← All Features
Live Now

⚙ Admin Panel

Full control over your platform. User management, role-based access, audit logs, system configuration, and integration settings — everything an operator or IT admin needs to run a tight ship.

Open Admin Panel → Request a Demo
Full Log
Complete audit trail
Role Isolation
Granular permissions
Sessions
Active session control
API Config
Integration management
Admin Panel
🛠 Core Capabilities
Admin Capabilities
The Admin Panel gives platform administrators complete control over users, permissions, security, and system configuration. Every action is logged and auditable.
👥
User Management
Add, edit, suspend, and delete users from a single interface. Assign roles during creation or change them later. Bulk actions let you onboard an entire dispatch team at once or suspend multiple accounts simultaneously. Reset passwords with a single click — the user receives a secure reset link via email. View each user’s last login, total sessions, and activity summary. Deactivated accounts are preserved in the system for audit purposes but cannot access any data. Re-enable suspended accounts instantly when staff return from leave.
🔒
Role-Based Access Control
Granular permissions per role ensure that each user sees only what they need. Dispatchers manage loads but cannot touch financials. Drivers see only their own data. Recruiters access the application pipeline but not operational details. The admin defines which modules, actions, and data each role can access. Changes to role definitions take effect immediately across all users assigned to that role. Permission conflicts are flagged automatically before saving. The RBAC system is the foundation of both security and compliance on the platform.
📝
Full Audit Log
Every action on the platform is logged: who did it, what they did, when they did it, and from which IP address. Login attempts (successful and failed), role changes, document uploads, load modifications, user creation, password resets — everything. The audit log is immutable. Even admin users cannot modify or delete log entries. This is essential for FMCSA compliance audits, internal investigations, and insurance claims. Search and filter logs by user, action type, date range, or IP address. Export audit data to CSV for external analysis.
System Configuration
Company profile settings, notification preferences, ELD configuration, third-party integrations, API keys, and webhook endpoints — all managed from one place. Set your company name, address, and branding that appear across the platform and on generated documents. Configure email notification templates for load assignments, compliance alerts, and settlement notifications. Manage API credentials for broker integrations, factoring companies, and accounting software. Webhook configuration lets external systems receive real-time events from the portal.
🔒
Session Management
View all active sessions across the platform in real time. See which users are currently logged in, from which device, which browser, and which IP address. Force logout any user instantly if you suspect unauthorized access or if a device is lost or stolen. Configure automatic session timeout — the default is 30 minutes of inactivity, adjustable per role. Set IP restrictions to limit portal access to specific office networks or VPN ranges. Session data is retained in the audit log even after the session ends.
📊
Usage Analytics
Platform usage by user, feature adoption metrics, and login frequency — all visualized in the admin dashboard. See which dispatchers are most active, which features are underutilized, and when peak usage hours occur. Track onboarding progress for new users: have they completed their first load entry, uploaded their first document, sent their first message? Usage data helps you identify training needs, justify the platform investment, and spot users who may need additional support or who are not engaging with the system.
Admin-only access: The Admin Panel is only visible to users with the Owner or Admin role. Dispatchers, recruiters, and drivers cannot see the admin section in their navigation. There is no way for a non-admin user to access admin functions, even by manipulating URLs — all permissions are enforced server-side.
📝 Compliance
Audit Log
Every action on the platform is recorded with full context. Here is what a typical day in the audit log looks like.
Timestamp User Action Details IP Address
2026-04-19 08:14:22 sarah.m (Admin) User Login Successful login via Chrome on Windows 198.51.100.42
2026-04-19 08:17:05 sarah.m (Admin) Role Changed Changed user mike.j from Dispatcher to Admin 198.51.100.42
2026-04-19 08:22:31 mike.j (Admin) User Created Created new user: lisa.r with role Dispatcher 203.0.113.88
2026-04-19 09:01:44 dispatch01 (Dispatcher) Load Updated Load #28847: status changed from Booked to Dispatched 203.0.113.88
2026-04-19 09:15:02 unknown Failed Login Failed attempt for username: admin (invalid password) 192.0.2.17
Audit logs are stored permanently and cannot be modified or deleted by any user, including admins. This immutability is a core design principle — it ensures that the audit trail is always trustworthy for compliance reviews, legal disputes, and insurance claims.
What Gets Logged
Every meaningful action on the platform:
  • User login and logout events
  • Failed authentication attempts
  • User creation, modification, suspension
  • Role assignments and permission changes
  • Load creation, updates, status changes
  • Document uploads and downloads
  • System configuration changes
  • API key generation and revocation
  • Session terminations (manual and timeout)
Search and Filter
Find any event quickly with powerful filters:
  • Filter by specific user or role
  • Filter by action type (login, update, create)
  • Filter by date and time range
  • Filter by IP address or subnet
  • Full-text search across details field
  • Combine multiple filters simultaneously
  • Save filter presets for recurring reviews
  • Export filtered results to CSV
  • Real-time log streaming for active monitoring
Compliance Value
Why the audit log matters for your operation:
  • FMCSA auditors require access documentation
  • Insurance claims need timestamped proof
  • Internal investigations with full context
  • Broker disputes resolved with delivery evidence
  • Driver complaints addressed with action history
  • Security incidents traced to source IP
  • Unauthorized access attempts detected
  • Change management documentation automated
  • SOX-style controls for financial data access
👥 Roles
User Roles Explained
Each role on the platform has a specific set of permissions. Here is a detailed breakdown of what each role can and cannot do.
👑
Owner / Admin
The highest privilege level. Full access to every module, every setting, and every piece of data on the platform. Only this role can access the Admin Panel.
  • Create, edit, suspend, and delete users
  • Assign and modify roles for any user
  • View and export the complete audit log
  • Configure system settings and integrations
  • Manage API keys and webhook endpoints
  • View all active sessions and force logout
  • Access all financial data and reports
  • View all loads, drivers, and fleet data
  • Manage compliance documents for all drivers
  • Configure notification templates and rules
  • Set IP restrictions and session policies
  • Export any data from the platform
📡
Dispatcher
Focused on load management and driver coordination. Dispatchers have the tools they need to move freight without being distracted by admin, financial, or HR functions.
  • View and use the live dispatch map
  • Create, edit, and manage loads
  • Assign and reassign drivers to loads
  • View driver status, HOS, and availability
  • Upload and view load documents (rate cons, BOLs, PODs)
  • Send messages to drivers through the portal
  • View fleet status (read-only)
  • Update load statuses through the pipeline
Restricted: No access to payroll, settlements, user management, system settings, recruiter pipeline, or financial reports.
📜
Recruiter
Dedicated to finding, qualifying, and onboarding new drivers. The recruiter sees the application pipeline and DQ file management, but nothing operational.
  • View and manage driver applications
  • Collect and organize DQ file documents
  • Track onboarding workflow progress
  • Manage background check and MVR requests
  • Communicate with applicants via portal messaging
  • View recruiter-specific reports and metrics
  • Mark onboarding steps as complete
  • Transfer completed drivers to active roster
Restricted: No access to active loads, dispatch map, financial data, driver settlements, fleet maintenance, or system settings.
🙋
Driver
Self-service access to personal information only. Drivers can view their loads, upload documents, check their HOS, and see their pay statements. They cannot see any other driver’s data.
  • View own assigned loads and details
  • Upload POD photos, receipts, and documents
  • View personal DQ file status and expirations
  • Check HOS summary from connected ELD
  • Read and send messages to dispatch
  • View own pay statements and settlements
  • Update personal profile information
  • View own compliance document status
Restricted: No access to other drivers’ data, company financials, fleet maintenance, recruiter pipeline, user management, or system settings.
Role changes take effect immediately. When an admin changes a user’s role, the new permissions apply on their next page load. If the user is currently viewing a page they no longer have access to, they are redirected to their role’s default dashboard. No logout/login cycle required.
🛡 Security
Security Features
The Admin Panel includes multiple layers of security to protect your operation’s data and ensure only authorized users can access the platform.
Session Timeout
Automatic session expiration after a configurable period of inactivity. The default is 30 minutes, but admins can set different timeouts per role. Dispatchers who are actively working may get longer timeouts, while sensitive admin sessions can be set shorter. When a session expires, the user is redirected to the login page. Any unsaved work is preserved in a local draft so they can resume after re-authenticating. Session timeout is a critical control for preventing unauthorized access from unattended workstations — especially in shared office environments common in trucking operations.
🌐
IP Restrictions
Limit platform access to specific IP addresses or CIDR ranges. This is useful for carriers who want to restrict admin access to the office network or a VPN. You can set IP restrictions globally (all users) or per role (e.g., admin access only from office, dispatchers from anywhere). When a user attempts to log in from a restricted IP, they see a clear error message. All blocked login attempts are logged in the audit trail with the source IP. IP allowlists can be updated at any time by an admin without requiring a system restart. Supports both IPv4 and IPv6 addresses.
🔐
2FA Readiness
The platform is architected for two-factor authentication. The authentication system supports TOTP (time-based one-time password) tokens compatible with Google Authenticator, Authy, and similar apps. Admins can require 2FA for specific roles — for example, making it mandatory for admin accounts while optional for drivers. Recovery codes are generated during 2FA setup so users can regain access if they lose their device. The 2FA enrollment flow includes clear step-by-step instructions with QR code scanning, making it accessible even for less technical users.
🔐
Password Policies
Enforce strong password requirements across the platform. Admins configure minimum length, complexity rules (uppercase, lowercase, numbers, special characters), and password expiration intervals. When a user’s password expires, they are prompted to create a new one at next login. Password history prevents reuse of the last 10 passwords. Failed login attempts trigger progressive lockout: after 5 consecutive failures, the account is locked for 15 minutes. Admins can unlock accounts manually or let the lockout expire automatically. All password-related events are logged in the audit trail.
🔒
Data Encryption
All data in transit is encrypted with TLS 1.3. Sensitive data at rest (passwords, API keys, personal driver information) is encrypted using AES-256. Database backups are encrypted before storage. API keys are stored as salted hashes — the full key is shown only once at creation and cannot be retrieved afterward. Session tokens use cryptographically secure random generation. All encryption implementations follow NIST guidelines and are regularly reviewed. Certificate rotation happens automatically with zero downtime.
Security by design: These security features are not add-ons — they are built into the core architecture of the platform. Every API endpoint checks permissions server-side. Every database query filters by the authenticated user’s role. Even if someone bypasses the UI, the backend enforces access controls at every layer.
⚙ Configuration
System Configuration
The Admin Panel centralizes every configurable setting in one place. No more scattered config files or hidden settings.
🏢
Company Profile
Set your company name, legal entity name, address, and operating authority details. Upload your company logo for use across the platform, on invoices, and in the driver portal. Configure your default timezone, date format, and currency. These settings propagate to all generated documents, reports, and email templates automatically. Update your company profile at any time without affecting historical records.
🔔
Notification Settings
Configure which events trigger notifications and who receives them. Set up email alerts for compliance expirations (30, 14, 7 days before), load status changes, new driver applications, failed login attempts, and settlement approvals. Customize email templates with your branding. Enable or disable browser push notifications per role. Create escalation rules: if a compliance alert is not acknowledged within 48 hours, notify the next person up the chain.
🔗
API and Webhooks
Generate and manage API keys for third-party integrations. Each API key can be scoped to specific permissions (read-only, load management, document access). Set rate limits per key to prevent abuse. Configure webhook endpoints to receive real-time events when loads are created, statuses change, documents are uploaded, or drivers complete onboarding. Test webhook delivery with a built-in ping tool. View delivery logs to troubleshoot integration issues.
📡
ELD Configuration
Configure the connection between the portal and ERETH ELD devices. Set data sync intervals, choose which vehicle diagnostics to display in the fleet health panel, and configure HOS rule sets (property vs. passenger, short-haul exemptions, personal conveyance rules). Map ELD device IDs to specific vehicles and drivers. Monitor sync status to ensure data is flowing correctly. Troubleshoot connection issues with built-in diagnostic tools.
💰
Financial Settings
Configure driver pay structures (per mile, percentage, flat rate, or hybrid). Set up deduction templates for recurring charges like insurance, ELD lease, and fuel advances. Configure factoring company integration for invoice processing. Set payment terms and aging thresholds for accounts receivable tracking. Define fiscal periods for financial reporting. All financial configurations are version-controlled so you can see when and by whom any rate or structure was changed.
📦
Backup and Export
Schedule automatic data exports for offsite backup. Choose which data sets to include: loads, drivers, documents, financial records, audit logs. Export formats include CSV, JSON, and PDF for document archives. Set retention policies for how long exported data is stored. Receive notification when exports complete or fail. Manual export is available at any time for ad-hoc requests from auditors, insurance companies, or legal counsel.
🚀 Workflow
Common Admin Tasks
Here are the most common tasks administrators perform and how the Admin Panel streamlines each one.
Onboarding a New Employee
When a new dispatcher, recruiter, or back-office staff member joins your operation, the admin creates their account in under a minute:
  • Click “Add User” and enter name, email, and role
  • The system generates a secure temporary password
  • New user receives a welcome email with login instructions
  • On first login, they are prompted to set their own password
  • Role permissions apply immediately — they see only what they should
  • The entire process is logged in the audit trail
Investigating a Security Incident
If you suspect unauthorized access or unusual activity, the Admin Panel gives you the tools to investigate:
  • Open the audit log and filter by the suspicious timeframe
  • Check for failed login attempts from unfamiliar IPs
  • Review active sessions for unknown devices or locations
  • Force logout the affected user immediately
  • Suspend the account pending investigation
  • Reset the user’s password
  • Export the relevant audit entries for your records
  • Add the suspicious IP to the restriction list
Preparing for an Audit
When an FMCSA auditor or insurance company requests records, the Admin Panel makes it straightforward:
  • Open the audit log and set the date range requested
  • Filter by relevant action types (document access, compliance changes)
  • Export the filtered log to CSV
  • Pull driver DQ files from the document center
  • Generate a user access report showing who had access to what
  • Provide the auditor with timestamped, tamper-proof records
Offboarding a Departing Employee
When someone leaves the company, the admin ensures clean separation:
  • Suspend the user account immediately
  • Force logout all active sessions for that user
  • Revoke any API keys associated with the user
  • Review recent activity for any concerning actions
  • Reassign their active loads or applications to other staff
  • Account remains in the system (suspended) for audit history
  • The entire offboarding is logged with timestamps
🔗 Related
Related Features
Explore other parts of the VAU0 platform that integrate with the Admin Panel.
Ready to see it in action?
Every feature on this page is available today — free through December 2026. Sign up and start in minutes.