Module
Settings
The workspace layer — organisations and properties, who may do what and where, an audit log covering machines as well as people, step-up on the actions that matter, and an import that previews before it commits.
Settings answers the four questions a buyer with an incumbent system asks before any others: can I get my data in, who can do what, can I prove what happened, and how is a privileged action protected. An organisation holds properties; a property switches modules on and off; a person holds roles at a scope; and every action lands in one log.
An organisation, its properties, and what each one runs
Properties live under an organisation and each carries its own timezone, currency and formatting locale — how that property writes dates and numbers, independently of the language each person reads. Modules are switched on per property, and one that is off is not in that property's navigation at all.

Roles granted at a scope
Owner is reserved and can only be cloned; the default roles — Accountant, Front Desk, Manager, Read-only, Storekeeper — can be cloned, edited or deleted. A person's assignments are pills naming the role and the scope it applies to, org-wide or one named property. There is no such thing here as a role granted in the abstract.


One log for people, API keys and agents
Every row records the time, the actor, the channel it came through — app, API or MCP — the action, its target and the outcome. A module being switched off and an agent's tool call are the same kind of record, which is the only way one log can answer a question about either.

Step-up on the actions that deserve it
Refunds, folio adjustments, POS discounts and voids, waived ancillaries and card reveals each carry an amount threshold and a toggle. Re-authentication can be demanded always, or only above a value you choose, and the challenge names the action and the amount it is confirming.

An import that shows you what it will do first
A template workbook comes down, filled in it goes back up, and Nerve validates every cell and previews exactly what it will create or update before anything is committed. Every sheet is optional, so a property can bring what it has rather than everything at once.

The permissions an agent works within are these permissions — an API key is granted scopes from the same list a role grants a person, and a module a property has not enabled is not callable there either. Step-up applies to the operation rather than the screen, so a refund an agent attempts asks for the same re-authentication a receptionist's would.
Go deeper
Every screen above is documented, operation by operation, against the shipped product.
Wondering whether this is for a property your size?
← All features