SellerFolio · Guide

Using Settings

Settings holds four things: your own sign-in, who else is in the workspace and what they may see, the browser extension that records LIVE video receipts, and the shipping account labels are bought through. Most of it is quiet housekeeping. A few of the buttons take effect instantly for other people, and a few cannot be taken back — this guide is mostly about which ones those are.

The four sections

The rail down the left side of the screen jumps to each one, and the dot beside it mirrors that section's status — orange means something there wants attention.

Who can open this screen Settings needs either permission to manage the TikTok connection and capture tokens or permission to manage the team — not both. Someone with neither does not see Settings in the menu, and going to the address directly shows a no-access page. Packers hold neither, by design: their credentials are managed for them. A manager holds the first but not the second, so a manager sees Account, Video capture and Shipping, and no Team card at all.
Three things people look for here that are not here
Part 1

Account — your own sign-in

Two things, both about you and nobody else. The card header shows the email address you are signed in as.

01

Change your password

Change password opens a small dialog that asks for your current password first, then the new one twice. The dialog states the minimum length underneath the field and will not let you submit something shorter, or one of the passwords that turn up most often in breaches. If the current one is wrong the dialog says so and nothing changes.

Changing your own password does not sign you out anywhere — the confirmation says "use it next time you sign in", and it means it. That is deliberately different from an owner resetting someone else's password, which does sign that person out (step 09).

Packers do not have this A packer's credentials are owner-managed on purpose — there is no self-service password change for that role. If a packer needs a new password, an owner sets it from the Team card.
02

Signed-in devices

Every phone or tablet signed in to the mobile app as you, with the label it gave at sign-in, whether it is an Android or an iPhone/iPad, the last four characters of its access token so you can tell two of the same model apart, and when it was last used. Sign out asks you to confirm, then kills that device's access immediately.

You only ever see your own devices here, and you can only revoke your own. There is no way from this card to see or revoke somebody else's phone — for that, an owner resets that person's password, which revokes their devices as part of the same operation.

"That device was already signed out" Not a failure. It means the server has no live session for that device — it was already revoked, or the row is gone. If you came here to kill a lost phone, that message is the answer you wanted.
"Couldn't load" is not the same as "nothing is signed in" If the list fails to fetch, the header says Couldn't load and shows a Try again link — and the table and the empty state are both hidden, on purpose. An empty list would read as "no devices are signed in", which is the worst possible thing to tell someone hunting a stolen phone. If you see that message, retry before you conclude anything.
Part 2

Team & access — inviting people

There are two ways to add someone: send them an invitation, or create the account yourself. Inviting is the normal path and it leads the card. Only people who can manage the team see any of this.

03

Send an invitation

Type the email address, pick a role, press Send invite. The invitation goes out by email and appears in the pending list underneath with the date it expires — invitations are good for seven days, then the link stops working.

The link takes the recipient to a page showing the workspace name and the role they were offered. It deliberately does not show the email address it was sent to, so a link that ends up in the wrong hands does not disclose who it was for.

If they already have an account Accepting only adds them to this workspace. Their existing password is never read and never changed, and they are not signed in by the link — they sign in the normal way. A brand-new account sets its password on the accept page and is signed straight in.
04

When the email cannot be sent

The invitation still exists. A warning bar appears with the full accept link and a Copy link button — send it however you like. This is why a failed send is never a dead end: the row is real, the link is valid, only the delivery failed.

05

Resend and revoke

Resend issues a fresh link and re-sends the email. It also invalidates whatever link was already out — there is only ever one live invitation per email address, so the old one dies the moment the new one is issued. If someone says "I clicked the link and it did not work", check whether a resend happened after they got theirs.

Revoke asks you to confirm and then kills the invitation and its link for good. There is no undo — to invite that person again you send a new invitation, which is fine and creates a fresh seven-day link.

Two refusals worth recognising "That email already belongs to a member of this workspace" means they are already on the list below — edit their role there instead. "That email already belongs to another workspace and can't be added to this one" means the account exists but lives somewhere else; there is no workspace switcher, so an invitation would create access that person could never reach. Both are caught when you press the button rather than being discovered later by the recipient.
Part 3

Team & access — members and permissions

The list below the invitations is everyone with access right now. This is the part of Settings that changes what other people see, immediately.

06

Add a member directly

Add member directly creates the account there and then: name, email, a temporary password, and a role. The password field states the minimum length it will accept, and refuses the passwords that turn up most often in breaches — including the person's own name. No email is sent and nothing has to be accepted — they can sign in as soon as you press the button. Use it when you are sitting next to the person; use an invitation when you are not.

07

The three roles

Owner has everything, always. Manager has everything except managing the team. Packer has three things: view fulfillment and packing, buy and print shipping labels, and view orders — with every money figure hidden, because a packer does not hold the financial-figures permission. The full breakdown is in the roles table at the end.

Owner is structural An owner's permissions cannot be trimmed. Selecting Owner in the role dropdown greys out every checkbox and says so on the row — overrides are simply not applied to owners, in the screen and on the server alike.
08

Open a row to tune one person's permissions

Clicking a member's row expands a permission matrix underneath, grouped the same way the permissions are grouped: Data access, Financial, Actions, Account. Every box starts where the role puts it; ticking or unticking one records a difference from the role, and the row gets a customized pill in the list. Set a box back to what the role already gives and the override disappears again rather than being stored as a no-op.

Some boxes are greyed out with a Requires: note. Those permissions depend on others — you cannot let someone edit line costs without also letting them see the costing workbench and see financial figures. Turning off something upstream drops everything that needed it, all the way down the chain.

The highlighted row is the money switch Show financial figures is drawn in blue with a border because it is not one screen's permission — turning it off hides revenue, profit, margins and costs from that person everywhere in the app. Screens still open; the money is simply not in the data they receive.
Saving a role or permission change signs that person out Every browser session that member has is deleted as part of the same save. This is on purpose — an access change that only took effect at their next sign-in would leave someone holding permissions you just removed for up to a month. They will have to sign in again, and they will not be warned first.
09

Set password — resetting somebody else's credentials

Set password on a member's row opens a dialog that asks only for the new password. There is no current-password check — that is the whole point, and it is why the button needs seniority over the person you are pointing it at.

Setting a member's password does three things at once, all or nothing:

  • the password changes;
  • every phone or tablet signed in as them is revoked;
  • every browser session they have is deleted.

That combination is the answer to a lost or stolen device belonging to someone else. It is also, in practice, what actually happens when a device goes missing — far more often than the person finding the self-service revoke list themselves.

10

Remove a member

Remove asks you to confirm on the row, then deletes their membership and signs them out of everything. Your own row shows you instead of a Remove button — you cannot remove yourself here.

Removal cannot be undone Their membership, their role and any custom permissions on it are gone. You can add or invite the same person again afterwards, but that creates a fresh membership at whatever role you pick — the permission tuning you had done for them is not restored. If you only want to take access away temporarily, trimming permissions is the reversible option.
A workspace always keeps one owner Removing the last owner, or demoting them, is refused with "a workspace must keep at least one owner". The check holds even if two people try at the same moment, so there is no way to end up locked out of your own workspace.
11

What you will be stopped from doing

Managing the team is not the same as outranking everyone in it. Four rules are enforced on the server, and each has its own message:

  • "You don't have the seniority to manage this member." You may only act on people below your own rank. Owners can act on anyone, including other owners — so only an owner can edit an owner, or promote anyone to owner.
  • "You can only grant permissions you hold yourself." You can always restrict someone; you cannot hand out something you were never given.
  • "You can't change your own role — ask another owner." Nobody promotes or demotes themselves, owners included.
  • "A workspace must keep at least one owner." As above.

The same rules apply to invitations, which is why an invitation can never mint a role its sender could not have created directly. They are also re-checked when the invitation is accepted, against the sender's standing at that moment — a week-old invitation from someone who has since been demoted will not still create an owner.

Part 4

Video-receipt capture

The Chrome extension that records what was said on a LIVE and attaches it to the orders that came out of it. Setting it up is four steps and one button.

12

Read the status pill first

The pill reports what this browser actually says right now, not what happened during this visit:

  • checking… — still asking the browser.
  • not set up — the extension is not installed here, or the page has not been reloaded since it was.
  • not paired — installed, but not linked to a workspace, so captures have nowhere to go.
  • capturing — installed and paired; LIVE sessions capture automatically.
This is per browser, not per workspace Pairing on the studio laptop does nothing for your machine at home. Each browser that will run a LIVE needs its own install and its own pairing, and each will show its own status here.
13

The four steps, and the Pair button

Download the .zip and keep the folder somewhere permanent — Chrome loads the extension from that folder, so moving or deleting it breaks the extension. Load it at chrome://extensions with Developer mode on, via Load unpacked. Then reload this page: Chrome only exposes a freshly installed extension after a page load, which is why this cannot happen on its own. Finally press Pair to this workspace.

Pairing creates the access token for you and hands it straight to the extension — there is nothing to copy. If it does not confirm, the card says so and asks you to reload and try again; retrying reuses the same token rather than minting another. A paired card offers Re-pair instead, which is the thing to press if capture stops working.

A first-timer should use the Full walkthrough with screenshots link at the bottom of the card. The four cells are a reminder, not a tutorial.

14

Access tokens — the collapsed section

Access tokens is folded away because pairing handles it. Open it to see every live token: its label, the last four characters, and when it was last used — which is how you tell a token that is still capturing from one nobody has touched in months.

Create token mints one by hand for a machine you cannot pair from. The token itself is shown once, in a green box, with a Copy button; it is stored as a hash and can never be shown again. Losing it means creating another.

Revoking a token stops that browser capturing Immediately, with no warning at the other end. If a paired browser suddenly shows not paired, a revoked token is the first thing to check. Revoking is not reversible — pair again, or create a new token.
Part 5

Shipping — the Shippo account

Where labels are quoted and bought from. Everything on the ship dock depends on this card being complete and correct.

15

The API token, and the LIVE / TEST MODE pill

Paste a Shippo token into the field and save. It is stored encrypted and only its last four characters are ever shown again, in the card header. Leaving the field blank on a later save keeps whatever token is already stored — you never have to re-enter it to change an address or a preset.

The pill beside the card title is derived from the token itself: a token beginning shippo_live_ shows LIVE; anything else shows TEST MODE. Anything that is not explicitly a live token is treated as test, which is the safe way round.

LIVE buys real postage In LIVE mode, every label bought from the ship dock spends real money the moment it is purchased. Test mode produces labels that look right and carry no charge — use it while you are still checking the sender address and presets.
16

Sender address

Where parcels are shipped from, and the return address printed on the label. Five fields are required before a label can be bought at all: name, street, city, state and ZIP. Phone, email and second street line are optional. The country is fixed at US and shown under the grid rather than being editable.

What an incomplete address looks like elsewhere Buying a label with fields missing does not fail vaguely — the ship dock refuses with "complete the sender address in Settings" and names exactly which fields are missing. If you see that message, this is the card it means.
17

Label format and parcel presets

Label format is one of PDF_4x6 (the thermal-printer size), PDF or PNG, and it is what every purchased label comes back as.

Parcel presets are the boxes and mailers you actually use: a name, length, width and height in inches, and a weight in ounces. They become the choices offered when quoting a shipment, so a preset with the wrong dimensions quietly produces wrong quotes on every order it is picked for. + Add preset adds a row; Remove deletes one. Neither takes effect until you save.

18

The save bar

The bar at the foot of the card sticks to the bottom of the screen because the form is long. ● Unsaved changes appears the moment anything differs from what was loaded, including a token typed into the field. Discard re-reads the saved settings and throws your edits away. Save shipping settings is disabled until there is genuinely something to save.

"Couldn't load Shippo settings — reload before saving" If that note appears, the form on screen is not what is stored — it is the blank starting state. Saving from there would write that emptiness over your real configuration, which is why Save stays disabled until a successful load. Reload the page; do not try to retype it from memory.
When

Something looks wrong

?

The Account and Team cards have vanished

If a box at the top says Couldn't load your account, both cards are hidden because they depend on the same request — press Retry. Everything below is unaffected and still trustworthy. If there is no error box, you simply do not hold the permission each card needs.

?

Team & access says "Couldn't load team settings"

The member list and permission definitions did not arrive. Try again in place is the fix. A separate failure to refresh only the invitations list is reported on its own and leaves the rest of the card working — reload the page to see the latest pending invitations.

?

Connecting a TikTok shop bounced back here with an error

Two refusals land on this screen as a toast, both enforcing one shop to one workspace from opposite directions. "That TikTok shop is already connected to another workspace" means somebody else has it. "This workspace is already connected to a different TikTok shop" means this workspace is taken — connecting another shop needs a new workspace. Neither leaves your existing connection damaged: the refusal happens before anything is saved.

?

Someone says they were signed out for no reason

Three things here sign a person out, all of them immediately and without warning them first: changing their role, changing their permissions, and setting their password. Setting their password also kills their phones and tablets. If it was not one of those, it was not this screen.

?

An invitation link says it does not work

Four causes, in order of likelihood: a later Resend replaced it; the seven days ran out; it was revoked; or it has already been accepted. A revoked or unknown link is deliberately indistinguishable from one that never existed — that is a privacy choice, not a bug. Send a fresh invitation.

Reference

Roles, permissions and what changes where

Everything below is what the app actually enforces, not a summary of intent. Where a table says a role does not hold something, the server refuses it — not just the screen.

A

The three roles

RoleCanCannot
Owner Everything. Every permission in the list below, always — including managing the team, and acting on other owners. Custom permission overrides are not applied to an owner at all. Change their own role. Remove or demote the last remaining owner.
Manager Everything an owner can, except manage the team: every read, edit and action, including seeing financial figures, running syncs, spending AI credits, buying labels, approving returns, managing the TikTok connection, the Shippo account and capture tokens, and changing their own password. Manage team members or permissions — so no Team & access card, no inviting, no removing, no password resets for other people.
Packer Exactly three things: view fulfillment and packing, buy and print shipping labels, and view orders. Everything else — including seeing any financial figure (order screens render for a packer with every money field blank), opening Settings at all, and changing their own password. Packer credentials are set by an owner.
A role is a starting point, not a cage Any permission below can be granted or denied per person from the matrix in step 08, within the two limits in step 11: you cannot grant what you do not hold, and owners cannot be trimmed.
B

Every permission, and what it depends on

These are the rows of the matrix, in the groups the screen shows them in. The third column is what must also be on — switch a prerequisite off and everything that needed it goes with it.

GroupPermissionRequires
Data accessView orders
Data accessView returns
Data accessView fulfillment & packing
Data accessView show detail
Data accessView costing workbench
Data accessView purchases
Data accessView reports & P&L
Data accessView customers & buyer historyView orders
Data accessView operating expensesShow financial figures
Data accessView settlements, payouts & reserve
FinancialShow financial figures (revenue, profit, margins, costs)
ActionsEdit line costs & cost catalogView costing workbench, Show financial figures
ActionsCreate & edit purchasesView purchases, Show financial figures
ActionsCreate & edit expensesView operating expenses, Show financial figures
ActionsApprove & reject returnsView returns
ActionsBuy & print shipping labelsView fulfillment & packing
ActionsRename & resolve showsView show detail
ActionsCorrect AI transcriptsView orders
ActionsRun AI transcription (spends credits)
ActionsTrigger TikTok sync & refresh
AccountChange own password
AccountManage capture tokens & TikTok connection
AccountManage team members & permissions
Why expenses are gated but purchases are not Most screens handle a member without financial figures by blanking the money and leaving the rest readable. An expense stripped of its amount is a date and a vendor and nothing else, so the whole screen is gated on financial figures instead of masked.
C

What a change here does elsewhere

What you changeWhat it affectsReversible?
Your own password Only your next sign-in. Nothing is signed out. Change it again.
Sign out a device That phone or tablet loses access immediately. No — sign in again on the device.
A member's role or permissions What they see and can do, everywhere, at once. Every browser session they have is deleted in the same operation. Yes — change it back. They stay signed out either way.
Show financial figures, off Revenue, profit, margins and costs disappear for that person across the whole app, and everything that requires it (cost, purchase and expense editing, the expenses screen) turns off with it. Yes.
Set a member's password Their password changes, every device of theirs is revoked, and every browser session is deleted. No — set another password.
Remove a member Access ends immediately; their role and custom permissions are gone. No. Re-adding creates a fresh membership at whatever role you pick.
Revoke an invitation Its link stops working. No — send a new invitation.
Resend an invitation A new link goes out and the previous one dies. No — the old link cannot be restored.
Revoke a capture token That browser stops recording LIVE video receipts. No — pair again or create a new token.
Shippo token Which Shippo account is quoted and charged, and whether the ship dock is spending real postage or test postage. Yes — paste a different token.
Sender address The return address printed on every label bought from now on, and whether labels can be bought at all. Yes — but labels already bought keep the old address.
Parcel presets The box choices offered when quoting a shipment, and therefore the rates quoted. Yes.
D

Tunable values that change what you see — and where they actually live

None of these are on this screen. They are platform settings, edited in a separate super-admin console with its own sign-in, and they apply to every workspace on the server. They are listed here because when a screen behaves in a way no seller setting explains, one of these is usually why.

SettingDefaultWhat it changes, and where
Stalled-parcel threshold4 days A parcel already handed to the carrier with no new scan for this long is flagged stalled — the badge on Fulfillment and the tracking timeline. Set above the carrier's normal quiet stretch, or ordinary ground parcels read as stalled.
Tracking poller interval15 minutes How often carrier scans are refreshed. Set to 0 and the Movement and Last update columns on Fulfillment go empty. Applies after a restart.
Margin-outlier floor10% product margin A costed line whose product margin falls below this is flagged in Costing. Below-cost selling is normal in clearance-heavy live selling, so a low or negative floor turns that from a queue into information.
Margin-outlier ceiling65% product margin A costed line above this is flagged in Costing. The high side catches data errors — a margin near 100% is usually a missing digit or a cost of zero.
Use known item weightsoff Buys labels at your own approved item weights rather than only TikTok's declared one. Changes what every label costs, so it is switched on deliberately once approved weights look right.
Look up unknown item weights with AIon Enables the Suggest weight buttons on Merchandise. On-demand only — nothing is looked up automatically, and no suggestion reaches a label until approved.
Monthly transcription cap5,000 per workspace per month How many AI transcriptions one workspace may run in a calendar month, and the figure behind the used/remaining credit display. 0 stops new transcriptions.
Correct misheard names as they arriveon Asks the name-cleanup model whether an unrecognised brand or product name is a mishearing of one you already sell. Corrections are reviewable name fixes.
Background auto-sync interval15 minutes (0 disables) A floor under the webhook triggers. Applies after a restart — see the note below about how syncs actually start here.
Break-detect sensitivity / base idle threshold500% of pace / 5 minutes When the packing timer asks "still packing?" — the gap that triggers the prompt, and the floor used before there are enough packs to know your pace.
Trend volume floor20 packages A packing day below this still appears in history but is greyed out and left out of the trend line and the average.
Error-log retention30 days resolved / 90 days quiet How long the Error log keeps a resolved error, and how long an unresolved one that has stopped recurring survives. An error that keeps happening resets its own clock and is never aged out while active.
How a sync actually starts Three ways, and only three: the Sync now indicator in the sidebar; a TikTok event push, which starts a sync after a short quiet period so a burst of pushes does not become a burst of syncs; and the background scheduler, which only exists when its interval is above zero — and on this deployment it is set to zero, which makes event pushes the only automatic trigger.
E

What is not set here — and where it is

ThingWhere it lives
Connecting or re-authorizing your TikTok shop The Connect TikTok / Reconnect TikTok button in the Dashboard header, which sends you to TikTok's own authorize page. Only the outcome lands back on Settings. The pill beside it also warns when TikTok says the authorization is expiring, or that the app was deauthorized.
Which events TikTok pushes to us Registered against the push URL in TikTok Partner Center — not in this app.
The push URL's secret, and every platform tunable in table D The super-admin console, a separate sign-in. Nothing in this workspace's Settings reaches it.
A listing's price, and its declared package weight and dimensions Set on TikTok. SellerFolio imports them after each order sync and never writes anything back to a listing.
Fees, payouts, reserve and bank details TikTok's. The app only ever reads statements and settlements; there is no path from here that changes them.
Running a sync The freshness indicator in the sidebar.
Last

Habits worth keeping

01

Trim permissions before you reach for Remove

Removing is permanent and takes their custom permissions with it. Turning access down is reversible and does the same job for someone who is away, on notice, or between shifts.

02

Tell someone before you change their access

Role and permission saves sign that person out mid-task with no warning at their end. Ten seconds of notice turns "the app broke" into "I know why".

03

Read the pending invitations list before you re-invite

A resend kills the link already out. If someone is halfway through accepting, an impatient second click is what breaks their link.

04

Prove the Shippo setup in test mode first

Sender address and parcel presets are cheap to get wrong and expensive to discover live. A test token produces a label that looks exactly right and costs nothing.

05

Check the capture pill on the machine that will run the LIVE

It is per-browser. The only status that matters is the one on the laptop that will actually be broadcasting, checked before the show rather than after it.

06

Prune access tokens you no longer recognise

Last used is the tell. A token nobody has touched in months is a live key to your workspace's capture endpoint with no owner — revoke it, and re-pair the machine if it turns out to matter.