Platform settings and operators
For the people who run a SourceLace server: SourceLace's own cloud, or your organization's self-hosted install. Most server settings (sign-in apps, connector apps, the AI key, Stripe, email, switches) are set by a Super Admin on the Platform settings page in the app, without access to the hosting dashboard. Only four bootstrap settings stay with the host.
Who can do what
Three roles run a SourceLace server. Each can do everything the ones below it can.
- Super Admin: everything, including Platform settings, adding and removing operators, and deleting organizations. At least one Super Admin always exists.
- Operator: organizations, pricing, licenses, features, renaming and exporting organizations. Not secrets, not operators, not deleting organizations.
- Support: read-only views of organizations, plans, billing and the template library, without secrets.
The people listed in SOURCELACE_ALLOWED_EMAILS on the server are always Super Admins: it is the bootstrap and emergency list, and only the host can change it. A Super Admin adds everyone else under Platform settings, Operators, by email and role. Removing an operator takes effect at their next click: they are signed out, unless your own organization's email domain still lets them in as an ordinary member. Every change is in your audit log.
Organizations
Operators manage each organization on the Organizations page (under Operator in the menu; the page is headed "Organizations and plans"). Its Organizations tab lists every organization; click one to open its own page, with its plan and price, discounts, connectors, status, trial, admins, contact, contract and single sign-on, and to change them. Everything here can also be done from an AI app with the admin_customers tool. Every change is recorded in your audit log and, under your name, in the organization's own audit log; contact details are recorded as "changed", never their values.
Finding an organization
The list shows 50 organizations a page, with each one's plan, status, seats and yearly value. With thousands of organizations, find one instead of scrolling:
- Search looks in the name, the organization ID, the admins' and the contact's email addresses and the email domains. Every word you type must match.
- Plan and Status (active, trial, paused, deleted) narrow the list. Trial ends within 7 days shows the trials to extend or convert soon; Payment problem shows organizations with a failed payment or an overdue invoice.
- Sort by name, plan, seats, AI use this month or yearly value (after discounts). Click a column's heading to sort by it, and again to reverse the order.
Searching, filtering and sorting run on the server, across every organization. The seats, AI use and value in the list are at most a minute old; Refresh works them out again. An organization's own page always shows the latest.
The other long lists on this page work the same way, 50 at a time with a search box:
- Features: search organizations by name or ID, and Show only those with any feature set, or with one feature set. After you change a switch, that row updates in place.
- Organization status: search by name, organization or license ID, contact or plan, and show hosted or self-hosted ones only.
- Stripe billing: search by organization ID or Stripe customer ID, and show those paying by card or by invoice. The yearly totals always cover every organization.
In an AI app, the admin_customers tool's list takes the same search, plan and status, and returns at most 50 organizations unless you ask for a different limit (up to 200); offset gives the next ones.
Price book versions
The Price book tab keeps every version of the price book. All versions shows, for each, the day it started (From), the day the next version took over (Until), who saved it and its note. The version in effect today says now and one that starts later says scheduled. A version saved for a month that already had one replaces it (replaced).
View opens a version's whole price book, read-only: plan prices and limits, connector add-ons, AI credits, trial terms and the full JSON. Compare with current highlights every value that differs from the version in effect today, with both values side by side. Past versions are never changed: to change prices, save a new version from this month or a later one.
Trials
A trial lets a new organization try SourceLace free, without a card. Start one when you add the organization (Start as a trial) or later with Start a trial, and choose the plan it is a trial of. A trial has that plan's features, narrowed by the trial terms in the price book: by default 14 days, 5 people, 2 sources, AI in the app up to $50 in all (then it stops; their own AI apps keep working), no changes to records, and 1 agent.
- Extend the trial adds days, counted from its end (or from today once it has ended).
- Convert to a paid plan ends the trial and puts the organization on the plan you choose, with its full limits. Nothing is lost.
- When a trial ends unconverted, the organization is paused, not deleted: sign-in tells their people the trial ended. Extending or converting lets them back in at once. Their chats are deleted 30 days after the trial ended (the trial terms set how long); everything else is kept until you delete the organization.
The trial terms are part of the price book (Trial terms), so changing them is a new price book version, like a price change; trials already running keep their end date.
Pausing and resuming
Pause stops everyone at the organization from signing in, and their AI apps stop working at the next request. Nothing is deleted. Give a reason (such as "unpaid invoice 1042"); it is recorded in both audit logs. Sign-in tells their people that the organization is paused and to ask their SourceLace contact. Resume lets everyone back in. An organization paused because its trial ended comes back by extending or converting the trial instead.
Renaming and exporting
Rename changes the name people see; the organization ID never changes. Export downloads the organization's settings and audit log as a JSON file: its plan, discounts and limits, people and roles, sources (without passwords, secrets or keys), groups, single sign-on (without its secret) and audit entries. It never contains data from their sources, sign-ins to them, or AI keys. Any Operator can rename and export.
Deleting an organization
Only Super Admins can delete an organization. Give a reason. Nobody at the organization can sign in from that moment, and 7 days later SourceLace removes everything it stores for them: people, sources and sign-ins, chats, agents, plan and billing records, audit log and encryption key. Until then, Undo delete puts the organization back as it was (active or paused). After the 7 days it cannot be undone; your own audit log keeps a record of the delete and the removal. Export the organization first if you need its settings or audit log.
Admins, contact and contract
- Admins: add admins by email, or replace them (the admins you leave out become members). An address that already uses SourceLace with another organization cannot be added. New admins take a seat.
- Admin contact: the full name, email and phone of the person to talk to about the account. Only operators see it, and it does not let them sign in.
- Contract: the contract's start and end dates and notes, for renewals. Nothing is switched off on the end date, and prices stay in the price book and the organization's discounts.
Set on the server
These stay in the server's environment variables, set wherever the server is hosted, because the server needs them before it can read anything else:
DATABASE_URL: where everything is stored, platform settings included.SOURCELACE_ENCRYPTION_KEY: the master key that encrypts what is stored, so it is never stored in the database itself.SOURCELACE_PUBLIC_URL: the server's address (andSOURCELACE_APP_URLif the app has its own address). Set it, unless your hosting platform provides the address itself.SOURCELACE_ALLOWED_EMAILS: the first Super Admins.
A few technical ones also stay there when you use them: SOURCELACE_ENV, SOURCELACE_MODE, SOURCELACE_REDIS_URL, SOURCELACE_LICENSE (self-hosted) and PORT.
A brand-new server also needs a way for those first Super Admins to sign in: set the Google sign-in client ID and secret (or the Microsoft ones) in the environment once, to start. After that you can move them into the app like the other settings.
The Set on the server only table at the bottom of Platform settings lists these, with the value each has now and where it comes from: an environment variable (with its name), the hosting platform itself for the address, or the built-in default. The database and Redis addresses are shown without their user name and password, and the master key and the license only as "hidden".
Precedence: the server wins
Every platform setting can still be set in the environment, with its SOURCELACE_ name. If it is, that value wins: the page shows it as Locked on the server, with the value hidden if it is a secret. If it is not set there, the app's value applies; if neither is set, the default does.
Secrets saved in the app are encrypted with the master key. No page or API ever shows them again: only whether each is set, by whom and when.
Import from environment
To move settings off the hosting dashboard: open Platform settings and choose Import from environment. The button only appears when there is something to copy, and shows how many settings that is. SourceLace copies every platform setting that is set in the environment into the app at once, without asking you to confirm. They keep coming from the environment until you delete them there; then the app's values take over. Check the page shows Copy saved in the app next to each before you delete anything.
What needs a restart
Most changes apply within seconds, on every server, with no restart. These are read only while the server starts, so a change waits for the next restart or deploy (the page marks them Takes effect after a restart):
- Google and Microsoft sign-in (client IDs, secrets and the Microsoft accounts setting), because turning sign-in on or off changes who may run the server.
- Retry declined replies (the AI client is set up at start).
- Run AI agents on this server (the scheduler starts with the server).
- Rows kept per result, how long results are kept, and how long a previewed change can be applied.
If values saved in the app would stop the server starting (such as a sign-in client ID without its secret), SourceLace refuses to save them, and at start it leaves them out rather than not starting.
Sign-in
The Google and Microsoft apps people sign in with, and the email domains of your own organization.
Connector apps
SourceLace's own app registration at each vendor (Salesforce, HubSpot, Google Workspace, Atlassian, NetSuite, Gong, Slack and others), plus SourceLace's own AWS identity for assuming organizations' Amazon S3 roles (never used to read buckets directly) and the SAP sandbox key. People still sign in to each source with their own account. A connector switches on as soon as both its client ID and secret are saved. The Test button lists which connector apps are complete.
AI
The AI key for the AI included in the plans. Test asks the provider whether it accepts the key. Organizations can still add their own key in their Settings.
Billing (Stripe)
The Stripe secret key and the webhook signing secret. Test asks Stripe whether it accepts the key and says whether it is in test or live mode. Billing switches to the new key at once.
How SourceLace sends email, such as alerts: none (the default), SMTP (any mail server, such as Google Workspace with an app password) or Postmark. Send test email sends a message to you. Sending alerts comes in a later update; for now the settings are kept and tested.
Switches
Whether this server runs AI agents, whether database sources may be on private network addresses, and whether Preview features are on for every organization.
Preview features on for every organization
On by default. While it is on, every Preview feature is on for every organization, in production too. Turn this off before your first real customer; then Preview features are off unless you turn them on for an organization (Organizations page, Features tab). Either way, an On or Off you set for one organization on the Features tab wins, so you can still turn one feature off for one organization. The change applies at once and is recorded in your audit trail. The Features tab says which way the server is set. The staging server always has Preview features on.
Tuning
How many rows a query shows at first, and how long results and previewed changes are kept. Business limits such as sign-in lengths, query timeouts, parallel agent runs and the default plan are not here: they are on the Limits page, per plan and per organization.