Docs

Workspace Settings

Configure Workspace-wide settings, including event types, accounting exports, dashboards, roles, security, notifications, API access, and organizational defaults.

administrationsystemconfiguration

Workspace Settings

Workspace Settings allow administrators to configure Workspace-wide preferences, review subscription status, and manage security policies, appearance defaults, and system behavior. In the sidebar they appear under Settings -> Workspace. These settings affect all users in your Workspace and should be managed carefully.

General settings

  • Set the Workspace name shown in navigation and Workspace selectors. Renaming the Workspace also updates the Workspace's cloud root folder name.
  • Set the unique Workspace handle used by the managed fallback sender address. It must be 3–48 characters, start and end with a letter or number, and otherwise use lowercase letters, numbers, and hyphens. Einblick previews the normalized value and checks availability before saving. A change applies to future mail; already-sent messages keep their original From address and replies still follow Reply-To.
  • Set the default country and currency used by Workspace workflows.
  • Set the default content language used as the source language for new editorial content. This is independent of each user's interface language; when left empty, Einblick derives it from the Workspace country.
  • When invoicing is enabled, choose the default billing wage used as the final fallback for work-time billing.
  • Set the default invite role preselected when admins invite a new Workspace member.
  • The Inventory card holds Allow negative material balance, which is enabled by default. When disabled, Einblick rejects any outbound booking that would push material stock below zero — including completing a production run. Production reservations remain informational warnings in either mode.

Data model and custom fields

  • Open Workspace Settings → Data Model to manage custom fields for buildings, events, event slots, and festivals when those features are enabled.
  • Custom fields can be short text, long text, rich text, number, boolean, date, or select fields. Configure their stable slug, label, description, required state, group, and display order; a field's slug and type cannot be changed after creation.
  • Short text, long text, and rich-text fields can be marked Translatable. Record forms then keep one source value plus values for additional languages. Editors can add or remove language variants and use AI translation when their permissions and the Workspace AI policy allow it.
  • Archiving a definition removes it from active forms without rewriting the native schema. Fields managed by an external source are labeled and keep their external ownership metadata.

Dashboards

  • Open Workspace Settings -> Dashboards to assign shared dashboard layouts to members.
  • Create or share the layout from the main Dashboard first. Shared layouts appear even when inactive; assigning one or setting it as default activates it.
  • Apply a shared layout to all active account-backed members, members with selected roles, or selected individual members. Members without accounts are not listed because a dashboard is an account-owned app preference. The page shows each listed member's current dashboard and saved personal dashboards, and you can assign a shared layout directly from a member row.
  • Set default makes a shared layout the Workspace fallback for members without another active dashboard.
  • Delete personal dashboards removes personal layouts for the targeted members after assigning the shared layout. Users with Workspace settings management access can also remove an individual member's saved dashboard from the member table.
  • The dashboard management view works in batches of up to 250 active account-backed members.

Roles

  • Open Workspace Settings -> Roles to review Workspace roles and create custom roles for invitations and member assignments.
  • The protected Admin role is seeded by the system and cannot be edited or deleted.
  • Custom roles can start empty or copy the grants from an existing role. Copying a role copies its current permission grants.
  • The role detail view groups active grants by resource and action. All grants allow the action broadly; conditional grants are evaluated per record by the stored predicate.
  • Conditional predicates offer actor values that match the selected field type. Account-reference fields can compare with Current user; Workspace-member fields can compare with Current member or members in groups the actor leads; group fields can compare with groups the actor leads or belongs to.
  • Conditional access is edited as one or more rule sets. Multiple rule sets are ORed by the authorization layer, and advanced admins can edit the raw filter AST JSON for a rule set; the backend validates it again before saving.
  • Role-management actions follow the roles permission: read controls access to the page, and create, update, or delete control the matching changes. Permission resources follow the Workspace's enabled features, with roles and workspace always available.
  • When Tasks is enabled, the automations resource exposes separate actions for viewing rules, editing drafts, publishing, turning rules on or off, previewing, managing runs, archiving, and transferring ownership.
  • The shared automation builder requires the Automations feature and unrestricted Automations read access in addition to the matching automations action. Publishing also checks the owner's unrestricted read access to the source collection and the permission required by the action, such as deleting source records or creating Tasks. These permissions are checked again when the action executes.
  • The salary permission currently exposes read access only. It controls salary-cost charts on group detail pages.
  • Conditional user and role grants can also restrict target roles to the member's own role, roles below their own role, or an explicit role list.
  • Clear permissions removes every stored grant from an unprotected custom role after confirmation, which is useful before rebuilding a role from scratch.
  • Custom roles can be renamed or described. Deleting a custom role also removes its grants, but deletion is blocked while the role is assigned to any member.

Subscription

  • Open Workspace Settings -> Subscription to review the Workspace's current subscription data.
  • The page shows the subscription status, billing status, monthly price, next renewal, tax status, collected tax ID when available, and the currently enabled feature keys.
  • The effective feature list includes dependencies. For example, enabling CMS also enables Files because CMS media fields store uploads there.
  • If a new monthly price is already scheduled, the page also shows the pending amount for the next billing cycle.
  • Complete billing setup opens Stripe Checkout for paid Workspaces that already have a price but no active Stripe subscription yet.
  • Manage subscription opens the live Stripe customer portal for Workspaces that already have a Stripe customer.
  • The page also includes recent Stripe subscription invoices, which you can open directly from the invoice list.
  • Admins can see an in-app billing banner when checkout still needs to be completed or Stripe reports a payment issue.

Accounting

  • Open Workspace Settings -> Accounting when invoicing is enabled and you need to configure bookkeeping handoff defaults.
  • Save Workspace-wide export settings such as provider, BMD client number, account chart, bookkeeper recipients, default revenue and expense accounts, document inclusion, export locking, and tax-code mappings per source type and VAT rate.
  • The account chart controls which seeded accounts and category mappings are used. Austrian Workspaces default to the Austria EKR chart unless another chart is configured.
  • The partner-number table lets you maintain customer and vendor numbers, VAT IDs, tax numbers, default accounts, cost centers, payment terms, and export status per organization.
  • Accounting learning rules show the account choices Einblick has learned from bills, financial entries, and bank transactions. Admins can change the mapped account or archive an outdated rule.
  • Connected Stripe accounts can sync balance transactions and payouts into the journal. These postings use the chart's Stripe clearing account, payment-processor-fee account, bank account, and default revenue account.
  • Run the handoff workflow in Accounting Exports. That page previews a monthly period, shows blocking issues and warnings, generates immutable export snapshots, creates BMD ZIP packages, stores the manifest, and records Mark sent handoffs.
  • Preview and settings support multiple providers, but ZIP package generation is currently wired only for BMD.

Billing

  • Open Workspace Settings -> Billing when invoicing is enabled and you need Workspace-wide billing defaults.
  • Maintain wages, member employments, the default invoice PDF template, invoice PDF title/top/bottom/reverse-charge defaults, email signatures, and payment reminder settings.
  • Maintain invoice email body templates separately for English, German, and Czech. The send dialog starts with the template for the sender's current interface language and uses the localized default when that template is empty.
  • Payment reminders have three ordered levels. Each level can define its timing, late fee, new due-date offset, message template, attachment default, BCC, notification, and whether Einblick sends it automatically.
  • Wages define hourly rate, currency, billing category, revenue account, validity dates, and notes. They are used for work-time billing, invoice positions, and salary-cost snapshots. A wage with closed payroll records is read-only; duplicate it for future rate, category, account, or validity changes.
  • Creating, updating, duplicating, or archiving a billing wage is recorded in Workspace activity and links back to Billing settings.
  • Employments can also be managed from member detail pages. Each employment requires an active issuer organization and a period, and can include working-time, vacation, and compensation settings. An employment used by a closed timesheet or locked work time is read-only; end it and create a new employment for future changes.
  • Reusable product records are managed in Products, not in Billing settings.
  • Invoice PDF defaults support placeholder tokens for client, invoice number, dates, amounts, issuer, project, and service description. The reverse-charge text appears only on reverse-charge invoices; when its Workspace default is empty, the PDF uses the built-in text in the invoice language. New invoices use the other defaults unless the invoice provides its own PDF text.

API

  • Open Workspace Settings -> API when the Workspace has the API feature enabled.
  • Access follows the api role permission. read controls viewing keys and external sites, use allows short-lived credentials for interactive API reference requests, and create, update, or delete control the matching changes.
  • Create API keys for CMS collections, supported native endpoints, standard resource writes, and public commands.
  • Limit readable fields per endpoint, add server-side filters, configure writable fields separately, and grant only the resource write actions or commands external consumers should be allowed to call.
  • The page also includes install commands for the official @einblick/sdk and links to the per-key schema and OpenAPI documents. The interactive API reference uses a signed-in, short-lived credential without revealing the permanent key; write-capable keys require confirmation before requests are enabled.
  • External Sites on the same page let you register live origins and copy the publishable site key for in-page editing.
  • See Einblick SDK In-Page Editing for framework support and cache invalidation guidance.

Newsletters

  • Open Workspace Settings -> Newsletters when the Workspace has the Newsletters feature enabled.
  • Review the current monthly recipient usage for Einblick-hosted sending, including sent, reserved, failed, blocked, remaining, and limit values.
  • Choose whether public API newsletter signups subscribe immediately or require email confirmation before the address can receive campaigns.
  • The page shows whether active SMTP or Google Workspace senders are available. Manage those accounts, verified sending domains, DNS verification, and domain sender identities in Workspace -> Email.
  • Maintain audience groups in Contact Groups. Campaign audiences can target individual contacts, contact groups, users, user groups, and organizations.

Jobs

  • Open Workspace Settings -> Jobs to configure Workspace-wide recruiting defaults.
  • Set the default locale for new openings and optionally limit the supported locales available for job content.
  • Decide whether public applications require email confirmation before they count as submitted.
  • Add the privacy-policy URL used on the public application form.
  • See Jobs for the internal review flow and public job pages.

Events

  • Open Workspace Settings → Events to configure event types, slot and admission contracts, public booking defaults, and reservation email delivery. Managing this catalog requires unrestricted Workspace-settings management access.
  • Start each event type from a reusable template. The template fixes the stored event and slot form layout; the type adds its stable key, visible name, description, relations, presentation source, reservation default, and custom-slot policy. Unavailable templates explain which required Workspace feature is missing.
  • New types start as drafts. Activate a type to offer it for new events, or retire it to remove it from the picker without detaching existing events. A type with no events can be deleted.
  • Slot roles give programme entries a stable key and visible label. The separate category contract assigns those roles to every type built from that base category.
  • Each base category can have one working draft and one active contract. Rules set minimum and maximum role counts, which slots are created by default, publication-time start and end requirements, admission mode, capacity scope, booking policy, public visibility, and whether custom slots are allowed.
  • Saving a contract draft does not change event creation. Activating it retires the previous active version; newly created events record the new version, while existing events keep the contract version already stored on them.
  • Public booking defaults control whether visitors must enter a phone number, whether they see a notes field, and which privacy-policy link appears below the reservation button.
  • Reservation confirmation, waitlist, and email-verification templates can be customized per available language. Edit the subject and formatted body, and insert {{name}}, {{eventTitle}}, {{eventDateTime}}, {{tenantName}}, or {{confirmationUrl}} from the variable picker. Load default copies the localized default into the editor; Reset to default removes a saved override.
  • See Events for how types affect creation, the event form, programme, and public presentation.

Calendar

  • Open Workspace Settings → Calendar to manage official public holidays. They are enabled by default.
  • Use the Workspace country or override it, then choose nationwide coverage or an exact supported subdivision. Einblick does not broaden a selected local region to neighboring regions.
  • The page shows OpenHolidays as the data provider and reports sync status. Holidays appear read-only in Calendar, Work Schedule, and timesheets and do not change expected hours or balances. For work schedules and timesheets, a member's employment holiday region overrides the Workspace subdivision.

Appearance

  • Set default theme (light or dark) for all users.
  • Configure organization branding and visual identity.
  • Customize default interface elements and styling.
  • Control how the system looks for all users by default.

Security

  • Open Workspace Settings -> Security to manage Workspace-wide security policy.
  • Workspace admins can require MFA for active Workspace members with accounts. Users without 2FA are shown the setup screen before they can continue into the Workspace; members without accounts are unaffected because they cannot sign in.
  • MFA is account-level: once a user enrolls, the same enrollment protects every Workspace they belong to.
  • Users cannot disable 2FA while any Workspace or system-admin policy still requires it.
  • Protected system-admin access also requires account-level MFA in addition to the configured system-admin email allowlist.

Notifications

  • Configure default notification preferences for the organization.
  • Set up notification templates and messaging defaults.
  • Manage Workspace-wide notification channels and delivery methods.
  • Control which events trigger notifications by default.
  • Workspace notification defaults apply to Workspace-scoped events. Account-wide events such as chat messages, incoming calls, daily digest, sign-in alerts, and Workspace invitations are controlled in personal notification settings.

Display

  • Set the Workspace-wide date and duration formats.
  • Open Workspace Settings -> Work Times to configure confirmation policy, project allocation, group/location tagging, overlap handling, work scheduling, long-work thresholds, pause rules, timesheet PDF columns, close deadlines, PDF email delivery, and automatic email body templates.
  • Each Work Times settings card saves and validates only its own fields. Discard restores that card, while saving it preserves unsaved edits on every other card.
  • The confirmation policy controls whether saved work times are approved immediately or require leader/admin confirmation, employee confirmation, or both. Manager-side confirmation also exposes pending confirmations and absence approval actions for supervised people.
  • The overlap setting controls whether one member can save work-time entries that overlap another non-archived entry in the same Workspace.
  • Enable Work Schedule to let users with work-time create access plan future entries in the day, week, or month grid. Their role target rules decide which active members and groups appear.
  • Long-work and pause rules can either warn or block saving. The pause rule defaults to 30 minutes after more than 6 worked hours when enabled.
  • Monthly timesheets appear when the Workspace has the timesheets feature. Closing a month locks approved work times and absences and generates PDF timesheets.
  • Timesheet close deadlines can be off, set to the end of the period month, or set to a custom day and time in the following month. The deadline can only mark the period overdue or also notify responsible people, depending on the selected behavior.
  • Timesheet PDF delivery can be off, immediate on close, or collected into a monthly batch. Choose the exact active identity from a verified sending domain, Google Workspace, or SMTP, or use the managed Einblick fallback; the fallback requires a usable Reply-To address. Recipients can include the employee, the employee's group leaders, and additional fixed email addresses. Employees without accounts use their Workspace contact email and are skipped when none is set.
  • Generated timesheet PDFs can optionally show Category and Activity columns. Custom email bodies can be maintained separately for English, German, and Czech; an empty language uses its localized default, and the default email signature is appended.
  • Monthly batch sending can stay manual, run automatically when all required sheets are closed, or run automatically after the close deadline only if the period is complete.

Absence reasons

  • Open Workspace Settings -> Absence Reasons to manage the Workspace's absence catalog. Catalog management requires unrestricted update access for absences.
  • Create custom reasons or seed the DACH starter set for common leave types.
  • Each reason can define whether it is paid, needs approval, requires a medical certificate, defaults to whole-day or multi-day, counts as working time, and affects vacation balance.

Naming conventions

  • Configure how entities are named throughout the system.
  • Set up naming patterns for projects, tasks, work orders, etc.
  • Customize terminology to match your organization's language.
  • Control how items are identified and displayed.

Best practices

  • Review Workspace settings regularly to ensure they align with organizational needs.
  • Document any custom configurations for future administrators.
  • Test changes in a non-production environment when possible.
  • Communicate significant changes to users before implementing them.
  • Keep security settings up to date with current best practices.
  • Use naming conventions that are consistent and clear for all users.