Back-office access (email sign-in)
BlueSage staff see every organization and can do everything here. One organization scopes the account to that org alone — its dashboard, transactions, events, locations and devices, and nothing else. A scoped user cannot see this page, cannot create or delete organizations, and cannot rotate credentials, so they can neither widen their own access nor remove yours.
Sign-in codes are single-use, expire in 10 minutes, and only work in the browser that requested them (a relayed/phished code fails). A single staff address is the safest configuration: it cannot remove itself and it cannot be removed as the last one, so nobody can take it away. A second staff address buys mailbox redundancy but makes each removable by the other — add one only if you want that trade. Scoped users never affect this either way; they cannot see this page. Password sign-in disables automatically while this list is active; the break-glass, for a dead mailbox or any other way in, is ADMIN_FORCE_PASSWORD=1 in the server env + restart (requires server access, by design).