Browse documentation

Platform administration

Current release · Updated October 3, 2026

Separate staff sign-in, workspace provisioning and account access controls.

Sign in separately

Open app.drykraft.com/sa with an explicitly created platform account. Workspace owners and administrators do not receive platform access. New platform accounts must add DryKraft platform to their own authenticator and enter a six-digit code before entering the console. Keep the ten recovery codes private; each works once. Use existing authenticator or recovery proof for later sign-in. Platform sessions end after 15 minutes without a successful platform request and expire after four hours.

Platform owner manages staff accounts and global settings. Owner/administrator manages workspace and customer account access; support can inspect management directories, while billing can inspect saved subscriptions. Read-only accounts cannot change state. Role/status changes end affected staff sessions. At least one active platform owner is retained.

Inspect and control customer access

Use Workspaces or Users, search by name/email/address, then open the detail page. Directories show safe identity, membership and saved subscription information. Business records, passwords and provider credentials are excluded. A workspace suspension pauses shared access and background billing checks while retaining stored data. A customer account disable ends that person’s sessions across workspaces, retaining memberships and account credentials. Restoration requires a fresh customer sign-in and still follows membership/subscription permissions.

Each status change needs a saved version, meaningful reason and confirmation. If another administrator changed the item, reload and review its saved status. Immutable audit records the change. Read platform audit separately from the customer workspace audit trail.

Provision and invite an owner

Choose Workspaces - Create workspace. Enter the company name, unoccupied address, owner email, default/enabled currencies, named timezone and provisioning reason. Creation atomically initializes standard objects, a sales pipeline, dashboard and seven-day owner invitation. The 15-day trial starts at workspace creation. It creates no customer user or membership until acceptance.

Copy the private invitation link from the result and share it with the named recipient; this operation does not send an email. Existing recipients sign in with their own password and authenticator when enabled. New recipients create their account during acceptance. Expired/revoked links or an issuer whose authority changed cannot grant ownership. Replaying an accepted invitation cannot recreate membership that was removed. Identical provisioning retries reuse the saved workspace; keep the request ID and inputs unchanged. The setup page keeps its request ID in the address, so the original staff account can reload to recover a saved result after a timeout.

Commercial administration API

Platform owners, administrators and billing staff can create and publish versioned plans through the platform API, then assign a specific immutable version to a workspace. Publishing a new version does not change existing assignments. Workspace price metadata is USD 1 per user per month and USD 12 per user per year; this catalog does not create a Dodo product or collect payment. The monthly/annual checkout API and customer selector are deployed. Successful payment and paid renewal acceptance remain pending. Enterprise versions have negotiated prices rather than an invented amount.

The current live-resource ceilings cover workspace memberships, unmerged People contacts, custom records outside the seven built-in objects, pipelines, all workflows, active workflows, enabled calendars and integrations. Integration counts include saved workflow credentials and enabled outreach/calendar connections and customer webhooks. Null means no ceiling at that level; zero prevents growth. Downstream overrides may only reduce the plan. Concurrent creation checks the same workspace lock; a lower ceiling retains existing records and prevents further growth. Pausing or disabling a resource can free its active allowance.

The API can extend a trial to a later date within the next 90 days, or record an enterprise agreement with a reference, start/end dates and seat allowance. A current agreement can grant workspace access; expiry or insufficient seats removes that agreement grant. It does not fabricate a paid provider subscription. Plan, agreement and trial changes require a current version and reason and publish immutable audit and lifecycle events. Commercial console forms are deployed after bounded browser acceptance and a fresh finish review. Plans opens immutable versions, Workspaces opens saved plan/limits, and administrative changes require a reason and review. Consumed usage, credit settlement, successful payment and paid renewal acceptance, coupons, add-ons and reseller inheritance remain unfinished.

Settings, subscriptions and scope

Platform settings can open/close new account registration and configure the public support email and maintenance notice. Only platform owners save these versioned settings. Subscriptions shows saved provider status, purchased seats, trial/renewal dates and sync time; viewing or suspending an account does not charge or refund money.

This chapter describes the implemented console foundation and customer management. The console foundation is deployed at app.drykraft.com/sa after bounded commercial acceptance, restricted-access checks and backup restoration checks. Each new staff account must complete its own authenticator setup before entering. Consumed meters/credits, reseller controls, domain branding, reusable snapshots, approved support access and transactional email remain separate unfinished release scope. Those unfinished features are not available in the deployed foundation.