Founder/platform-admin surface. Invitation links are shown once — copy and deliver them manually over a trusted channel. They are never retrievable later, only reissuable (which kills the old link).
Sign in (platform admin session required)
New tenant (SAAS-17 provisioning)
Creates the tenant in DRAFT. Then, in order: add the FlowProof trial, invite the initial owner (OWNER), activate, and let the owner accept the invite. Activation is blocked until an owner (or a live owner invitation) exists. No SQL involved.
Tenant
Provisioning
| Module | Plan | Status | Trial ends | Actions |
|---|
Add module subscription
Adds a new module to the selected tenant. Existing module subscriptions are never changed or replaced from here — their lifecycle stays on the per-row actions above. Only modules the tenant does not already have are offered.
Lead import (CSV, SAAS-18)
Imports an existing lead backlog into the tenant selected above.
Allowed columns: name, phone, email, city, country, message, interest, priority
(header row required; at least one of name/phone/email). Max 500 rows / 256 KB.
Always dry-run first — commit stays disabled until a clean dry-run of the same file.
| Batch | Brand | Rows | Imported | Dup (file) | Dup (existing) | When |
|---|
Initial owner (OWNER → TENANT_OWNER)
Every tenant needs exactly one owner. Provisioning the initial owner is a dedicated SUPER_ADMIN-only action — the public role label is OWNER, stored canonically as TENANT_OWNER. Activation is blocked until the tenant has an active owner or a live pending owner invitation. The owner accepts the invite after activation.
New invitation (MEMBER / VIEWER)
Regular team access only. The initial owner is provisioned from the dedicated panel above, never from here. MANAGER is unavailable by design; platform identities cannot be invited.
Invitations
| ID | Invitee | Role | Status | Expires | Actions |
|---|
Members
Change a member's role inline, or manage their membership lifecycle. The last active tenant owner cannot be suspended, revoked, or demoted.
| ID | Name | Role | Status | Actions |
|---|
Tenant audit history
Tenant lifecycle, membership and subscription events — safe metadata only, most recent first.
| When | Event | Actor | Details |
|---|