Security & Admin

Five role tiers, a full audit trail, real-time security alerts, and single sign-on — the control layer that lets admins run ThirdEyee with confidence instead of spreadsheets and guesswork.

Enterprise control, without the overhead

Every role sees exactly what it should — nothing more. Every admin action is logged. Every sign-in can go through Google or Microsoft. Security here isn't a separate product; it's underneath everything.

Role-based access, 5 tiers deep
Full audit trail, CSV-exportable
Google & Microsoft single sign-on
Real-time security alerts
Admin Employee Manager HR Admin AUDIT TRAIL admin.arjun approved user r.mehta Today, 09:14 AM manager.priya extended deadline — Project Nova Today, 08:52 AM super_admin updated screenshot interval Yesterday, 06:40 PM

Access & security, explained

Four systems keep control where it belongs — with the right person, logged, and reviewable.

Role-Based Access
Audit Trail
Security Alerts
Single Sign-On

Role-Based Access

Five tiers, scoped automatically

Employee, Manager, HR, Admin, and Super Admin each unlock a different slice of the product. Managers don't just see "their team" as a flat list — visibility follows the actual reporting chain, recursively, so a manager of managers still sees everyone underneath.

  • Every route checks the signed-in role before rendering anything
  • Employees land on their own dashboard; there's no accidental company-wide view
  • A blocked action shows a clear "not authorized" page, not a silent failure
Super Admin HR Mgr Mgr Mgr

Audit Trail

Every admin action, kept honestly

Approvals, edits, subscription changes, policy updates — every action an admin or manager takes is logged with who did it, what changed, who it affected, and when.

  • Super Admins see platform-wide history; company admins see only their own company
  • One click exports the full trail to CSV for compliance or a board review
  • Nothing in the trail can be edited after the fact
AUDIT_LOGS_REPORT.CSV LOG ID ADMIN ACTION TIME 1042arjun.papproved user09:14 1041priya.sedited schedule08:52 1040super_adminupdated policyY'day 1039arjun.prejected userY'day Export CSV

Security Alerts

Flagged the moment it happens

Anti-cheat flags and other unusual activity land in a dedicated Security Alerts feed — separate from ordinary activity reports, so they never get lost in the noise. An optional email notice can flag a suspected sensitive-keyword or data-leak event straight away.

  • Scoped by role: managers see their team, admins see the company, super admins see everything
  • Each alert keeps its reason on record — jiggler, auto-clicker, keyboard spam, or a flagged keyword
  • Alerts inform a conversation; nothing is auto-punished
Mouse Jiggler Detected k.verma · 2 min ago Sensitive Keyword Flagged s.iyer · 18 min ago Case Reviewed & Cleared r.mehta · 1 hr ago

Single Sign-On

Sign in the way your team already does

Google Workspace and Microsoft 365 / Azure AD login sit right alongside email and password. New accounts still go through an approval queue, and invite links carry a secure, single-use setup token.

  • No separate password policy to enforce or reset
  • Invite-based onboarding keeps company rosters accurate from day one
  • Self-serve password reset for the accounts that use email login
Sign in to ThirdEyee Continue with Google Continue with Microsoft — or — Email & Password

The control layer, at a glance

5

Role tiers, from Employee up to Super Admin

2

Built-in SSO providers — Google & Microsoft

1-click

CSV export of the full audit trail

14-day

Free trial applied automatically to every new company

Govern access with confidence

Nobody gets more access than their role calls for

Approval-Based Onboarding

New sign-ups sit in an approvals queue until an admin says yes — no unvetted accounts slip into a company roster.

Secure Invite Links

Invites carry a single-use setup token, so an employee's first login is tied to the exact invite an admin sent.

Office IP Allow-listing

Pin your office's IP once, and location reporting can tell "at the office" from "somewhere else" automatically.

Configurable Tracking Policy

Screenshot interval and idle timeout are company-wide settings an admin sets once — not something each agent decides on its own.

Unauthorized Access Handling

Every route checks the signed-in role on the server, not just in the menu — so there's no hidden URL that quietly bypasses permissions.

Password Reset & Recovery

A self-serve reset flow for email-based accounts, so a forgotten password never has to become an admin's problem.

Keep the business side under control too

Admin tools that go beyond access control

Software License Governance

Tag each app with its monthly cost, and get a flagged recommendation whenever a license is barely being used.

Subscription & Seat Management

See current seats used against your plan's quota at a glance, with a 14-day free trial applied automatically for new companies.

API Keys & Webhooks

Generate a company API key and wire up webhooks — for example, notify another tool automatically when a project completes.

Sensitive Keyword Alerts

An early flag when monitored activity suggests a possible data leak, emailed straight to your security contact.

Multi-Tenant Isolation

Every company's users, logs, and settings stay cleanly separated — an admin only ever sees their own company's data.

Graceful Subscription Gating

If a plan lapses, the team keeps access to billing and account pages to sort it out — nobody gets abruptly locked out mid-task.

Security your team can trust, control your admins will love

Start a free trial and see the full role, audit, and access system in your own account.

Start Free Trial