Module

Settings

The workspace layer — organisations and properties, who may do what and where, an audit log covering machines as well as people, step-up on the actions that matter, and an import that previews before it commits.

Register Waitlist →Read the docs →

What it is

Settings answers the four questions a buyer with an incumbent system asks before any others: can I get my data in, who can do what, can I prove what happened, and how is a privileged action protected. An organisation holds properties; a property switches modules on and off; a person holds roles at a scope; and every action lands in one log.

01

An organisation, its properties, and what each one runs

Properties live under an organisation and each carries its own timezone, currency and formatting locale — how that property writes dates and numbers, independently of the language each person reads. Modules are switched on per property, and one that is off is not in that property's navigation at all.

The Properties screen in Nerve's Settings. The active property expands into an app-enablement grid with a labelled on/off toggle per app, one of them switched off; a second property below offers a “Switch to” action.
One organisation, many properties, each with its own apps switched on.
02

Roles granted at a scope

Owner is reserved and can only be cloned; the default roles — Accountant, Front Desk, Manager, Read-only, Storekeeper — can be cloned, edited or deleted. A person's assignments are pills naming the role and the scope it applies to, org-wide or one named property. There is no such thing here as a role granted in the abstract.

The People list in Nerve's Settings. Each person is a card with their name, email and their role assignments as removable pills, each naming the role and the scope it applies to — org-wide, or one named property.
A role is always granted at a scope, never in the abstract.
The Roles screen in Nerve's Settings. Owner is marked “Reserved · full admin” and can only be cloned; the default roles below it — Accountant, Front Desk, Manager, Read-only, Storekeeper — can each be cloned, edited or deleted.
Start from a default role, clone it, and change what you need.
03

One log for people, API keys and agents

Every row records the time, the actor, the channel it came through — app, API or MCP — the action, its target and the outcome. A module being switched off and an agent's tool call are the same kind of record, which is the only way one log can answer a question about either.

The Audit Log in Nerve. Each row records when something happened, the actor, the channel it came through — app, api or mcp — the action, its target, and the outcome pilled ok, denied or error.
A configuration change and an agent's API call sit in the same log.
04

Step-up on the actions that deserve it

Refunds, folio adjustments, POS discounts and voids, waived ancillaries and card reveals each carry an amount threshold and a toggle. Re-authentication can be demanded always, or only above a value you choose, and the challenge names the action and the amount it is confirming.

The Step-Up Security screen in Nerve, listing the protected actions that can demand re-authentication — a folio refund, a folio adjustment, a POS discount or void, a waived ancillary, a card reveal — each with an amount threshold and an on/off toggle.
Re-authentication can be required always, or only above a value you set.
05

An import that shows you what it will do first

A template workbook comes down, filled in it goes back up, and Nerve validates every cell and previews exactly what it will create or update before anything is committed. Every sheet is optional, so a property can bring what it has rather than everything at once.

The Data Import screen in Nerve. A “Download template” button provides the onboarding workbook, and the upload panel explains that every cell is validated and previewed before anything is committed.
Nothing is committed before you have seen what the import will create.
What it means for an agent

The permissions an agent works within are these permissions — an API key is granted scopes from the same list a role grants a person, and a module a property has not enabled is not callable there either. Step-up applies to the operation rather than the screen, so a refund an agent attempts asks for the same re-authentication a receptionist's would.

Go deeper

Every screen above is documented, operation by operation, against the shipped product.

Register Waitlist →Start from your property type →

Wondering whether this is for a property your size?

← All features