This guide is based on a browser-recorded walkthrough in the rebuilt DrillerDB console. When a step can send, submit, export, or change account access, the guide calls out the review boundary.
Security & Settings is the admin control room for company identity, account access, MFA posture, and external integrations. Review these pages before changing anything that affects users, customer-facing branding, API access, billing, or third-party connections.
Quick Start
- Open Settings and review company identity, defaults, display, onboarding, and optional feature controls.
- Open Security to check MFA adoption, enforcement status, and supported authentication methods.
- Open Users to review active users, roles, MFA indicators, account status, and the Add User boundary.
- Open Integrations to scan accounting, GPS/fleet, communications, and AI provider status.
- Open a provider detail page and stop before saving credentials, testing, connecting, disconnecting, or enabling automation.
Step-by-Step: Security & Settings
Start with company settings
Open Settings to review company identity, contact details, default location settings, logo, display preferences, onboarding status, and optional company-wide features. Treat Save Changes and upload controls as admin-only actions.
Company settings feed proposals, invoices, customer portal pages, field paperwork, and default units, so review the downstream impact before saving.
Review MFA and security posture
Open Security to check active-user count, MFA-enabled count, adoption coverage, enforcement status, and supported authentication methods.
Use Enforce MFA only after users are ready for the next-login setup requirement.
Confirm user access from the Users page
Open Users to review active users, role filters, MFA indicators, account status, and the Add User boundary. This is where admin access changes happen.
Scan integrations before connecting anything
Open Integrations to review accounting, GPS and fleet, communications, and AI automation providers. Each provider card shows whether it is connected before you open its detail page.
Open a provider detail and stop at the connection boundary
Open an integration detail page to review status, credential fields, OAuth choices, test buttons, and disconnect controls. Do not connect, test, save secrets, disconnect, or enable automation until the office has approved the change.
OAuth, API keys, webhook secrets, and accounting connections are live security boundaries. Store only approved credentials.
Admin and security boundary
This guide records read-only review of company settings, MFA posture, user access, and integration setup. It does not save company settings, invite or deactivate users, generate API keys, connect OAuth accounts, save secrets, test credentials, disconnect providers, or enable automation.
Use settings saves, user changes, API keys, MFA enforcement, billing changes, and integration connection controls only after the account owner or admin has approved the exact change.