Workspace, team access & security
Role-based access with custom roles, MFA enforcement and step-up checks, a full audit log, brand identity, multi-property, domains and billing.
Updated 2 August 2026
What it is
The control room of your workspace: who can see and do what, how strongly sign-in is protected, what changed and who changed it — plus your brand identity, your properties, your domains and your subscription billing.
What problem it solves
"Who can see payroll?" and "who changed that price?" are questions most systems can't answer. In a venue where casual staff, managers and owners all touch the same system, access needs to be deliberate and every significant change needs a record.
How it works
-
Roles define access. Ship-ready system roles cover the common jobs and can be switched on or off; custom roles are built by ticking permissions grouped into plain domains — menu and kitchen, orders and service, finance, people, marketing, insights, admin. Duplicate a role to start from something close. To invite a person into one of these roles, see Inviting your team & staff logins.
-
Security sets multi-factor authentication enforcement — optional, required for admins, or required for everyone — and sensitive actions like saving integration credentials demand a fresh step-up re-authentication regardless.
-
The audit log records every state-changing action in the workspace: who, what, when, severity and the before-and-after state — filterable by actor, action, target and date, and exportable to CSV for an investigation.
-
Brand identity sets your colours, logo and typography once, and both your admin and your public site wear them.
-
Properties manage multi-venue groups — each location with its own details, contacts and hours. Domains verifies your custom web domain by DNS record, and the separate sending domain verifies the address your emails come from, so campaigns and confirmations send as you, not as a platform.
-
Billing shows your current plan, invoices from Stripe with payment links and PDF downloads, and recent usage. Communications holds each user's notification preferences.
Everything inside the system
- Role-based access control with system and custom roles, permission domains, duplication and archiving.
- MFA enforcement levels and step-up re-authentication for sensitive actions.
- Complete audit log with filters, severity and CSV export.
- Brand identity across admin and public surfaces.
- Multi-property management, custom-domain verification and a verified sending domain.
- Subscription billing with invoices and usage, and notification preferences.
This is built into NexDine — access, security and audit are platform features, not add-ons. Subscription invoices are issued through Stripe, and everything is managed from inside NexDine.