Admin guide
Everything in this guide lives under Settings and is visible to administrators only (team leaders see the Guide and their team's approvals).
Roles and access
| Role | Can |
|---|---|
| Administrator | Everything: people, invitations, approvals, section access, billing, data, integrations |
| Team leader | Manage their own team, invite people, approve their team's leave and working-hours requests, propose extra access (an administrator approves) |
| Team member | Use the shared sections plus any sections granted to them |
- Shared areas (Settings → Access) are the sections every member gets.
- Per-person access is the Section access checklist on a person's card in the Directory, or on the invite.
- Access requests raised in the app queue under Settings → Access.
- Server-side enforcement: the API only returns the records a person's section access allows (
NOVUHUB_ENFORCE_DATA_ACCESS=1, the default). - Offboarding: the Offboarding panel on a person's Directory card walks through hand-over, access removal and the leaving date; accounts provisioned through SCIM are deactivated by the identity provider. Data stays for audit and erasure flows.
Modules
Settings → General → Modules switches whole sections on or off for the workspace (tasks, mind maps, portfolios, workflows, calendar, workload, risk radar, CRM, people, team, finance, bills, reports, sustainability, SOPs, learning, messages, activity). Hidden modules keep their data.
Workflow & fields
- Task statuses and deal stages are editable lists with colours; one status is the completion status used by reports and the Gantt.
- Custom fields (text, number, select) are extra fields shown on every task and included in exports.
- Working hours and the workspace time zone drive workload, the calendar and reminders. People can override the time zone for themselves.
Notifications
Choose which events send in-app notifications and emails (assignments, mentions, approvals, due-soon reminders, weekly recap). Email needs SMTP or a transactional provider configured on the server (see Installation & upgrades). Web-push subscriptions are stored when VAPID keys are configured.
Integrations
- Connection tokens for the Claude/MCP connector and the REST API — the workspace owner generates them; the secret is shown once and stored hashed.
- Mailbox — IMAP details for the shared inbox that feeds My Emails and the supplier-invoice reader.
- AI — the provider key used for invoice extraction and drafting.
- Report branding — company name, logo, colours and legal footer used on every exported PDF and e-invoice.
- Video — the meeting link template used by calendar events.
- Webhooks are managed through the API (
/api/v1/webhooks), see API & integrations.
Subscribers (platform owner only)
If your email is on the NOVUHUB_ANALYSIS_OWNER_EMAILS allow-list, Settings gains a Subscribers tab: monthly recurring revenue, annual run rate, paying customers, trials, billed seats, average revenue per customer, a per-plan breakdown and every workspace with its plan, status, seats, value and renewal date. Prices come from the plan configuration (NOVUHUB_PLANS); a workspace's value is its plan price × billed seats. The tab does not exist for any other workspace and the endpoint behind it refuses anyone else. No card or bank data is involved — that stays with the merchant of record.
Billing
Seats are counted from active members. When billing is enabled on the server the Billing tab shows the plan, seat count, trial or grace period and a Manage subscription button that opens the merchant-of-record's hosted checkout. NovuHub never sees card or bank details; the provider sends signed webhooks that update the subscription state.
Data & privacy
- Export the whole workspace as JSON (and every person's own data on request) — Settings → Data.
- Import a JSON export, or reset to the sample data set.
- GDPR tools: per-person data export, erasure (anonymises the person's records and removes their account), a PII-access log, consent versions and retention settings — Settings → Data & Privacy.
- Legal pages: Impressum, privacy policy and cookie notice are generated from the company details set on the server.
Security
- Two-factor authentication (TOTP with backup codes) is enabled per account under Settings → Security; the operator can disable it server-wide with
NOVUHUB_2FA_ENABLED=0. - Sessions last 14 days; Remember me 30 days (both configurable).
- Login throttling, CSRF protection, strict security headers and a Content Security Policy are always on. See Security.
Single sign-on and provisioning
OpenID Connect sign-in and SCIM provisioning are configured on the server by the operator; once enabled the login page shows the SSO button and your identity provider creates, updates and deactivates accounts automatically. See Single sign-on & provisioning.
Public pages your customers may see
| Page | Purpose |
|---|---|
/help/<token> | Public help centre built from your knowledge base, with a feedback form |
| Lead form | Public form that creates CRM contacts |
| Booking page | Public appointment booking into the calendar |
/status | Live service status |
/changelog, /developers | Release notes and API reference |