bottom of every invoice.
Payout scheduleDaily (T+2), Weekly, Bi-weekly or Monthly gateway payouts.
Dunning retriesHow many times a failed payment is retried.
Grace period (days)Days a tenant stays active after a failed payment before it is marked past due.

Plans & trials

FieldWhat it controls
Trial lengthHow long a new workspace runs free, for example 14 days.
Trial requires cardWhether sign-up asks for a payment method. Off by default.
Default planThe plan a trial converts to unless the tenant chooses another.
Per-seat overage priceCharge per user above a plan's included seats.
Annual discount (%)Discount for paying yearly, shown on the pricing page.

Email & notifications

FieldWhat it controls
From name, From address, Reply-toThe sender identity on every transactional email.
SMTP host, SMTP port, SMTP user, SMTP secure (TLS)The outbound mail server. Passwords are set on the server, never here.
Superadmin email alertsToggles for New signup, Payment succeeded, Payment failed, Invoice sent, Subscription cancelled and Trial ending.

Security

FieldWhat it controls
Enforce 2FAOff, Owners & admins, or Everyone.
Session timeout (min)Idle minutes before a session ends.
Password min length, Password complexityPassword policy for every tenant.
Login rate-limit / IPAttempts per minute per address before throttling.
Allowed admin IPsComma-separated list; blank allows any address to reach the console.
Audit loggingKeeps the append-only audit trail on.

Data & compliance

FieldWhat it controls
Data regionUAE, EU or US hosting region.
Backup schedule, Backup retention (days)Hourly, Daily or Weekly backups and how long they are kept.
PDPL modeUAE Personal Data Protection Law handling.
GDPR modeEU data-subject handling for European tenants.
Allow data exportWhether tenants may export their data in bulk.

Feature flags

Switches that turn capabilities on or off for the whole estate: Manufacturing, POS, AI layer, WhatsApp inbox, e-invoicing, Multi-company and Arabic / RTL.

Localization

FieldOptions
Default languageEN or AR
TimezoneAsia/Dubai (GST), Asia/Riyadh (AST), Asia/Kolkata (IST), Europe/London (GMT), UTC
Date formatDD/MM/YYYY, MM/DD/YYYY, YYYY-MM-DD, D MMM YYYY
Number format1,234.56 or 1.234,56 or 1 234.56

Legal & registry

Terms URL, Privacy URL and DPA URL are linked from sign-up and emails. Company registration no. and DUNS number are the registry identifiers printed on invoices and used for organisation validation.

Maintenance

Coming-soon mode shows a holding page to the public while staff keep working. Maintenance banner text is shown to all tenants when set. API webhook URL receives platform events.

Where values live

In the demo the console keeps its edits in your browser so you can explore freely. In production, settings, gateway keys and company records are stored server-side and every change is audit-logged.