PLATMETRIX
Master · Platform Admin

Platform Admin Console

The master control surface for Platmetrix — managing every tool, account, paywall and access grant across the platform.

User Handbook
Section 01

Overview & who this is for

The Platform Admin Console is the master control surface for Platmetrix. From one place you manage every tool in the suite, every account, the paywalls that gate paid work, and the access each person holds. This handbook is written for the two roles that operate it.

RoleWhat they can doWhat they can't
Master adminEverything: all tools, create/delete any account, reset any password, flip any paywall, push site changes, and grant assignability to others.Nothing is withheld — this is the top of the tree.
Platform adminManage accounts, tools, access and invitations; run the Quote Builder; day-to-day operations.Destructive site-wide changes and granting assignability (reserved for master).

The delegated model in one idea

Below the two admins sits a hierarchy of account holders. The concept that makes it work is assignability — a right that lets certain account holders create and manage accounts beneath them without being full admins. A Regional Manager assigns Property Managers; a Property Manager assigns on-site staff; an Enterprise Owner assigns its own users. Master and Platform admins sit above all of it.

In the console

Accounts that can create sub-accounts show a green can assign tag next to their role. End users (staff, residents, individual clients) have no such tag — they consume access, they don't hand it out.

Rule that protects you

Only the Master admin can grant assignability. That keeps control of who can spawn accounts in one pair of hands, no matter how large the tree grows.

Section 02

The console at a glance

The console has four tabs across the top. The number on each tab is a live count.

TabWhat it holdsYou go here to…
ToolsThe full tool registry, grouped by product family.See every tool, its release status, access tier, and which roles can open it.
AccountsEvery account, filterable by role.Open a person's account & payment info, or jump into any tool they hold.
AccessA per-account grant board.Tick tools on or off for an account.
InvitationsAccounts invited but not yet active.Resend, activate, or revoke.

Two clicks that do the most work

Click a name

Opens the account drawer: contact details, reporting line, assignability, and the full payment information block — plan, deposit, invoice, balance, renewal and market tier. Reset password, impersonate and suspend live at the bottom.

Click a tool button

Opens that tool's admin panel for that account: how many sub-users are registered, who is active, invitations out, the account's own grant, and — for PropIQ — its client admin and licensed properties.

Section 03

Managing each tool

Tools live in four families. Every tool has a handle (e.g. PM·PROP), a release status, and an access tier that decides how it's granted.

Admin & Billing

ToolHandleWhat you manage
Admin ConsolePM·ADMINThe master surface itself — accounts, protected pages, the access matrix and payment tiers.
Quote BuilderPM·QUOTEBuild and price client proposals; it lives in the portal toolbar for admins.

Operations (the IQ apps)

ToolHandleWhat you manage
PropIQPM·PROPProperty operations — maintenance, prospects, leasing, banking, reconciliation. Granted per property (see Section 06).
AssetIQPM·ASSETPortfolio & asset performance — valuations, equity and returns rollup across properties.
LoanIQPM·LOANLoan & debt tracker — amortization, debt-service coverage, maturities and lender packages.
Resident PortalPM·RESIDResident-facing app — payments, requests and documents, scoped to a single unit.

Market Intelligence

ToolHandleWhat you manage
Market IntelligencePM·MKTIQSite scorecards, comps, Go/No-Go radar and underwriting. This is the paywalled report product — its live market is Dayton, OH. Access is set by tier, not a simple on/off (see Section 04).

Design Studio

ToolHandleWhat you manage
Unit StudioPM·UNITFloor-plan and 3D unit designer with casework elevation builder.
Facade StudioPM·FACADEFacade and massing studies in 3D. beta
Site PlannerPM·SITESite planning — earthwork, detention, parking yield and cost model.
Construction PhasingPM·PHASEStick-frame trade sequencing and phasing. beta
How granting works

Every tool except Market Intelligence is a straight grant — open an account, click the tool, use Manage access, or tick it on in the Access tab. Market Intelligence is granted by paywall tier instead, because a client can hold the market at study level or full level.

Owner vs granted

A tool shown as owner on an account (e.g. a Property Manager who owns PropIQ for their property) is locked as granted and can't be accidentally revoked. Everything else toggles freely.

Section 04

Paywalls & billing tiers

Market Intelligence is sold in stages. The paywall is a single field on the account — page_access.tier — and moving it is how you unlock work as money clears. There are no webhooks to wait on and no redeploys: you flip the tier, and the client's view changes on their next load.

TierStored valueWhat the client sees
No accessnoneThe market isn't on their account.
Awaiting depositgrantedA payment prompt only — the deposit link.
Deposit paid · studydepositThe desktop study unlocks.
Paid in fullfullThe full report — site pins, aerials, scorecards, comps, underwriting.

Flipping a tier

  1. Open the client's account (click their name).
  2. Read the Payment information block — deposit status, invoice number, balance.
  3. When the money clears (Stripe deposit or QuickBooks invoice), move the tier up one step.
  4. The client's viewer reflects it immediately — nothing to deploy.
Why it's manual by design

Payment confirmation is a human step on purpose. Money clears → you raise the tier → access opens. Because storage reads are tier-gated on the server, a client can't skip a stage by viewing source.

Billing, in the drawer

Enterprise accounts show the paid deposit and paid invoice; single-market clients show the open Stripe link and balance due; child accounts show billing rolling up to their parent. Stripe handles deposits; QuickBooks carries the invoice number.

What's sent when you flip a tier
Access granted
Your study is now unlocked
“Your payment is complete and your full market study is available.”

Flipping to full emails the client that their study is unlocked. Flipping to deposit instead sends the client a receipt and alerts the Director of Sales to follow up.

Section 05

Assigning user accounts & access

Accounts fall on one of two branches beneath the admins: the consulting / market-intelligence side (Enterprise Owners and their Clients) and the property-management side (Regional Managers, Property Managers, Staff, Residents).

RoleCan assign?Typical grant
Master adminYes — and grants assignabilityAll tools
Platform adminYesAdmin Console, Quote Builder, Design Studio
Sales adminNoQuote Builder — create & modify quotes
Enterprise ownerYes (its own users)Market Intelligence
Regional managerYes (managers & staff)AssetIQ, LoanIQ, PropIQ
Property managerYes (its own staff)PropIQ
Client / Staff / ResidentNoTheir one tool

Granting a tool

  1. Go to Accounts and filter to the role you want, or open the Access tab.
  2. Click the account, then Manage access — or tick the tool on directly in the Access board.
  3. For Market Intelligence, set the tier instead of a plain toggle.
  4. The grant is live at once — the account's tool button appears on their card.
Registered users & invitations, automatically

When you open a tool on an account, the registered users and invitations sent lists are built from that account's sub-accounts — you don't maintain them by hand. Invite a user under an Enterprise Owner and they appear here the moment the invite goes out.

What's sent when you grant a tool
Access granted
You now have access to a new tool
“You’ve been given access to a new tool in Platmetrix.”

Granting a tool emails the user that it’s available to them, scoped to the property and role you chose.

What's sent when you add a user
Account created
Welcome to Platmetrix
“An account has been created for you. Sign in and set your password to get started.”

Adding a user emails them a welcome with sign-in details; if you mark them an administrator, the note says so.

Section 06

PropIQ: client admins & properties

PropIQ is licensed differently from the other tools because it's bought per property, and the client runs their own staff inside it. Opening PropIQ on an account shows two sections you won't see on other tools.

Client admin

Each PropIQ account has one client admin — the person on the client side who assigns property staff and sets their access levels. For a Regional Manager that's usually themselves; for a single property it's the Property Manager. Use Change to reassign it.

Properties · PropIQ licensed

These are the specific properties the account purchased PropIQ for. Each row shows the property, unit count, address, its assigned client admin, staff count and status.

Reserved to you

Creating a new property and assigning its client-specific admin rights are Main / Platform admin actions (marked with that tag on the section). The client admin manages staff within a property; only you and platform admins spin up new properties and grant the property-level admin seat.

Adding a property

  1. Open the purchasing account → the PropIQ button.
  2. Under Properties, choose Create property and enter name, address and unit count.
  3. Use Assign admin on the new row to name its property-level client admin.
  4. That admin can now invite and manage staff for the property.
Section 07

Access levels & rights

Holding a tool is only the first layer. Inside each tool, every person has a set of rights — the specific actions they're allowed to take. These are the access levels you see and edit on each user in the account matrix (Operations → tool → company → property → expand a user).

Roles carry a default level

When a user is added, their role seeds a starting set of rights. The clearest example is the maintenance chain in PropIQ:

LevelCan do
Property managerEverything below, plus schedule, manage vendors and prospects, post charges, and manage staff & access.
Maintenance supervisorView calendar, view & create tickets, schedule work, assign tickets, close & route to property management, upload photos, manage vendors.
Maintenance techView calendar, view & create tickets, close & route to the supervisor, upload photos.
Leasing agentView calendar, view tickets, manage prospects.
AccountantView tickets, post charges.
Where you see it

Open a user in the account matrix and expand Access & permissions. Granted rights are filled in; the count (e.g. 5/12) shows how many of the tool's capabilities that person holds.

The full capability catalog

Rights are specific to the tool you're viewing.

PropIQ

View calendar, view tickets, create tickets, schedule work, assign tickets, close & route to supervisor, close & route to property management, upload photos, manage vendors, manage prospects, post charges, manage staff & access.

Resident Portal

Make payments, submit requests, attach request photos, view documents, view community news, post community news, review applications.

AssetIQ

View dashboards, edit valuations, view debt, export reports.

LoanIQ

View loans, edit amortization, run DSCR, manage lender packages.

How rights are assigned

  1. Seeded on creation. A new user's role applies its default rights automatically — a maintenance tech starts with the tech set, a supervisor with the supervisor set.
  2. Tuned per person. In the account matrix, expand the user and tap any capability to grant or revoke it. The change is immediate and the count updates.
  3. Owned by the Regional Property Manager. Editing these levels is a Regional PM (or admin) action. A tech can't widen their own rights; the RPM sets what each of their people can do.
Who can edit whom

A Regional Property Manager edits rights only for people within their own properties. Property staff see their rights read-only. Master and Platform admins can edit anywhere — the same subtree scoping that governs the rest of the hierarchy.

Behind the scenes

Rights are data, not code — which is why the RPM can change them live with no deploy. Here's the chain each time a capability is toggled.

  1. Where it's stored. Each grant row in project_access — keyed by user, property and tool — carries a capabilities array. The chips you see are that array.
  2. The toggle writes one row. Granting or revoking a capability upserts that single project_access row's capabilities — one write, applied instantly.
  3. RLS decides who may write. A policy allows a user to change a capability row only when the target account's ancestry traces back to them and they hold can_assign (Regional PM, PM, or admin). Everyone else is read-only.
  4. The tool enforces it. PropIQ (and the others) check the capability before showing or allowing an action — "Assign ticket" simply isn't offered to someone without assign. RLS guards the data; the app guards the screen.
  5. It's logged. Capability changes record who and when, and surface in the Audit log.
-- capabilities live on the tool grant alter table public.project_access add column if not exists capabilities text[] default '{}'; -- only an assigner in the same subtree may edit rights create policy "assigner edits caps" on public.project_access for update using ( auth_can_assign(auth.uid()) and is_descendant(account_id, auth.uid()) );
Ships with the migration

The capabilities column and its policy are part of portal-hierarchy-upgrade.sql — the same migration that adds delegated administration and the properties table.

Section 08

What happens when an account is created

Every account is one auth.users record joined to one profiles row. Here's the full chain each time you create one — useful when something looks off and you need to know which layer to check.

  1. Auth user is created. In Supabase → Authentication → Users → Add user, with Auto Confirm on (or send an invite). This mints the login and a UUID.
  2. A profile row appears. The handle_new_user trigger on auth.users inserts into public.profiles with the same id, the email, and defaults: is_admin=false, status='invited'.
  3. You set the account's place in the tree. Fill account_type, parent_account_id (who they report to) and can_assign (whether they may create sub-accounts). Master is the only role that may set can_assign=true.
  4. RLS scopes them instantly. Row-Level Security policies read those profile fields, so from this moment the account can only see rows that trace to them — their properties, their market, their subtree.
  5. You grant tools. Rows go into project_access (IQ apps), page_access.tier (Market Intelligence), and — for PropIQ — a properties assignment. This is what lights up their tool buttons, each grant seeded with the role’s default rights (see Section 07).
  6. The invitation goes out. Status moves invited → active on first sign-in. Delegated accounts sit at pending until an admin activates them.
The payoff

Because access is data in Supabase — not baked into the site — none of this needs a redeploy. Create, grant, flip a tier, revoke: all live the instant you save.

If a new account sees nothing

It's almost always the profile row or a grant, not the login. Check, in order: does a profiles row exist with the right account_type and parent_account_id? Is there a matching project_access / page_access grant? Are the RLS helper functions installed?

Section 09

Coding, Netlify & Supabase operations

Two systems run the platform: Netlify serves the front end, Supabase holds the data, auth, and access rules. The delegated model in this handbook needs one schema upgrade before it's live.

The one migration to run first

portal-hierarchy-upgrade.sql adds the columns and table the console assumes. Run it in the Supabase SQL Editor before deploying the console.

-- profiles: delegated administration alter table public.profiles add column if not exists account_type text default 'user', add column if not exists parent_account_id uuid references public.profiles(id), add column if not exists can_assign boolean default false, add column if not exists status text default 'invited'; -- properties: PropIQ is licensed per property create table if not exists public.properties ( id uuid primary key default gen_random_uuid(), account_id uuid references public.profiles(id), name text, address text, units int, property_admin_id uuid references public.profiles(id), status text default 'active' ); alter table public.properties enable row level security;
Order matters

Run the SQL first, then deploy. If you deploy first, the console loads but shows empty until the columns and properties table exist.

Deploying the front end (Netlify)

Netlify manual deploys replace the whole site, so a page can't ship alone — the entire bundle goes together.

  1. Assemble the bundle: index.html, home.html, viewer.html, admin.html, this platform-admin page, and config.js.
  2. Drag the folder onto the Netlify deploy pane.
  3. Confirm config.js is present — it carries the Supabase URL and publishable key; without it the site can't connect.
Never omit config.js

It's the connection. A deploy missing it will load a blank, sign-in-looping site.

Supabase surfaces you'll touch

SurfaceWhat lives there
SQL EditorMigrations and RLS policies. Paste full blocks — the schema upgrade above, plus per-table policies.
Authentication → UsersCreate logins (Add user + Auto Confirm) and send invites.
StoragePrivate buckets: protected-pages (market reports), resident-docs (resident files).
Edge Functions → SecretsKeys only — e.g. FRED_API_KEY, Stripe keys. Never put keys in front-end files.
Keys never touch the client

Publishable Supabase key in config.js is fine — that's its job. Everything secret (Stripe secret, FRED, service-role) lives only in Supabase Edge Function secrets. If a secret ever appears in chat or a file, rotate it immediately.

Section 10

Quick reference & glossary

Common tasks

TaskWhere
Grant a tool to an accountAccounts → click account → Manage access, or Access tab
Unlock a paid market studyClick client → raise Market tier to Deposit paid / Paid in full
Reset a passwordClick account → Reset password
Add a PropIQ propertyClick account → PropIQ → Create property
Name a property's client adminPropIQ panel → Assign admin on the property row
Activate a pending sub-accountInvitations tab → Activate
Let someone create sub-accountsMaster only → set can_assign=true on their profile

Glossary

TermMeaning
AssignabilityThe right to create and manage accounts beneath you. Granted only by the Master admin.
Client adminThe client-side person who manages property staff and their access inside PropIQ.
Paywall tierThe Market Intelligence access stage: none → awaiting → deposit → full.
Owner grantA tool locked as granted to the account that owns it, so it can't be revoked by mistake.
RLSRow-Level Security — Supabase rules that scope each account to only its own rows.
profilesThe table joining each login to its role, parent, assignability and status.
Remember

Access is data, not deployment. Almost everything you do in this console takes effect live — the only thing that needs a Netlify deploy is a change to the page files themselves.

PLATMETRIX · Platform Admin Console User Handbook · Console reflects seed data; your live screens show your own accounts.