Use the Right Admin Surface
Arcus separates organization-level controls from entity-level settings. This keeps company access, billing limits, and entity creation separate from daily operating settings like shipping, tax, users, products, and documents.- Organization Overview: review the current plan, usage, and enabled features.
- Entities: create sandbox or production entities and deactivate or reactivate existing entities.
- Organization Users: invite people and assign them to one or more entities.
- Roles and Entity Team: tune what users can do inside an entity.
- API Keys: create personal entity-scoped tokens for scripts that act as your user.
- Developers: manage shared entity API keys, webhooks, logs, analytics, collections, docs links, and SDK links when your role allows it.
Review the Organization Overview
In the deck, choose Organization, then Overview. The overview shows the current plan, subscription status, feature badges, and usage against limits such as entities, users, and products. Each usage bar reads “used / limit” with how many are left, and At limit when the limit is reached. Upgrade Plan opens Choose Your Plan; only the organization owner can change the plan, and on a complimentary beta plan the page reminds you that you will never be charged without advance notice.
Use the organization overview to see plan status and whether entity, user, or product usage is near a limit.
Manage Entities
Where: Organization > Entities An entity is a separate operating company or environment inside the same organization. Each entity has its own customers, products, inventory, accounting, documents, settings, and user memberships. Company data never crosses entities or organizations: no administrative tool, even for an owner of one company, can read or change another company’s records. The page is titled Entities with “Manage the business entities in your organization.” Four tiles count the whole organization and each one filters the list when selected: Total Entities, Live, Sandbox, and Pending Deletion. The search box finds an entity by name or code, and two filters narrow the list: All environments, Live, or Sandbox, and All statuses, Active, Inactive, or Pending deletion. With no match the page shows No entities match your filters with a Clear filters button, and with no entities at all it shows No entities yet with “Create your first entity to get started.” If the list cannot be read you see Could not load entities and Try again.
The Entities page shows each entity, its environment, active status, member count, and location count.
- Production: live operating data. Use this for real orders, payments, labels, inventory, and accounting.
- Sandbox: test and training data. Use this before changing a production process.
- Active: users with membership can enter the entity.
- Inactive: the entity is no longer available for normal work, but its record remains in the organization.
Create an Entity
Use Create Entity only when the business truly needs a separate company, separate sandbox, or separate live environment. If you only need a warehouse, store, ship-from address, or receiving location, create a location instead.
Create Entity asks for a name and an environment before Arcus creates the new entity.
- In the deck, choose Organization, then Entities.
- Select Create Entity.
- Enter a clear Entity Name, for example “Acme Distribution”. Arcus assigns the short entity code shown on the tile.
- Choose Production (LIVE) or Sandbox (SB) under Environment.
- Select Create. You see “Entity created”, and the new tile appears. Create stays unavailable until the name is filled in.
- Invite or assign the users who should access the new entity.
- Complete the entity setup checklist before using it for live work.
Deactivate or Reactivate an Entity
Deactivation is an access and operating-control action. It is not a cleanup shortcut. Use it when an entity should no longer be used for normal work, such as an old sandbox, a retired division, or a duplicate entity created during setup.- Confirm no team is actively using the entity.
- Review open orders, open POs, unpaid bills, unposted accounting work, and active integrations.
- Export or archive required reports before removing day-to-day access.
- Tell users which entity replaces it, if any.
- Reactivate only after confirming why the entity was disabled.
Delete an Entity or Close the Organization
Entity deletion and organization closure are primary-owner actions. Use them only after deactivation, review, and internal approval.- Delete appears only for inactive entities and only to the organization’s primary owner. It opens Delete Entity in two steps. Review shows the rows that will be removed, the connector secrets that will be deleted, any sandbox children that go with it, and Per-table row counts. Confirm asks you to type the confirmation phrase shown, with an optional reason, and then Schedule Deletion with the length of the cooling-off window.
- Pending Deletion means deletion has been scheduled. The entity is frozen during the cooling-off window and nothing is deleted automatically. Cancel Deletion at any time in the window makes the entity active again, with “Deletion of” the code “cancelled. The entity is active again.”
- When the cooling-off window ends, the tile reads that cooling-off ended and the entity is not deleted automatically. Delete Now opens Permanently delete this entity?, which says it cannot be undone and affects only this entity, then asks you to verify it is you with a second factor (see below). The deletion then runs in the background and can take up to about an hour for a very large entity.
- Stop Deletion while it runs asks “Stop background deletion?” and warns that rows already deleted cannot be recovered. If a run fails, the tile shows the failure and Revive Entity brings the entity back.
- Deleting the last production entity removes only that entity and leaves the organization in place. To close everything, use Close Organization.
- Last active entity cannot be deactivated as a normal entity cleanup path. Arcus directs the primary owner toward the organization closure flow instead.
- Close Organization is the front-door action for closing the whole account, in the Danger Zone on Organization > Overview (primary owner only). It previews affected entities, users, rows, and connector secrets, then requires typing the organization’s exact name, a final acknowledgement, and a second-factor check. A brand-new organization (under 7 days old) closes immediately on confirmation, and an established one uses a 7-day grace window you can cancel with Cancel Closure.
- Transfer primary ownership, above Close Organization in the same Danger Zone, hands the single delete authority to another active Owner. Pick the person under Select the new primary owner, select Transfer, and verify with a second factor. When there is no other active Owner, the page says “No other active Owner to transfer to. Grant someone the Owner role first, then return here.”
- Pending Closure means the organization is scheduled for teardown. The primary owner can cancel closure while the cancel action remains available.
Verify It Is You
Deleting an entity, closing the organization, and transferring primary ownership ask for a second factor in a window titled “Verify it’s you” with the action named. Choose a method: the Authenticator code from your authenticator app, Email me a code (a one-time code goes to your masked email address, with Resend code), or Use security key. Only the methods you have set up and your organization allows are offered, and an email code is always available unless the organization requires a security key. Enter the 6-digit code and select Verify, which stays unavailable until all 6 digits are in. You may see “Verification failed.”, “Security key verification was cancelled.”, or “Could not send the code.”Use Personal API Keys Safely
Personal API keys let scripts authenticate to Arcus as your user for the current entity. They are useful for controlled reporting, scheduled imports, and operational automation, but they should be handled like passwords.
The API Keys page shows only safe key metadata. Arcus never shows the full token again after creation.
Create an API Key
- Open API Keys from the account or profile area.
- Select New key.
- Name the key after the script or job that will use it.
- Choose an expiration in days. Shorter is safer.
- Select only the scopes the script needs. Empty scopes mean unrestricted, so avoid leaving scopes empty unless there is a clear reason.
- Create the key.
- Copy the token immediately and store it in your secret manager.

Give each key a purpose-specific name, expiration, and narrow set of scopes.
API Key Safety Rules
- Use one key per script or integration job so it can be revoked without breaking unrelated work.
- Prefer scoped keys over unrestricted keys.
- Use expirations and rotate keys on a schedule.
- Revoke a key immediately if it may have been shared, copied into logs, or committed to code.
- Remove keys during offboarding or when a script is retired.
- Review last-used timestamps to find stale keys.
Common Blocks
- Create Entity is blocked: check your organization role and plan entity limit.
- Sandbox setup is refused: a sandbox can only be created under the company you are signed in to. Switch to the right company first.
- Delete Now does nothing until you verify: the second-factor window must be completed within a few minutes. Start again if it expired (“This verification expired or was already used. Start again.”).
- A user cannot see a new entity: add the user to the entity from Organization Users and confirm their role.
- An entity is missing from the selector: confirm it is active and the user has an active membership.
- Delete is missing on an entity tile: confirm the entity is inactive and you are the organization’s primary owner.
- Close Organization is missing: only the primary owner sees the organization closure danger-zone control.
- API Keys page is unavailable: your role may not include personal API key management or API Access may not be enabled.
- Scope cannot be selected: your user must already have that permission before a key can receive it.
- Script stopped working: check expiration, revoked status, entity context, and whether your role or scopes changed.

