Docs

Workspace Settings

Configure Workspace-wide settings, including event types, accounting exports, dashboards, roles, security, notifications, API access, and organizational defaults.

administrationsystemconfiguration

Workspace Settings

Workspace Settings allow administrators to configure Workspace-wide preferences, review subscription status, and manage security policies, appearance defaults, and system behavior. In the sidebar they appear under Settings -> Workspace. These settings affect all users in your Workspace and should be managed carefully.

Settings pages that use cards keep a separate draft for each card. Save or discard the card you changed; saving one card leaves unsaved changes on the other cards untouched.

General settings

  • Set the Workspace name shown in navigation and Workspace selectors. Renaming the Workspace also updates the Workspace's cloud root folder name.
  • Set the unique Workspace handle used by the managed fallback sender address. It must be 3–48 characters, start and end with a letter or number, and otherwise use lowercase letters, numbers, and hyphens. Einblick previews the normalized value and checks availability before saving. A change applies to future mail; already-sent messages keep their original From address and replies still follow Reply-To.
  • Set the default country and currency used by Workspace workflows.
  • Set the default content language used as the source language for new editorial content. This is independent of each user's interface language; when left empty, Einblick derives it from the Workspace country.
  • Set the default invite role preselected when admins invite a new Workspace member.

Sharing

  • Open Workspace Settings → Sharing to manage how other Workspaces find and connect to yours. The page is available with Workspace sharing and shows only the sections allowed by the current role.
  • List in Workspace directory lets other Workspaces find yours by name when sharing records or connecting Chat channels. Turning it off removes name-based discovery; an eligible reviewer can still receive a channel invitation sent directly to a verified email address.
  • Review pending and active records shared with your Workspace, records shared by your Workspace, and incoming or active channel connections. Item-share actions follow the Shares permissions; reviewing channel connections requires unrestricted Chat review access.
  • An accepted channel connection gives the other Workspace permission-based access to the channel. Public channels can then be discovered and joined there, while private channels still require explicit members. See Chats for the full connection workflow.

Inventory

  • Open Workspace Settings → Inventory to configure material stock behavior. The page is available when Materials is enabled and you have material read access plus Workspace-settings management access.
  • Allow negative material balance is enabled by default. When disabled, Einblick rejects any outbound booking that would push material stock below zero — including completing a production run. Production reservations remain informational warnings in either mode.

Data model and custom fields

  • Open Workspace Settings → Data Model to manage custom fields for buildings, events, event slots, and festivals when those features are enabled.
  • Custom fields can be short text, long text, rich text, number, boolean, date, or select fields. Configure their stable slug, label, description, required state, group, and display order; a field's slug and type cannot be changed after creation.
  • Short text, long text, and rich-text fields can be marked Translatable. Record forms then keep one source value plus values for additional languages. Editors can add or remove language variants and use AI translation when their permissions and the Workspace AI policy allow it.
  • Archiving a definition removes it from active forms without rewriting the native schema. Fields managed by an external source are labeled and keep their external ownership metadata.

Dashboards

  • Open Workspace Settings -> Dashboards to manage shared layouts, a separate default for each role, and the Workspace-wide fallback.
  • The page shows role coverage, the source of each role's default, and how many widgets that role can see. You can create an editable shared layout directly from a role's automatically generated widget set.
  • For a member without a pinned choice, Einblick tries the role default, then the Workspace default, then generates a layout from role, permissions, and enabled features. A default with no visible widgets is skipped, and later role, feature, or default changes apply automatically.
  • Pin a shared layout to all active account-backed members, selected roles, or selected members, or reset them to automatic resolution. Members without accounts are not listed because they have no dashboard.
  • The member table shows each current source and personal layouts. Administrators can remove an individual personal dashboard when cleaning up old choices.
  • The dashboard management view works in batches of up to 250 active account-backed members.

Roles

  • Open Workspace Settings -> Roles to review Workspace roles and create custom roles for invitations and member assignments.
  • The protected Admin role is seeded by the system and cannot be edited or deleted.
  • Custom roles can start empty or copy the grants from an existing role. Copying a role copies its current permission grants.
  • The role detail view groups active grants by resource and action. All grants allow the action broadly; conditional grants are evaluated per record by the stored predicate.
  • Conditional predicates offer actor values that match the selected field type. Account-reference fields can compare with Current user; Workspace-member fields can compare with Current member or members in groups the actor leads; group fields can compare with groups the actor leads or belongs to.
  • Conditional access is edited as one or more rule sets. Multiple rule sets are ORed by the authorization layer, and advanced admins can edit the raw filter AST JSON for a rule set; the backend validates it again before saving.
  • Role-management actions follow the roles permission: read controls access to the page, and create, update, or delete control the matching changes. Most permission resources follow the Workspace's enabled features. Roles, Workspace, Admission, Ticket Fulfillment, Ticket Refunds, and Ticket Seating remain available regardless of feature selection.
  • When Tasks is enabled, the automations resource exposes separate actions for viewing rules, editing drafts, publishing, turning rules on or off, previewing, managing runs, archiving, and transferring ownership.
  • The shared automation builder requires the Automations feature and unrestricted Automations read access in addition to the matching automations action. Publishing also checks the owner's unrestricted read access to the source collection and the permission required by the action, such as deleting source records or creating Tasks. These permissions are checked again when the action executes.
  • The salary permission currently exposes read access only. It controls salary-cost charts on group detail pages.
  • Conditional user and role grants can also restrict target roles to the member's own role, roles below their own role, or an explicit role list.
  • Clear permissions removes every stored grant from an unprotected custom role after confirmation, which is useful before rebuilding a role from scratch.
  • Custom roles can be renamed or described. Deleting a custom role also removes its grants, but deletion is blocked while the role is assigned to any member.

Subscription

  • Open Workspace Settings -> Subscription to review the Workspace's current subscription data.
  • The page shows the subscription status, billing status, monthly price, next renewal, tax status, collected tax ID when available, and the currently enabled feature keys.
  • The effective feature list includes dependencies. For example, enabling CMS also enables Files because CMS media fields store uploads there.
  • If a new monthly price is already scheduled, the page also shows the pending amount for the next billing cycle.
  • Complete billing setup opens Stripe Checkout for paid Workspaces that already have a price but no active Stripe subscription yet.
  • Manage subscription opens the live Stripe customer portal for Workspaces that already have a Stripe customer.
  • The page also includes recent Stripe subscription invoices, which you can open directly from the invoice list.
  • Admins can see an in-app billing banner when checkout still needs to be completed or Stripe reports a payment issue.

Usage

  • Open Workspace Settings -> Usage to compare current use with the plan allowances for active account-backed members, storage, AI credits, managed newsletter recipients, and paid tickets sold.
  • Each card shows the used and included amount, its ongoing, calendar-month, or contract-year period, warning state, and what happens above the allowance. Depending on the plan, Einblick only counts usage, warns, blocks additional use, or permits priced overage up to an optional cap. Member seats block above their allowance; storage continues with a warning.
  • Storage and AI sections break usage down by area, feature, and responsible member where available. Test-mode ticket usage is shown separately and is never billed.
  • Additional charges lists overage by month, meter, quantity, unit price, net amount, and status. Overage is billed monthly in arrears and appears as separate lines on the next Einblick invoice; invoiced entries link to the invoice list under Subscription.

Accounting

  • Open Workspace Settings -> Accounting when invoicing is enabled and you need to configure bookkeeping handoff defaults.
  • Save Workspace-wide export settings such as provider, BMD client number, account chart, bookkeeper recipients, default revenue and expense accounts, document inclusion, export locking, and tax-code mappings per source type and VAT rate.
  • The account chart controls which seeded accounts and category mappings are used. Austrian Workspaces default to the Austria EKR chart unless another chart is configured.
  • The partner-number table lets you maintain customer and vendor numbers, VAT IDs, tax numbers, default accounts, cost centers, payment terms, and export status per organization.
  • Accounting learning rules show the account choices Einblick has learned from bills, financial entries, and bank transactions. Admins can change the mapped account or archive an outdated rule.
  • Connected Stripe accounts can sync balance transactions and payouts into the journal. These postings use the chart's Stripe clearing account, payment-processor-fee account, bank account, and default revenue account.
  • Run the handoff workflow in Accounting Exports. That page previews a monthly period, shows blocking issues and warnings, generates immutable export snapshots, creates BMD ZIP packages, stores the manifest, and records Mark sent handoffs.
  • Preview and settings support multiple providers, but ZIP package generation is currently wired only for BMD.

Billing

  • Open Workspace Settings -> Billing when invoicing is enabled and you need Workspace-wide billing defaults.
  • Choose or clear the default billing wage used as the final fallback for work-time billing.
  • Maintain wages, member employments, the default invoice PDF template, invoice PDF title/top/bottom/reverse-charge defaults, email signatures, and payment reminder settings.
  • Maintain invoice email body templates separately for English, German, and Czech. The send dialog starts with the template for the sender's current interface language and uses the localized default when that template is empty.
  • Payment reminders have three ordered levels. Each level can define its timing, late fee, new due-date offset, message template, attachment default, BCC, notification, and whether Einblick sends it automatically.
  • Wages define hourly rate, currency, billing category, revenue account, validity dates, and notes. They are used for work-time billing, invoice positions, and salary-cost snapshots. A wage with closed payroll records is read-only; duplicate it for future rate, category, account, or validity changes.
  • Creating, updating, duplicating, or archiving a billing wage is recorded in Workspace activity and links back to Billing settings.
  • Employments can also be managed from member detail pages. Each employment requires an active issuer organization and a period, and can include working-time, vacation, and compensation settings. An employment used by a closed timesheet or locked work time is read-only; end it and create a new employment for future changes.
  • Reusable product records are managed in Products, not in Billing settings.
  • Invoice PDF defaults support placeholder tokens for client, invoice number, dates, amounts, issuer, project, and service description. The reverse-charge text appears only on reverse-charge invoices; when its Workspace default is empty, the PDF uses the built-in text in the invoice language. New invoices use the other defaults unless the invoice provides its own PDF text.

API

  • Open Workspace Settings -> API when the Workspace has the API feature enabled.
  • Access follows the api role permission. read controls viewing keys and external sites, use allows short-lived credentials for interactive API reference requests, and create, update, or delete control the matching changes.
  • Create API keys for CMS collections, supported native endpoints, standard resource writes, and public commands.
  • Limit readable fields per endpoint, add server-side filters, configure writable fields separately, and grant only the resource write actions or commands external consumers should be allowed to call.
  • The page also includes install commands for the official @einblick/sdk and links to the per-key schema and OpenAPI documents. The interactive API reference uses a signed-in, short-lived credential without revealing the permanent key; write-capable keys require confirmation before requests are enabled.
  • External Sites on the same page let you register live origins and copy the publishable site key for in-page editing.
  • See Einblick SDK In-Page Editing for framework support and cache invalidation guidance.

Newsletters

  • Open Workspace Settings -> Newsletters when the Workspace has the Newsletters feature enabled.
  • Create optional subscription lists for preferences such as Festival or Band news. Maintain their recipient-facing name and description, review subscriber counts, or archive them without removing memberships. Each list gets a generated slug. Campaigns without a list use global newsletter opt-in; campaigns with one require both global opt-in and membership in that list.
  • Choose whether public API newsletter signups subscribe immediately or require email confirmation before the address can receive campaigns.
  • The page shows whether active SMTP or Google Workspace senders are available. Manage those accounts, verified sending domains, DNS verification, and domain sender identities in Workspace -> Email.
  • Maintain audience groups in Contact Groups. These select the people to consider and remain separate from subscription lists, which record newsletter preferences. Campaign audiences can target individual contacts, contact groups, users, user groups, and organizations.
  • Review recipient allowances, enforcement, and additional charges under Workspace Settings -> Usage.

Jobs

  • Open Workspace Settings -> Jobs to configure Workspace-wide recruiting defaults.
  • Set the default locale for new openings and optionally limit the supported locales available for job content.
  • Decide whether public applications require email confirmation before they count as submitted.
  • Add the privacy-policy URL used on the public application form.
  • See Jobs for the internal review flow and public job pages.

Events

  • Open Workspace Settings → Events to manage the event catalog, public booking defaults, and reservation email delivery. Managing the catalog requires unrestricted Workspace-settings management access.
  • Creating a type is a guided flow. Start blank or from a neutral starter, then set the name and permanent key, relation requirements, scheduling mode, and field placement. A starter is copied into the new type and can be changed; it does not remain a shared source of behavior. Options that depend on an unavailable Workspace feature are disabled with an explanation.
  • Relations to buildings, artists, festivals, festival days, and addresses can be hidden, optional, or required before publication.
  • Choose title and image sources independently from the event, building, or artist. A building or artist used as a source becomes required before publication. Each inherited value can either allow an event-specific override or stay strict; strict fields are hidden from the event form.
  • The address can belong to the event or come strictly from its building. Building-sourced addresses make the building required, hide the event-address relation and form fields, and do not allow an event-specific override.
  • Scheduling supports one slot, fixed named slots, or free-form slots. Fixed slots are defined in the same editor and can reuse an existing role, be required or repeatable, stay internal, set admission behavior, and optionally allow additional slots. Each named role chooses a time range with start and end or a point in time with one time, such as last entry. A slot rule can also require staffing, seed the required headcount, and override the type's volunteer signup policy.
  • Configure admission for the whole event separately from each slot role. Whole-event registration or ticketing works without making a slot bookable; slot admission can offer registration, tickets, both, or no booking for each public programme role.
  • Enable Volunteers gives events of the type a dedicated staffing area and assignment controls. Choose one whole-event volunteer pool or separate assignments per staffed slot, then set organizer-managed, open, or approval-based signup as the default. The Volunteers needed field can still be placed or hidden separately for whole-event staffing.
  • Fields can be shown, placed under More details, or hidden. The editor groups General, Registration, Tickets, and Volunteers fields and only offers each booking group when the type's whole-event or slot admission uses it. Hiding a previously available field checks how many events contain data, asks for explicit confirmation, then clears that value from every event of the type and records the action. For types with more than 500 events, the preview checks the first 500 and marks its counts as lower bounds.
  • New types are active immediately. Retiring a type removes it from new-event selection while existing events remain linked; only an unused type can be deleted. Type and slot-role changes are recorded in Workspace activity.
  • Editing also exposes waitlist order and whether calendar moves require confirmation. Existing events use the current type configuration, while slot rules already used by existing slots cannot be removed.
  • Public booking defaults control whether visitors must enter a phone number, whether they see a notes field, and which privacy-policy link appears below the reservation button.
  • Reservation confirmation, waitlist, email-verification, event-invitation, accepted-pass, guest-ticket, and partner-portal templates can be customized per available language. Event templates share name, event, date, and Workspace variables; guest tickets add {{reference}}, {{partnerName}}, and {{qrImage}}. Partner portal mail has allocation, budget, and portal-link variables. Place {{ctaButton}} where a supported template's action button should appear; if it is omitted, Einblick appends the button automatically. Load default copies the localized default into the editor; Reset to default removes a saved override.
  • Pass after accepting controls what an invited guest receives after accepting. By default, Einblick sends a separate email containing the QR pass and attaches a one-page PDF. The email can be disabled, and its PDF can be turned off while email remains enabled. Attach PDF to guest tickets separately controls the printable PDF sent with guest-list and partner tickets. Generated QR images and PDFs are kept in the protected Event passes system folder in Files.
  • Show cover image is enabled by default and uses the event's effective cover as a wide header in the invitation email, accepted-pass email, guest-ticket email, and RSVP page. Events without a cover stay text-only.
  • Reservation and invitation emails use a shared Workspace-branded layout. It shows an eligible Workspace logo or falls back to the Workspace name, and follows the Workspace setting for the einblick logo in the footer.
  • See Events for how types affect creation, the event form, programme, and public presentation.

Calendar

  • Open Workspace Settings → Calendar to manage official public holidays. They are enabled by default.
  • Use the Workspace country or override it, then choose nationwide coverage or an exact supported subdivision. Einblick does not broaden a selected local region to neighboring regions.
  • The page shows OpenHolidays as the data provider and reports sync status. Holidays appear read-only in Calendar, Work Schedule, and timesheets and do not change expected hours or balances. For work schedules and timesheets, a member's employment holiday region overrides the Workspace subdivision.

Appearance

  • Open Workspace Settings → Appearance to set the default theme and brand color. Members can still override the theme in their personal settings.
  • Maintain an Icon and Full logo separately. The Icon is a compact 1:1 mark for Workspace switchers and avatars; the Full logo is a horizontal wordmark for headers. Each shape has Light, Dark, and Color slots: Light means white artwork for dark backgrounds, while Dark means black or dark artwork for light backgrounds. Transparent files are recommended.
  • Every slot accepts a manual upload. When the Dark slot contains an SVG, Generate versions can create selected Light, Dark, and Color variants for that shape. Multicolor artwork is flattened for the monochrome variants; the Color version can keep the original artwork or use one tint.
  • Changing the brand color does not silently recolor an existing logo. Einblick marks a generated Color variant made from the previous brand color so you can review and regenerate it.
  • The Documents, Email, and Public pages cards independently choose no logo, the Icon, or the Full logo, plus Color with monochrome fallback or monochrome only. Documents and email can also show a name beside the mark. When no suitable mark is available, the name is shown instead. The default is the Full logo, Color with fallback, and no additional name.
  • The Documents card controls invoice and offer headers. An issuer organization's logo takes priority, with Workspace artwork as the fallback. Timesheet PDFs independently use the Full Workspace logo suited to their light page.
  • Public event and job pages use the public-page mark matched to the visitor's light or dark theme. A form shows that mark only when Show Workspace logo is enabled on the form. The hosted ticket shop always uses the Full logo matched to the current theme.
  • Email is rendered on a light background and uses an email-safe raster version of the selected mark. The Hide einblick branding switch removes the einblick logo from public pages and Workspace emails; a form can also hide it in its own settings.

Security

  • Open Workspace Settings -> Security to manage Workspace-wide security policy.
  • Workspace admins can require MFA for active Workspace members with accounts. Users without 2FA are shown the setup screen before they can continue into the Workspace; members without accounts are unaffected because they cannot sign in.
  • MFA is account-level: once a user enrolls, the same enrollment protects every Workspace they belong to.
  • Users cannot disable 2FA while any Workspace or system-admin policy still requires it.
  • Protected system-admin access also requires account-level MFA in addition to the configured system-admin email allowlist.

Notifications

  • Configure default notification preferences for the organization.
  • Set up notification templates and messaging defaults.
  • Manage Workspace-wide notification channels and delivery methods.
  • Control which events trigger notifications by default.
  • Workspace notification defaults apply to Workspace-scoped events. Account-wide events such as chat messages, incoming calls, daily digest, sign-in alerts, and Workspace invitations are controlled in personal notification settings.

Display

  • Set the Workspace-wide date and duration formats.
  • Open Workspace Settings -> Work Times to configure confirmation policy, project allocation, group/location tagging, overlap handling, work scheduling, long-work thresholds, pause rules, timesheet PDF columns, close deadlines, PDF email delivery, and automatic email body templates.
  • Each Work Times settings card saves and validates only its own fields. Discard restores that card, while saving it preserves unsaved edits on every other card.
  • The confirmation policy controls whether saved work times are approved immediately or require leader/admin confirmation, employee confirmation, or both. Manager-side confirmation also exposes pending confirmations and absence approval actions for supervised people.
  • The overlap setting controls whether one member can save work-time entries that overlap another non-archived entry in the same Workspace.
  • Enable Work Schedule to let users with work-time create access plan future entries in the day, week, or month grid. Their role target rules decide which active members and groups appear.
  • Long-work and pause rules can either warn or block saving. The pause rule defaults to 30 minutes after more than 6 worked hours when enabled.
  • Monthly timesheets appear when the Workspace has the timesheets feature. Closing a month locks approved work times and absences and generates PDF timesheets.
  • Timesheet close deadlines can be off, set to the end of the period month, or set to a custom day and time in the following month. The deadline can only mark the period overdue or also notify responsible people, depending on the selected behavior.
  • Timesheet PDF delivery can be off, immediate on close, or collected into a monthly batch. Choose the exact active identity from a verified sending domain, Google Workspace, or SMTP, or use the managed Einblick fallback; the fallback requires a usable Reply-To address. Recipients can include the employee, the employee's group leaders, and additional fixed email addresses. Employees without accounts use their Workspace contact email and are skipped when none is set.
  • Generated timesheet PDFs can optionally show Category and Activity columns. Custom email bodies can be maintained separately for English, German, and Czech; an empty language uses its localized default, and the default email signature is appended.
  • Monthly batch sending can stay manual, run automatically when all required sheets are closed, or run automatically after the close deadline only if the period is complete.

Absence reasons

  • Open Workspace Settings -> Absence Reasons to manage the Workspace's absence catalog. Catalog management requires unrestricted update access for absences.
  • Create custom reasons or seed the DACH starter set for common leave types.
  • Each reason can define whether it is paid, needs approval, requires a medical certificate, defaults to whole-day or multi-day, counts as working time, and affects vacation balance.

Naming conventions

  • Configure how entities are named throughout the system.
  • Set up naming patterns for projects, tasks, work orders, etc.
  • Customize terminology to match your organization's language.
  • Control how items are identified and displayed.

Best practices

  • Review Workspace settings regularly to ensure they align with organizational needs.
  • Document any custom configurations for future administrators.
  • Test changes in a non-production environment when possible.
  • Communicate significant changes to users before implementing them.
  • Keep security settings up to date with current best practices.
  • Use naming conventions that are consistent and clear for all users.