Workspace controls
Permissions, approvals, and reset controls
Do not confuse convenience with authorization. Sensitive actions need explicit roles, approval gates, and durable audit evidence.
Workspace members
Demo roles illustrate least-privilege access.
DO
Demo Owner
owner@demo.invalid
DS
Demo Sales User
sales@demo.invalid
DF
Demo Finance User
finance@demo.invalid
Sensitive-action approvals
Disable only when a documented control replaces the approval gate.
Campaign launch
Owner/admin must approve the live launch.
Budget increase
Require evidence and owner approval before spend rises.
First outbound sequence
Review tone, consent, and unsubscribe handling.
Invoice creation
Confirm approved scope and deterministic totals.
Finance export
Finance or owner approval required before export.
Secrets and API keys
Never expose provider secrets in client-side environment variables.
Workspace data connectiondemo sandbox
Server credentialsserver only
Payment configurationcheck integrations
Lead-source configurationcheck integrations
Service-role, Stripe secret, and provider access tokens must never use a NEXT_PUBLIC_ prefix.
Reset demo workspace
Restore the bundled campaigns, leads, deals, quotes, invoices, and finance records.