# Manage

> The Administrator surface - users, roles, organization settings, API keys, webhooks, data operations, and the trust story.

Source: https://app.assetlab.ca/docs/manage

Everything in this section lives under **Settings**, and all of it requires the **Administrator** role. It's the smallest surface in AssetLab and the one with the longest consequences - decisions here shape what everyone else sees.

## What lives here

| Page | What it covers |
|---|---|
| [Users & invitations](/docs/manage/users-and-invitations) | Getting people in, roles, removal |
| [Roles & user groups](/docs/manage/roles-and-permissions) | Scoping teams by site, system class, and work category |
| [Organization settings](/docs/manage/org-settings) | Identity, currency, notifications, workflow options |
| [API keys](/docs/manage/api-keys) | Scoped, tenant-bound keys for the API and MCP |
| [Webhooks](/docs/manage/webhooks) | Pushing events to your other systems |
| [Import & export](/docs/manage/import-export) | Data in, data out, in bulk |
| [Security & data residency](/docs/manage/security) | Where data lives and how it's protected |
| [Language & localization](/docs/manage/language) | English and French |

## The Administrator's first hour

For a new organization, work through Settings in this order:

1. **General settings** - currency *first* (it lives on the **General** tab, and money formatting flows everywhere).
2. **Users** - invite the core team with conservative [roles](/docs/start/roles-and-access).
3. **User groups** - once dispatch by district or trade matters; small teams can skip them (ungrouped users are unrestricted).
4. **Work order / requester portal settings** - categories and routing to match your operation.
5. **API keys** - when you're ready for [AI](/docs/ai) or integrations, not before.

## A standing habit

Settings changes are organization-wide and immediate. Two safeguards worth adopting:

- Announce changes that alter what people see (categories, portal fields, group scopes) - a silent change reads as a bug to the field.
- Review users and API keys on a calendar - quarterly is plenty, forgetting entirely is the failure mode.
