# NSCC — System Configuration (vs Administration)

**Audience:** Product / eng / IPS leadership / tenant admins  
**Last updated:** 2026-08-22  
**Product:** NorthStar Courier Command — **NSCC w/Accounting, HR and Payroll** *(optional SKU; ops + Sage bridge remains available)*  
**Related:** [Customer pack](./NSCC_ACCT_HR_PAYROLL_CUSTOMER_PACK.md) · [Enterprise readiness](./NSCC_ENTERPRISE_READINESS_PREP.md) · [Living blueprint](./NSCC_FINANCE_HR_PAYROLL_BLUEPRINT.md) · [Data Dictionary](./NSCC_DATA_DICTIONARY.md) · Decisions A/B in [customer questions](./NSCC_ACCT_PAYROLL_CUSTOMER_QUESTIONS.md)

---

## The split (decision)

| Area | Job | Who |
| --- | --- | --- |
| **Administration** | People & privilege — who is admin, roles, access, audit of who changed what | Platform role `administration` |
| **System Configuration** | Tenant product setup — what is on, which vendors/APIs/law packs, feature SKUs | Same privileged people, different job |
| **Back Office** | Day-to-day Accounting / Payroll / HR / Master Data | Ops, finance, HR clerks |

**Name:** use **System Configuration** in product copy (not “Administration” and not “demo settings”). Keep **Administration** as the **role** and for user/role/security surfaces (Admin Console).

```text
Administration (people)     System Configuration (tenant product)
  roles / access               feature modules on/off
  audit who changed what       vendors / APIs / law packs
                               maps / AI keys (migrate from Admin Console)
        \                     /
         \                   /
          Back Office (day-to-day work)
            Accounting / Payroll / HR (only enabled modules)
```

---

## Config domains (catalog)

| Domain | Examples | Today |
| --- | --- | --- |
| **Feature modules** | Documents, Training, Appraisals, Certified Payroll, Analytics, … | Always on in HR/Payroll catalogs; Phase 1 toggles Documents / Training (+ short HR list) |
| **Maps / logistics APIs** | Mapbox (later Google/others) | Admin Console connection password |
| **AI APIs** | OpenRouter / OpenAI / … | Admin Console connection passwords |
| **Background screening** | Checkr / Sterling / HireRight / First Advantage / Accurate / GoodHire / practice mode | System Configuration company pick + **Decision C**; Admin Console passwords |
| **Payroll vendors** | Check / Gusto / practice mode | System Configuration (not Payroll day-to-day screens) |
| **Compliance / regulatory vendors** | Subscribe vs AI vs hybrid (**Decision A**) — risk/reward/cost | SysConfig Enterprise decisions + [brief](./NSCC_ENTERPRISE_DECISIONS_AB.md) |
| **Payroll tax & money path** | Bureau / self / hybrid (**Decision B**) — risk/reward/cost | SysConfig Enterprise decisions + payroll company pick |
| **Law packs** | State packs IPS operates in; federal overlays | HR Regulations KB; tenant selector starts in SysConfig UI |
| **Fiscal calendar** | Fiscal year start month (Jan vs Jul, etc.); drives YTD P&amp;L, budget phasing, period labels | **System Configuration → Fiscal calendar** (also Budget / Period Close) |
| **Notifications / ops prefs** | Digest, ticker | System Configuration modal (former System Preferences) |
| **Integrations** | Sage bridge mode, finance mode / tenant SKU | Path/env / finance-config — migrate labels later; **bridge path is permanent** |

---

## Tenant stack (locked product rule)

New customers are **not** forced into native Accounting / HR / Payroll. Two stacks stay first-class:

| Stack | What the customer gets | External systems |
| --- | --- | --- |
| **Ops + bridge** (live / demo style) | Dispatch, Pulse, Planner, Master Data, field work — money/people books stay in their ERP/payroll SoR | **Sage Connect** (and later other SoR bridges) remains available — same “talk to other systems” path live and demo use today |
| **NSCC w/Accounting, HR and Payroll** (demo2 style) | Native Accounting / HR & Payroll / Leadership pillars in NSCC | Bridge optional (hybrid) or phased native SoR |

**Do not remove** Sage Connect / staging / middleware just because native finance exists. Demo2 may hide Sage Connect when native is on; **ops-only and Sage-primary tenants keep it.**

System Configuration will own the tenant SKU / finance-mode label (migrate from path/env). Until that control ships, treat live+demo as the bridge reference and demo2 as the native reference — both stay shippable.

Related: Paths A/B/C in [`NSCC_NATIVE_FINANCE_EXECUTIVE_BRIEF.md`](./NSCC_NATIVE_FINANCE_EXECUTIVE_BRIEF.md) · SoR decision in [`NSCC_ENTERPRISE_READINESS_PREP.md`](./NSCC_ENTERPRISE_READINESS_PREP.md).

---

## Admin vs System Configuration vs Back Office

| Concern | Administration | System Configuration | Back Office |
| --- | --- | --- | --- |
| Who can sign in / which role | Yes | — | Uses roles |
| Turn Documents / Training off | — | Yes | Tabs hide when off |
| Mapbox / AI keys (interim) | Admin Console (temporary) | Deep-link / migrate here | — |
| Draft invoices / run pay | — | — | Yes |
| Demo sandbox ops | Admin Console | — | — |

**Security note:** Org secrets (API keys) should not stay browser-only long-term. Phase 1 may still deep-link to Admin Console fields; Cloud Functions / vault is out of scope for this pass.

---

## Phase 1 product shape (shipped with this doc)

1. Support → **System Configuration** (was System Preferences); chrome title **System Configuration**.
2. **Feature modules** — toggles for HR modules (Documents, Training, Appraisals, Recruitment, …). Persist to Firestore `live_siteConfig/featureModules` with localStorage fallback.
3. **Outside companies** — pick payroll company and screening company in plain language (Practice mode / Check / Gusto / Checkr / Sterling). Connection passwords stay in Admin Console.
4. **Law packs** — state checklist + federal baseline (UI; Decision A vendor wiring later).
5. **Enterprise decisions A & B** — customer records appetite for regs path and tax/money path with risk · reward · cost framing (contracts still prep).
6. **Cloud & operating costs** — honest cost map for Firebase / GCP, Mapbox, **SMTP2GO**, new markets, enhancements ([brief](./NSCC_CLOUD_AND_OPERATING_COSTS.md)); surfaced in SysConfig so IPS sees it next to A/B.
7. Admin Console keeps demo ops + temporary connection passwords; callout points operators to System Configuration for integrations & features.

---

## Out of scope (this pass)

- Full secret vault / Cloud Functions for API keys  
- Completing Checkr/Sterling handler gaps  
- Restoring ad-hoc menu visibility tooling (feature flags supersede for product modules)  
- Implementing Decision A/B **vendor contracts** (choice UI is in SysConfig; OAuth / feeds come after pick)  

---

## Success criteria

- IPS materials clearly separate **Administration** (people) from **System Configuration** (product/tenant setup).
- Operators have a home for APIs, vendors, law packs, and feature on/off.
- Documents / Training can be disabled and disappear from Back Office HR nav.
- Customer pack + readiness + blueprint stay the wired story.
