Admin Guide

    Complete guide to administering Nino360

    Administrator Overview

    As a Nino360 administrator, you have comprehensive control over your organization's platform configuration, user management, security settings, and system monitoring. This guide covers all administrative functions.

    User Management
    Add, remove, and manage user accounts
    Security
    Configure authentication and permissions
    Monitoring
    Track system health and usage

    Tenant Management

    Creating a New Tenant

    1. Navigate to Admin → Tenants
    2. Click "Create Tenant" button
    3. Enter tenant details:
      • Company name
      • Workspace slug (e.g., "acme" for acme.nino360.com)
      • Industry and company size
      • Primary administrator email
    4. Configure initial settings (locale, currency, timezone)
    5. Assign subscription plan
    6. Click "Create" to provision the tenant
    ⚠️ Important

    Workspace slugs cannot be changed after creation. Choose carefully as this becomes part of the tenant's URL.

    Managing Existing Tenants

    View Tenant Details: Click on tenant name to see full configuration
    Update Settings: Modify tenant information, branding, and preferences
    Suspend Tenant: Temporarily disable access (billing issues, violations)
    Delete Tenant: Permanently remove tenant and all data (requires confirmation)

    User Management

    Adding Users

    Users can be added through several methods:

    Individual Invitation
    1. Go to Settings → Users
    2. Click "Invite User"
    3. Enter email address
    4. Select role (Admin, Manager, Employee)
    5. Assign to specific departments/teams
    6. Send invitation
    Bulk Import
    1. Download CSV template from Settings → Users → Import
    2. Fill in user information (email, name, role, department)
    3. Upload completed CSV file
    4. Review and confirm import
    5. Invitation emails sent automatically
    SSO/SAML Integration

    Configure automatic user provisioning from your identity provider (Azure AD, Okta, Google Workspace). Users are created automatically on first login.

    Managing User Roles

    Tenant Admin
    Full access to all modules, can manage users and settings
    Permissions: All permissions including admin:all
    Manager
    Can view and manage team data, access most modules
    Permissions: Module read/write permissions, no admin access
    Employee
    Basic read access to relevant modules
    Permissions: Limited read permissions, no management capabilities
    💡 Custom Roles

    Create custom roles with specific permission sets in Settings → Roles & Permissions. Mix and match module access to fit your organization's structure.

    User Operations

    Deactivate User
    Suspend access without deleting account
    Reset Password
    Send password reset link to user
    Change Role
    Modify user permissions and access level
    Delete User
    Permanently remove user and data

    Security Settings

    Authentication Configuration

    Password Policy
    • • Minimum length: 8 characters (configurable)
    • • Require uppercase, lowercase, numbers, symbols
    • • Password expiration: 90 days (optional)
    • • Password history: Prevent reuse of last 5 passwords
    Multi-Factor Authentication (MFA)
    • • Enforce MFA for all users
    • • Supported methods: Email OTP, SMS, Authenticator App, Biometric
    • • Configure MFA exemptions for trusted IPs
    • • Backup codes for account recovery
    Session Management
    • • Session timeout: 8 hours (configurable)
    • • Concurrent session limit: 5 devices
    • • Force logout on password change
    • • IP address tracking and alerts

    SSO/SAML Configuration

    1. Go to Settings → Security → SSO
    2. Select identity provider (Azure AD, Okta, Google Workspace)
    3. Enter provider metadata:
      • Entity ID
      • SSO URL
      • Certificate
    4. Configure attribute mapping (email, name, role)
    5. Enable Just-In-Time (JIT) provisioning
    6. Test SSO connection
    7. Enforce SSO for all users (optional)
    🔒 Security Best Practices
    • • Enable MFA for all administrator accounts
    • • Review audit logs weekly for suspicious activity
    • • Implement IP allowlisting for admin panel access
    • • Rotate API keys every 90 days
    • • Enable email notifications for security events

    System Monitoring

    Health Dashboard

    Access real-time system health metrics from Admin → System Health:

    System Status
    All systems operational • 99.9% uptime
    API Response Time
    Average: 245ms • P95: 850ms
    Database Performance
    Query time: 95ms avg • 1,247 connections
    Active Users
    Current: 847 • Peak today: 1,203

    Audit Logging

    All administrative actions and security events are logged in the blockchain-backed audit trail:

    Logged Events Include:
    • User login/logout
    • Failed authentication attempts
    • User creation/deletion
    • Role changes
    • Permission modifications
    • Data exports
    • Configuration changes
    • API key usage
    Access audit logs at Admin → Audit Logs. Logs are immutable and verified via merkle tree hashing.

    Alerts & Notifications

    Configure automated alerts for important events:

    • Security Alerts: Failed login attempts, suspicious activity, MFA bypass attempts
    • System Alerts: High error rates, performance degradation, downtime
    • Usage Alerts: Storage limits reached, API rate limits exceeded
    • Billing Alerts: Payment failures, subscription changes

    Module Configuration

    Enable or disable specific modules based on your organization's needs:

    CRMEnabled
    HRMSEnabled
    Talent/ATSEnabled
    FinanceEnabled
    ProjectsDisabled
    VMSDisabled
    BenchDisabled
    TrainingEnabled
    Configure module settings at Settings → Modules. Disabling a module hides it from navigation and revokes all associated permissions.

    Data Management

    Backups

    • Automatic Backups: Daily full backups, retained for 30 days
    • Manual Backups: Create on-demand backups before major changes
    • Point-in-Time Recovery: Restore to any point within last 7 days
    • Export Options: Download tenant data in JSON, CSV, or SQL format

    Data Retention

    Configure data retention policies in Settings → Data Management:

    • • Audit logs: Retained indefinitely (compliance requirement)
    • • Deleted records: Soft-deleted for 30 days, then hard-deleted
    • • User data: Retained until account deletion
    • • File uploads: Retained per configured policy (default: 1 year)
    ⚠️ GDPR Compliance

    Users have the right to request data deletion. Process these requests within 30 days via Settings → Data Requests. All personally identifiable information will be permanently removed.

    Support & Troubleshooting

    Common Issues

    User cannot log in
    Check user status is "active", verify email is confirmed, reset password if needed
    SSO not working
    Verify SSO configuration, check certificate validity, test attribute mapping
    Performance issues
    Check system health dashboard, review slow query logs, contact support if persistent

    Get Help

    📧 Email Support
    admin-support@nino360.com
    📞 Priority Support
    24/7 phone support for Enterprise plans
    💬 Live Chat
    In-app chat (bottom right corner)
    📚 Admin Portal
    admin.nino360.com/docs