System / Operations
Open Settings → System with an active Administrator role in your current workspace. System information describes the whole application. Company and access administration describe a workspace. Switching to a workspace where you are not Administrator removes System access; the backend enforces the same restriction.
Health meanings
Section titled “Health meanings”HEALTHY means the check succeeded. WARNING means an operator should review the information. ERROR means a check failed. NOT CONFIGURED means optional integration metadata has not been supplied. Colors always have text labels.
Liveness means the backend process responds. Readiness requires a reachable database and current migrations; production also requires safe security/URL configuration. Pending migrations must be applied by the deployment operator, never through Settings. Database errors show safe status only. During a database outage session authorization may also fail: the page shows a generic unavailable message; use the public minimal readiness probe and contact the operator.
The page shows build/version, environment, security configuration booleans and operator-reported backup status. It does not show secret values or configured hostnames/paths. Frontend and Help are not remotely probed: configured URLs alone do not prove those services are available. Refresh status retrieves a new projection. Missing build metadata is reported as unavailable, never invented.
Backup status
Section titled “Backup status”payIQ reads a small metadata file supplied by the production backup process; it does not run backups. NOT CONFIGURED is not evidence of a backup. A successful backup older than the configured threshold (24 hours by default) shows WARNING. A failed latest attempt or unreadable/malformed metadata shows ERROR. A recent successful timestamp does not prove recoverability. Restore verification is reported separately and may be unreported. Contact the deployment operator to review encrypted off-host copies, retention and disposable restore evidence. Optional backup metadata cannot block application readiness.
Safe diagnostics and troubleshooting
Section titled “Safe diagnostics and troubleshooting”Download safe diagnostics JSON gathers only the operational projection and timestamp. No payroll/employee records, session values, logs, environment dump, passwords, keys, filesystem paths or backup contents are included. Access is Administrator-only and responses cannot be cached. Treat deployment information as internal when sharing it with support.
For pending migrations, ask the deployment operator to run migrations once. For unreachable database, check approved database/container operations outside payIQ. For security warnings, review HTTPS proxy, secure cookies, HSTS, explicit hosts, public URLs and additional trusted origins. An empty additional trusted-origin list is valid for a same-origin deployment. DEBUG cannot be enabled with production settings. Missing Help configuration requires matching backend URL configuration and frontend/Help rebuild settings. Raw error messages are not shown.
Administrator recovery
Section titled “Administrator recovery”The application protects the last active Administrator from supported removal,
demotion and deactivation. First access is provisioned through the host-side
bootstrap_workspace_admin management command, with prompted passwords and a
retained workspace UUID. There is no anonymous bootstrap page.
When no active Administrator remains, an authorized deployment operator can use
the command’s explicit --recover mode with the exact existing active workspace
UUID and name, a new account, and typed UUID confirmation. It refuses recovery
if an active Administrator remains and never escalates an existing user. Password
input is prompted twice without echo. --default selects that workspace; the new
membership is recorded in existing access history. This is not an existing-user
password reset or archived-company recovery facility.
Deployment operators should follow the repository’s
docs/deployment/production-runbook.md and docs/deployment/backup-restore.md.
payIQ provides no shell, deployment, migration execution, backup or restore controls.