Five role tiers, a full audit trail, real-time security alerts, and single sign-on — the control layer that lets admins run ThirdEyee with confidence instead of spreadsheets and guesswork.
Every role sees exactly what it should — nothing more. Every admin action is logged. Every sign-in can go through Google or Microsoft. Security here isn't a separate product; it's underneath everything.
Four systems keep control where it belongs — with the right person, logged, and reviewable.
Employee, Manager, HR, Admin, and Super Admin each unlock a different slice of the product. Managers don't just see "their team" as a flat list — visibility follows the actual reporting chain, recursively, so a manager of managers still sees everyone underneath.
Approvals, edits, subscription changes, policy updates — every action an admin or manager takes is logged with who did it, what changed, who it affected, and when.
Anti-cheat flags and other unusual activity land in a dedicated Security Alerts feed — separate from ordinary activity reports, so they never get lost in the noise. An optional email notice can flag a suspected sensitive-keyword or data-leak event straight away.
Google Workspace and Microsoft 365 / Azure AD login sit right alongside email and password. New accounts still go through an approval queue, and invite links carry a secure, single-use setup token.
Nobody gets more access than their role calls for
New sign-ups sit in an approvals queue until an admin says yes — no unvetted accounts slip into a company roster.
Invites carry a single-use setup token, so an employee's first login is tied to the exact invite an admin sent.
Pin your office's IP once, and location reporting can tell "at the office" from "somewhere else" automatically.
Screenshot interval and idle timeout are company-wide settings an admin sets once — not something each agent decides on its own.
Every route checks the signed-in role on the server, not just in the menu — so there's no hidden URL that quietly bypasses permissions.
A self-serve reset flow for email-based accounts, so a forgotten password never has to become an admin's problem.
Admin tools that go beyond access control
Tag each app with its monthly cost, and get a flagged recommendation whenever a license is barely being used.
See current seats used against your plan's quota at a glance, with a 14-day free trial applied automatically for new companies.
Generate a company API key and wire up webhooks — for example, notify another tool automatically when a project completes.
An early flag when monitored activity suggests a possible data leak, emailed straight to your security contact.
Every company's users, logs, and settings stay cleanly separated — an admin only ever sees their own company's data.
If a plan lapses, the team keeps access to billing and account pages to sort it out — nobody gets abruptly locked out mid-task.