A customer-side control plane for field communication
The PTTHex Customer Panel is the local authority for users, devices, channels, policy, admission, telemetry, dispatch, notifications, and operator workflows inside the signed customer license boundary.
Manage the operating model
Define who can use PTTHex, which devices are approved, and which channels, roles, and policies shape daily work.
What the Customer Panel manages
The panel keeps customer-side administration, operator visibility, and product policy separate from the Client app and the voice media service that carries live audio.
Organization structure
Model branches, departments, groups, users, devices, and channels so communication matches real responsibilities.
User and device approval
Client self-registration stays pending until Customer Admin approval. Disabled, rejected, expired, or missing-policy states fail closed.
Roles and permissions
Customer roles remain license-scoped and can support owner, security, dispatcher, branch, department, auditor, and operator responsibilities.
Channel and admission policy
Channel updates and live voice access stay tied to current membership, device approval, platform state, and policy checks.
Dispatch and map readiness
Dispatch workflows can cover local map readiness, telemetry policy, SOS routing, presence, device health, geofence policy, and aggregate reporting where licensed and approved.
Status and observability
Operator surfaces are designed to expose redacted status, readiness, and audit context without publishing raw logs, secrets, credentials, internal paths, or sensitive payloads.
Messaging, notices and broadcasts
Manage direct and channel messages, quick notices from a prepared set, and broadcasts. Delivery is tracked honestly through queued, sent, delivered, failed, and retrying, and a failed message is retried within policy rather than reported delivered.
Notifications policy and delivery
Administer providers, push devices, audience segments, and dispatch routing with credentials brokered and device tokens kept as opaque references. Emergency notifications take precedence over all others and cannot be silenced by preferences.
Voice, PTT and calling
Govern push-to-talk channels with admission and emergency preemption, plus the internal and external dialer. Policy and fraud checks can deny a call before it connects, and call history is kept without raw audio.
Zones and geofences
Define map zones, zone rules, and geofences bound to self-hosted map data. Entry and exit apply policy with explainable denials, and rules are versioned and rolled back rather than destructively deleted.
Translation and assistant policy
Set the self-hosted assistant, live translation, captions, and transcription policy. Every workflow is consent-gated and quota-metered within a signed entitlement, and raw audio is not retained.
Capacity and licensing
Work within a cryptographically signed capacity license that sets ceilings for users, devices, channels, departments, simultaneous speakers, and concurrent sessions. Local administration can narrow these limits but never expand them.
Reports built for review and export
The reports area gives managers a redacted, policy-bound view of operations. Every export is redacted and secret-free, and each report names the source revision it was built from so a stale source is never treated as fresh.
Overview
A filtered summary of customer-local activity across users, devices, channels, and dispatch.
Usage
Voice, calling, and channel usage within the signed license, paginated and streamed for large datasets.
Availability
Service availability with degraded windows surfaced honestly rather than smoothed over.
Incidents
Correlated, prioritized incident records drawn from an immutable, redacted timeline.
Compliance
Versioned policies, consent and retention enforcement, and a redacted evidence pack for review.
Exports
Downloadable outputs that stay redacted and within retention and license policy at all times.
Audit
An immutable, redacted record of admin actions, scoped to the customer's own license.
A dashboard that tells the truth
The panel dashboard shows real, customer-local status for license, devices, channels, dispatch, incidents, capacity, and readiness. A signal is marked healthy only when its state is genuinely live. Delayed, stale, unknown, degraded, offline, and maintenance states are shown as exactly that, so there is no false healthy.
- Managers see the true state of their own deployment, not an optimistic summary.
- Stale positions and unhealthy devices are marked, and clustering never hides an active SOS.
- Only redacted status summaries are shared upward, keeping raw data on the customer's server.
No false healthy
When a device stops reporting or a session degrades, the panel says so. Honest signals let dispatchers act on what is really happening in the field instead of trusting a green light that no longer reflects reality.
Customer-controlled authority
Managers administer everything on their own server. Local grants can narrow the licensed authority but never expand it, and every change is versioned and reversible with an immutable audit trail. The panel prefers disable, archive, and rollback over destructive deletion, so operations stay under local control without ever rewriting what the license signed.
Designed for customer-controlled operation
The Customer Panel runs on your own server. It uses a signed license, sign-in only with no public account signup, local maps, protected storage for sensitive data, and status views that keep private details out of sight.
- Checks its own license and stops rather than opening access when a check does not pass.
- Keeps sensitive data, secrets, and customer information out of anything shown publicly.
- Uses maps, monitoring, and reporting only within the policy and privacy scope you approve.
Prepare for a panel walkthrough
Share branches, departments, roles, user groups, device approval needs, channel structure, dispatch workflows, reporting needs, and deployment expectations.