Sign in

Invalid credentials
Byte Brew HR/ Dashboard
Super Admin
Platform Dashboard
Real-time overview across all tenants and services
Tenant Status
Module Adoption
Billing
Invoice generation and payment tracking
Batch Invoice Run
Runs invoices due today in PNG time (GMT+10) based on each tenant's registration billing date. Existing invoices are skipped.
Loading PNG date…
Billing day per tenant = day of month they registered (capped at 28 for short-month safety). Tenants registered on the 31st bill on the 28th of months without 31 days.
Individual Invoice
Generate a single invoice for one tenant.
All Invoices
MonthTenantAmountPaymentStatusDue
Loading…
Tenant Users
All registered users across tenant accounts
UserTenantRoleStatusRegisteredLast LoginActions
Loading users…
Tenants
Manage organisations on the Byte Brew HR platform
OrganisationPlanStatusEmployeesModulesCreatedActions
Tenant Metrics
Usage statistics and performance across all tenants
Module Management
Select a module to configure
Activity Log
Platform-level changes and events
User Management
Assign Firebase custom claims — controls Firestore access per your security rules
Super Admin
{ role: "super_admin" }
Read + write all /tenants documents. Full platform access. Only grant to platform admins.
Tenant User
{ tenantId: "NRA" }
Read own /tenants/{tenantId}. Read + write own /employees. Scoped to one tenant only.
Assign super admin claim
After setting claims, the user must call getIdToken(true) or sign out and back in for the new token to take effect.
Assign tenant user claim
Roles: Admin — full tenant access & all employees. Manager — view and manage self + direct reports. Employee — own profile and self-service requests only. Custom — module-scoped permissions defined in the tenant's custom role.
Change user role
Use this to update the role for an existing tenant user without changing their tenant assignment. For custom roles, the custom role ID must already exist on the tenant. The user must sign out and back in for the new token to take effect.
How Firestore rules use these claims
Path
Super admin
Tenant user (role)
/tenants/{tenantId}
Read + Write
Read — admin / manager / employee
/tenants/{tenantId}/employees
Read + Write
admin: all · manager: self+reports · employee: self only
/tenants/{tenantId}/accessRules/{moduleId}
Read + Write
Read (own tenant)
/tenants/{tenantId}/customRoles/{roleId}
Read + Write
Read (tenant) · Write (admin role only)
/tenants/{tenantId}/messaging/config
Read + Write
Read (tenant) · Write (admin role only)
/config/messagingService
Read + Write
✕ No access
Any path — unauthenticated
✕ Denied
✕ Denied
Account Settings
Tenant account configuration and domain management
Platform Identity
Authentication
Multi-factor Authentication
Require MFA for all admin accounts
SSO / SAML 2.0
Allow enterprise tenants to use their own identity provider
Session Timeout (inactive)
Auto-sign out after 60 minutes of inactivity
Domain Change Requests
Tenants may request to update their email domain. Review and approve or reject pending requests below.
Loading domain requests…
Notifications
New Tenant Notifications
Email alert when a new tenant is provisioned
Suspend/Reactivate Alerts
Alert on tenant status changes
Domain Change Alerts
Alert when a tenant submits a domain change request
Usage Threshold Alerts
Alert when a tenant exceeds 80% of their limit
Backend
Province GeoJSON
Upload the PNG province boundary GeoJSON used by the HR app's workforce map. The file must be a GeoJSON FeatureCollection where every feature includes an adm1_name property.
Loading current status…
Platform Controls
Module access, quotas, security rules and platform-wide defaults
Module management has moved to the Modules page — platform gates, tenant access, feature toggles, schema config and module definitions are all in one place.
Default Modules for New Tenants
Modules pre-enabled when a new tenant is provisioned
Tenant User Types
Control which organisation types are permitted to register on this platform.
Quota changes apply immediately. Saving plan limits syncs all tenants on that plan. Tenants over the new limit are flagged but not suspended automatically.
Plan Configuration
Full plan settings including enabled modules and messaging limits.
Security & Access
Blocklist
Support Tickets
Track and respond to issues raised by tenants
🎫
Navigate to this page to load tickets
Messages
Message channel access controls, limits, and delivery metrics
Email Channel
SMTP / transactional email delivery
tenants/{id}/messaging/config → emailChannel
SMS Channel
Twilio / SMS gateway delivery
tenants/{id}/messaging/config → smsChannel
WhatsApp Channel
WhatsApp Business API
tenants/{id}/messaging/config → whatsappChannel
Global Behaviour
All sent messages are permanently logged for audit
Prevents burst sending exceeding hourly thresholds
Only admins can send messages to employee groups
/config/messagingService
Per-Tenant Channel Overrides
Loading tenant overrides...
Channel Breakdown this month
Top Tenants by Volume
Storage
Firebase Storage access controls, quotas, and usage metrics
Global Storage Limits
Combined storage across all tenants
Access Rules
Unauthenticated download requests are denied
Tenants can only access their own tenants/{id}/ path
Files under /confidential/ require admin claim
Employees can write their own avatar file only
Security Rule Reference
Path
Super Admin
Tenant User (role)
tenants/{tenantId}/**
Read + Write + Delete
Read/Write own tenant only
tenants/{id}/documents/**
Read + Write + Delete
admin: all · manager: dept · employee: self
tenants/{id}/confidential/**
Read + Write + Delete
admin role only
tenants/{id}/avatars/**
Read + Write + Delete
Read all · Write own only
Any path — unauthenticated
× Denied
× Denied
Per-Tenant Storage Quotas
Loading tenant quotas...
Firebase Storage Buckets
Bucket configurations and access policies
png-hr.firebasestorage.app
Default bucket · Multi-region · Standard storage
Primary
Tenant isolation
✓ Enforced
Auth required
✓ Enabled
CORS policy
Configured
Public access
Blocked
Storage by Tenant
Storage by File Type
PS Reference Library
Platform-wide PNG Public Service reference items shown in all tenant portals
#TitleCategoryTypeURL / ContentStatusActions
Loading…
AI Knowledge Base
Global documents fed into every tenant's AI assistant alongside their own private knowledge base
How it works: Documents added here are automatically included in the AI assistant context for all tenants. Tenants can still upload their own private documents — both sets are merged when answering queries. Ideal for platform-wide policies, employment law, general orders, or compliance frameworks.
TitleCategoryTypeContent PreviewUpdatedActions
Loading…