Organization profile
From Settings → Organization, you can manage:- Organization name — Your team or company name
- Contact information — Primary email and phone
- Billing — Payment method and subscription details
Member management
Viewing members
The organization settings page shows all current members with their:- Name and email
- Role (Owner, Admin, Member)
- Artist access (which artists they can manage)
- Tour access (which tours they can view)
- Last active date
Roles and permissions
Inviting new members
- Click Invite Member
- Enter their email address
- Select their role
- (For Members) Assign artist and tour access
- Send the invitation
Modifying access
- Change role — Promote a Member to Admin, or adjust any role
- Update artist/tour access — Expand or restrict which artists and tours a Member can see
- Remove a member — Revoke all access immediately
Transferring ownership
The Owner role can be transferred to another Admin or Member:- Go to organization settings
- Select the member to transfer to
- Confirm the transfer
Security
Two-factor authentication (2FA)
Enable 2FA for your account to add an extra layer of security. When enabled, you’ll need a verification code from your authenticator app in addition to your password.Passkeys
Fanhaven supports passkeys — a passwordless authentication method using biometrics (Face ID, fingerprint) or a security key. Passkeys are more secure and more convenient than passwords.Audit log
The Audit Log (under Settings) tracks every significant action in your organization:- Member invitations, role changes, removals, and ownership transfers
- API key and webhook endpoint changes
- Tour and event creation/modification
- Financial actions (sales, refunds, payouts, settlements, cash drawer counts)
- POS activity (staff logins, device pairing, inventory counts)
- Integration connections and disconnections
The audit log is immutable — entries cannot be edited or deleted, and history is preserved even if the tour it relates to is later deleted. This provides a reliable record for accountability and compliance.
Best practices
- Use the principle of least privilege — Give members only the access they need
- Enable 2FA — Especially for Owner and Admin accounts
- Review access quarterly — Remove members who no longer need access
- Monitor the audit log — Check for unexpected activity periodically

