Skip to main content
Checked against the product · 2026-10-05

Monitoring, Sync and Audit — Admin Guide

Four Admin tabs answer a different question from the rest of the platform. They do not tell you what your numbers are — they tell you whether the numbers you are looking at are current and true: Operational Health, System Health, Data Sync, and Audit Log.

The distinction worth carrying: Operational Health is about your data, System Health is about the machine. A perfectly healthy machine will happily serve you numbers from a feed that stopped running last Tuesday.

For: administrators · Time: ~10 minutes, then about ninety seconds a day · You'll need: access in your company's permission matrix (Admin → Permissions) — the Admin Console row System Status opens Operational Health and System Health, and the Data Sync row opens Data Sync — plus the admin or CEO role for Audit Log. Apart from Trigger Sync, nothing on these four tabs changes your data.

How to access​

Admin — Operational Health is the tab you land on. System Health, Data Sync and Audit Log are in the same list.


The health strip above every Admin screen​

For a role that can read the configuration checks, every Admin screen carries the same strip above the section list, so it follows you from tab to tab. It is not the Operational Health banner, which grades your feeds: this one lists what needs attention in your own setup. It reads All checks passed in green, or N warnings found in amber, which opens to the list.

Two kinds of warning appear there:

  • Configuration gaps. Each says what is wrong and how many items it affects, and links straight to the screen that fixes it. Follow the link rather than hunting for the setting.
  • Scheduled jobs your books depend on that have gone too long without a successful run. Each names the job, the time since its last success and the threshold, for example Timecard ingest (daily): last successful run 31h ago (threshold 25h), or says no successful run on record. The daily jobs warn after 25 hours; the Gmail invoice poller after 30 minutes. Only jobs that do work for your company are listed: the ERP sync row is your own nightly sync, and Timecard ingest (daily) appears only while your timecards still arrive from a previous timekeeping system.

For a stale ERP sync, start at Data Sync (section 3). Any other stale job is Arcvue's to restart, not a setting: its link opens System Health, but report the warning to support with the time it first appeared.

Health checks could not be loaded, so this is not an all-clear means the request failed rather than came back empty. It tells you nothing about your setup; the strip tries again when you return to the tab or the window.


1. Operational Health — the daily glance​

Admin → Operational Health (the default tab)

One banner across the top and a grid of status tiles beneath it, grouped into Platform, Bookkeeper / Accounting, and NEO / BD.

The banner is the whole page in one line, and it has three states:

BannerMeans
All systems operationalEvery feed is current
Attention — a feed is stale or warningNothing has failed, but something has stopped being current
ACTION REQUIRED — a feed is failing or errored in the last 24hSomething is broken now

The middle state is the one that earns this page its keep. Green means current, not merely "no errors". A feed that simply stopped running raises no error anywhere — it just quietly keeps serving you last week's answer — and amber is how you find out. Treat amber as a real result, not a soft green.

The tiles​

Platform carries DB integrity, which reads all OK, unknown, or a count of corrupt databases, with the time it was last checked.

Bookkeeper / Accounting carries a sync tile for the accounting system your books are brought in from (it is named for that system), Last correction, and Errors (24h). Last correction reads green with no corrections recorded yet until someone first corrects the Bookkeeper, and turns yellow once the newest correction is more than a week old.

NEO / BD carries a tile per opportunity source, a per-division breakdown, and Team triage (7d) — decisions made in the last week.

A tile appears only when it can tell you something. A feed or opportunity source that has never run, or that is switched off for your company, is left off the page rather than shown red, and adds nothing to the banner; one that ran and then broke still raises. A company that has been deactivated raises nothing.

Most tiles are links, and they go to the page that fixes them. The sync tile opens Data Sync; the NEO tiles open NEO. Errors (24h) becomes a link only when the count is above zero — so if it is not clickable, there is nothing to go and look at.


2. System Health — is the machine alive​

Admin → System Health

Four figures — Overall, Database (Healthy or Error), Disk Usage, Uptime — plus a Health Checks list where each check shows its name, a pass/fail mark and a short detail.

This is the tab to open when the platform itself feels wrong: pages slow, an upload failing, a report timing out. It is not the tab that tells you whether your accounting data is current — that is Operational Health above.

"Health check unavailable" means the check itself could not be retrieved. Read that as unknown, not as healthy.


Previous runs​

Under the latest OCE run, Previous runs opens the runs before it from the last 30 days, newest first, with When, Status, Fails, Warnings and Runtime per run. It tells you whether a red run is a new condition or a standing one without re-running anything; a missing run where you expected one means the sync did not fire that day.

API health​

API health reads the live request window the server keeps: Requests, the request-weighted Error rate and the Slowest p95 latency across every path, then the paths ranked by error rate with Path, Requests, Errors and p95. A banner names any path at or over 5% errors on 20 or more requests -- the server's own alerting rule. No requests in the last 5 minutes is a real reading on a quiet system, not a failure; a failed read says Failed to load API health. Use it to separate a platform problem from a data problem before you open the books.

3. Data Sync — did the feed actually run, and can it connect at all​

Admin → Data Sync

A history table of every sync run — Date, Status, Duration, Tables Synced — with a count of runs recorded above it. On a new tenant it reads "No sync history", and says sync history appears after the first ERP sync run.

Pre-flight Check is the useful button on this page​

Pre-flight Check runs a real connection test against your ERP without changing anything, and returns a Pre-flight manifest:

Manifest lineWhat it tells you
StatusWhether the connection succeeded
AdapterWhich ERP adapter is configured
ERP versionThe version it found
Tables visibleHow many tables the connection can actually see
Blocking issuesListed in red — these stop a sync
WarningsListed in amber — a sync will run, but read them

This is how you separate the two failures that look identical from the outside: "the connection is broken" and "the connection is fine and there is nothing new." A successful pre-flight with zero blocking issues, next to a sync history that has not advanced, points at the schedule or at an empty source — not at the connection. Run it first, before anything else on this page.

A blocking issue is the answer, not a symptom. Work the list; each entry names what is stopping the sync.

The panel is headed Data Sync History and states how many runs it is showing, so a short list is a fact about how much has run, not a truncated view. Dismiss closes the pre-flight manifest — it dismisses the PANEL, not the run — so nothing is canceled by clearing it away.

About the Trigger Sync button​

Trigger Sync starts a real run. It reports the process it began — "Sync started for {tenant} (pid {n})" — and then reloads the history table beneath it, so the proof arrives on screen instead of being something you take on trust. A new row in the history table is still the durable evidence a run occurred, and that is what the confirmation points you at.

Setup & Repair → Manual Sync, behind maintenance mode, starts the same run — the two buttons call one sync (see Period Locks and Maintenance Tools). Either is refused while a budget year is locked, because a sync would overwrite the frozen budget; the message names the locked year and who locked it, and the remedy is to unlock the budget first.

Pre-flight Check and Trigger Sync appear only for a role with read-write access on the Data Sync row of your permission matrix. A role with read-only access there sees the history without either button.


4. Audit Log — who changed what, when​

Admin → Audit Log

Admin activity, newest first: Timestamp (UTC), User, Action, Details, IP. The header states plainly how many rows you are seeing out of how many exist. What lands here: every change made in the Admin console — users and permissions, configuration values, GL mapping, cost pools, exclusions, covenant scope, forecast parameters, email routing, the year rollover, AI keys, the invoice logo — each written in the same transaction as the change it records, so the log cannot claim something that rolled back and a change cannot land unrecorded.

ControlUse
Filter by userOne person's activity
Filter by action (substring)A kind of change — partial words work
Date rangeNarrow to a window
CSV exportDownload the complete filtered log, not just the screen

The export is complete or it is not written. It pages through every entry matching your filters — not the 100 the screen happens to be showing — so a single click gives you the whole filtered log. There is no slicing to do.

The screen and the file are different things, deliberately. The table shows the latest 100 entries because it is a screen, not a record; the header tells you the true total beside it. The CSV ignores that limit entirely.

Above 50,000 rows the export refuses rather than writing a partial file, and says so. That is the one case where you narrow the filters — by user, by action, or by date window — and it tells you when you are in it. A file that would have been incomplete is never produced, so an export you receive is one you can hand over.


5. Bookkeeper Intelligence — retired​

This page charted how often the Bookkeeper agreed with the previous system's ledger. That comparison ended with the parallel run: the previous system is no longer the book, so agreement with it stops being a measure of anything. The page, its route and its numbers were removed on 2026-09-06. What the Bookkeeper did with each item is still on the item itself, in the Bookkeeper queue and the escalation record.

6. A ninety-second daily routine​

  1. Operational Health — read the banner. Green, move on.
  2. Amber or red — open the tile that caused it; it links to the page that fixes it.
  3. If the sync tile is the culprit, Data Sync → Pre-flight Check before assuming anything about the connection.
  4. The health strip above the sections — All checks passed, move on; otherwise open it and work the list.
  5. System Health only when the platform itself feels wrong.
  6. Audit Log when you need to know who did something — not on a schedule.

7. When something looks wrong​

"The banner is amber but nothing is broken." Something has gone stale rather than failed. That is exactly what amber is for — find the tile and check when it last ran.

"DB integrity says unknown." The check has not produced a result. Unknown is not OK; look at System Health next.

"Sync history has not moved in days but Pre-flight passes." The connection is healthy, so the problem is the schedule or an empty source — not the ERP credentials.

"I clicked Trigger Sync and no new row appeared." Starting a run is not finishing one: the confirmation names the process it began, and the row appears in the history once that run records itself. If the button was refused instead, the message says why — most often a locked budget year.

"I cannot see Pre-flight Check or Trigger Sync." Your role has read-only access on the Data Sync row of the permission matrix. The history is yours to read; running either needs read-write there.

"My CSV export is missing entries." It contains everything matching your filters, not just the screen — so check the filters first. The one hard stop is 50,000 rows, and there the export refuses outright rather than writing a short file, so a file you received is not a truncated one.

"Errors (24h) isn't clickable." The count is zero. There is nothing to open.

"Health check unavailable." Treat it as unknown rather than healthy, and check whether the platform is otherwise responding.


One-line summary​

Operational Health is your daily glance and its amber state — stale, not broken — is the reason to read it, because green means current, not error-free. System Health answers whether the machine is alive, which is a different question. On Data Sync, Pre-flight Check is the diagnostic that separates a broken connection from an empty one, and a new row in the history table is the only proof a sync ran — on-demand syncs live on Setup & Repair, not here. On Audit Log, the CSV exports the complete filtered log, not the 100 rows on screen — it is safe to hand to an auditor, because above 50,000 rows it refuses rather than writing a partial file.