DocsSettings
Platform

Settings, Team & Roles

Multi-branch agency setup, user roles, currencies, integrations, and security (2FA, sessions, audit log).

Version 1.0
Updated Jun 30, 2026
Video tutorialWatch the full walk-through

The Settings module is where you configure how TravelBoost behaves for your agency — currencies, branches, user roles, integrations, security policies, branding, and the audit log. Every other module in the system reads from here.

Overview

Settings is grouped into seven sections:

  1. Agency profile — name, logo, address, base currency, base timezone
  2. Branches — sub-offices with their own staff, pipelines, and reporting
  3. Team & Roles — users, role definitions, permissions
  4. Currencies & FX — enabled currencies, rate source, manual overrides
  5. Integrations — payment gateways, accounting, WhatsApp, email, SMS, WordPress, GPS
  6. Security — 2FA, session policy, IP allowlist, audit log
  7. Branding — colours, logo, email templates, PDF templates

Multi-branch

A branch in TravelBoost is a sub-organisation under your agency. Common use cases:

  • Multi-city agency — Casablanca, Marrakech, Tangier branches
  • Multi-country agency — Egypt, UAE, Saudi Arabia branches
  • Multi-brand — luxury brand, mid-market brand, value brand

Each branch can have its own pipelines, suppliers, currencies, and team. Cross-branch reporting is available to head office users.

Team & Roles

The role system is hierarchical with clear scopes:

RoleDefault permissions
AGENCY_ADMINFull access, settings, billing
MANAGEROperations + reporting, can't change settings or billing
BRANCH_MANAGERManager scoped to one branch
AGENTDay-to-day sales: leads, customers, bookings, proposals — no finance
FINANCEFinance + reports, no operational mutations
SUB_AGENTRestricted portal — only their own leads + bookings
CUSTOMER_PORTALCustomer-facing, read-only view of their own trips
PILGRIMPilgrim portal access for a specific season
DRIVERDriver mobile portal — assigned trips only

Roles can be cloned and customised. Permissions are granular: read / create / update / delete / export / approve, per module.

Currencies & FX

Set your base currency once. Enable additional currencies the agency transacts in. The FX rate updates daily from the European Central Bank (or a custom source). Per-booking, you choose the transaction currency; the system always tracks both transaction-currency and base-currency.

Integrations

Available integrations (point and click):

CategoryProviders
Payment gatewayStripe, PayPal, CMI (Morocco), Paymob (Egypt), Mada (Saudi), local processors
AccountingXero, QuickBooks, Sage, Zoho Books
EmailSendGrid, Mailgun, Amazon SES
WhatsAppTwilio WhatsApp Business, Vonage, 360dialog
SMSTwilio, Vonage, regional gateways
GPS / fleetGPSGate, Wialon, Geotab, NMEA generic
WordPressTravelBoost plugin (auto-installs the bridge)
AuthenticationGoogle, Microsoft, SAML SSO (Enterprise plan)

Each integration shows connection status, last-event timestamp, and a "Test" button.

Security

  1. Enforce 2FA for the agency

    Security → 2FA policy → "Required for all users". On their next login, every team member is prompted to set up TOTP (Google Authenticator, Authy, 1Password).

  2. Set session policies

    Maximum session duration (default 8 hours), idle timeout (default 30 minutes), per-IP session cap, geo-restrictions.

  3. Add IP allowlist (optional)

    For agencies that operate from a fixed office, restrict admin access to known IPs. Field staff can use a "trusted device" exemption.

  4. Review the audit log

    Security → Audit log shows every mutation across the system: who, what, when, before/after values. Filterable by user, module, action type, date range. Exportable to CSV for compliance.

Branding

Upload your logo (PNG with transparent background works best). Pick your primary + accent colours. Customise PDF templates (proposal, invoice, contract, pilgrim manual). Customise email templates per language.

FAQ

Can I have different brandings per branch?

Yes — each branch can override the agency-wide branding for its own customer-facing surfaces (PDFs, emails, customer portal).

How do I deactivate a user who has left?

Team → click the user → Deactivate. Their sessions are revoked immediately. Their historical data (notes, mutations, audit trail) stays intact and attributed to them.

Is the audit log immutable?

Yes — entries are append-only. Even AGENCY_ADMIN cannot delete or modify entries. The log is retained for 7 years by default.

Can I export everything if I cancel?

Yes — Settings → Export agency data generates a full ZIP of every record (customers, bookings, payments, files) in JSON + CSV. Available for 30 days after cancellation.

What's next