Admin and operations
Platform staff run the marketplace from the admin console. Every staff and money action is written to an audit log with the actor, the action, and the before and after values.
Roles
| Role | Uses |
|---|---|
CUSTOMER | Storefront and buyer app |
SELLER_OWNER, SELLER_STAFF | Seller console and seller app, scoped to their own seller |
DRIVER | Driver app |
DISPATCHER | Dispatch console, delivery zones |
ADMIN | Admin console |
SUPER_ADMIN | Admin console, plus commission plans and feature flags |
Sellers and staff must use an authenticator-app second factor. A seller can never see another seller's data: the API answers "not found" rather than "forbidden", so it does not even confirm that the record exists.
What the admin console does
| Area | Views |
|---|---|
| Trust & moderation | Product moderation (approve / reject), reviews (publish, take down, remove media), questions, fraud review (read-only) |
| Onboarding | Sellers (KYC documents, approve, send back with a reason, suspend, reinstate, verify bank accounts); drivers (assign zones and cash limit, verify bank account, approve, suspend, reinstate) |
| Orders & disputes | Order lookup; disputes (review, resolve for buyer or seller with an optional refund amount, close); chargebacks |
| Finance | Payout runs, approval and marking payouts paid; currencies; funnel analytics |
| Commercial set-up | Commission plans (super admin), tax rates, shipping, coupons, gift cards |
| Catalogue | Categories, brands, taxonomy and attributes |
| Platform | Users, audit trail, feature flags (super admin), delivery zones, content (CMS pages, FAQs, versioned legal pages), message templates, support tickets |
Automated jobs staff should know about
The worker runs these on a schedule; only one instance runs each job at a time (a Postgres advisory lock).
| Job | Every | What it does |
|---|---|---|
outbox.relay | 5 s | Publishes domain events to their handlers |
notifications.send | 10 s | Sends queued email, push, SMS |
payments.webhooks | 5 s | Processes payment provider notifications |
inventory.release_expired | 1 min | Releases stock held by abandoned checkouts |
delivery.assign_pending, delivery.build_routes | 1 min | Assigns delivery tasks and plans routes |
orders.alert_missed_accept_deadlines | 5 min | Alerts sellers and admins about unanswered orders |
disputes.escalate_overdue | 15 min | Escalates disputes past their response deadline |
support.sweep_sla | 15 min | Flags support tickets that breached their SLA |
chargebacks.sweep_deadlines | 30 min | Watches chargeback evidence deadlines |
ledger.reconcile, delivery.reconcile_cod | 1 h | Checks the ledger and driver cash |
realtime.prune_pings | 6 h | Removes old driver location pings |
identity.prune_expired | 12 h | Removes expired sessions and codes |
| Daily | 24 h | Stock audit, rating reconciliation, funnel roll-up, product-view pruning, seller performance snapshots |
Payout runs are not in this list: finance starts them by hand. See Money rules.
Support and communication
- Buyers open support tickets from their account; staff answer from the console, and SLA breaches alert support.
- Buyers and sellers can message each other in conversations attached to their account.
- CMS content — pages, FAQs and legal documents with versions — is edited in the console and shown on the storefront help and legal pages.