Administration
Users and roles
Setup → Users & assignment lists users, their role (admin or member) and their manager. The manager chain is the role hierarchy used by sharing and approvals.
Sharing
For each object choose who sees records they do not own: public read/write, public read-only or private. Owners, their managers and admins always have full access.
Field history and audit
Changes to key fields (stage, amount, owner, status…) are recorded with who and when. The history is a hash chain: editing or deleting an entry breaks the chain, and the audit page says where.
Security
- Two-factor authentication with any authenticator app (My settings → Security).
- Single sign-on (Setup → Single sign-on): connect any OpenID Connect (Okta, Microsoft Entra ID, Google Workspace, Keycloak, Auth0…) or SAML 2.0 identity provider. People choose Sign in with SSO and enter their work email; the domain picks the connection. Options: create the account on first sign-in (with a default role) and require SSO for those domains (admins keep their password). SAML responses must be signed (RSA-SHA256); the page of each connection lists the values to give your provider (entity ID, ACS URL, metadata, redirect URI).
- Sign in with Google or Microsoft when the client IDs are configured.
- Login rate limiting and lockout, signed sessions stored in SoliDB.
- API tokens per user, stored as hashes.
Languages and currency
Users choose English, French or Spanish in their menu. The organization's currency (USD, EUR or GBP) is set in Setup → Company and applies to every amount and document.