Skip to content

Settings: Mail, Backup & Directory ​

This guide covers the three infrastructure screens under Settings → General: how GoldServe sends email, how backup health is monitored, and how GoldServe connects to an existing directory service.


Purpose ​

This answers: "How does the system actually send mail, what happens to our data if something goes wrong, and where do user accounts come from?"


Mail Server ​

Settings → General → Mail Server lists the configured outgoing mail servers and lets you add more. GoldServe sends a lot of its own email — notifications, portal invites, offer letters, payslips, ticket updates — and all of it goes out through one of these.

What a configuration holds ​

FieldNotes
Email HostThe mail server address.
Email PortThe port it listens on.
Default From EmailThe address mail appears to come from.
Email Host UsernameThe account used to authenticate.
Email Authentication PasswordThat account's password.
Display NameThe name shown beside the from address.
Use TLS / Use SSLThe encryption method. These are mutually exclusive — setting both is refused.
Fail SilentlyWhether a send failure is swallowed instead of raising an error.
Email Send Timeout (seconds)How long to wait before giving up on a send.
Primary Mail ServerMarks this as the system-wide fallback.
Dynamic display nameWhen on, the display name is taken from whoever triggered the mail rather than from the fixed Display Name.
CompanyThe company this configuration serves.

How the right server is chosen ​

  • Each company can have one configuration of its own. If a second one is saved for a company that already has one, the new one is discarded immediately and the existing one stays in place — so edit the existing configuration rather than adding another.
  • Exactly one configuration is the primary. Marking a new one as primary automatically clears the flag from the previous one, and the very first configuration created becomes primary whether or not it was ticked.
  • A configuration that is not primary must name a company. The primary one may stand alone and serve everything else.

Testing ​

Each configuration can send a test email to an address of your choosing. The test message carries the company's own name and logo when white-labelling is on, so it also confirms branding is resolving correctly. Send one before relying on a new configuration.

Outlook Mail (the alternative) ​

When the Microsoft 365 / Outlook module is installed, the Mail Server entry is replaced in the menu by Outlook Mail, and system mail goes out through a connected Microsoft account instead of an SMTP server. It is an either/or choice, not an addition — the two do not run side by side.

The full setup, including the Azure app registration behind it, is a deployment task — ask your operations team.


Backup Status ​

Settings → General → Backup Status is a read-only monitoring page. Backups themselves are run and configured by the operations team outside the application: schedules, destinations, encryption keys, and credentials are not editable here, by anyone.

The page shows:

  • A health badge — Healthy, Warning, Critical (stale), or Disabled. The warning appears once the last successful backup passes 23 hours old, and it turns critical past 25 hours, or when there has never been a successful one.
  • The last complete recovery point — when it finished, and its backup ID. A recovery point counts as complete only after both storage destinations verify their copy.
  • The nightly schedule and time zone the worker runs on.
  • The last 20 runs, each with its start time, backup ID, status, retention class, the status at each destination, and how long it took.

A backup covers the database and the uploaded files together, so a recovery point is a full restore point rather than just the records.

What happens behind this page — encryption, destinations, retention, and the restore procedure itself — is operations territory, documented with your deployment rather than here.


LDAP Configuration ​

Settings → General → LDAP Configuration holds the connection to an existing directory service, such as Active Directory or OpenLDAP:

FieldNotes
LDAP serverThe server address and port.
Bind DNThe account GoldServe connects as.
Bind passwordThat account's password.
Base DNWhere in the directory to look for users.

With the connection saved, users can be imported from the directory into GoldServe, or GoldServe accounts exported back into it. Those runs are started from the command line by an administrator, not from this screen.

The menu entry only exists when the LDAP module is installed. The full setup — standing up a directory from scratch, or connecting a Microsoft one — sits outside this screen and outside this guide.


What Each User Sees ​

ActionEmployeeReporting ManagerHR Administrator
Configure the mail server or Outlook connection——✅
Send a test email——✅
View backup status——✅
Change backup schedules or credentials———
Configure the LDAP connection——✅

How Visibility Is Decided ​

  1. Permissions. Mail configuration, backup status, and LDAP settings each need their own permission.
  2. Installed modules. The Outlook entry replaces the Mail Server entry when the Outlook module is installed; the LDAP entry only appears when the LDAP module is installed.
  3. Nobody can change backup configuration from the application — that is a deployment-level control, not a permission that can be granted.

Customization Options ​

  • Mail delivery — an SMTP server per company plus a system-wide primary, or a connected Outlook account.
  • Display name behaviour — fixed per configuration, or taken from whoever triggered the mail.
  • LDAP connection — server, bind account, and search base.

Good to Know ​

  • Mail server and Outlook are alternatives, not both at once. Enabling one replaces the other for sending system mail.
  • The primary configuration is the safety net. Mail for a company with no configuration of its own goes out through the primary, which is why one always exists.
  • Test before trusting. A wrong port or the wrong TLS/SSL choice fails silently in ordinary use if Fail Silently is on. The test email is the quickest way to catch that.
  • Backup credentials and schedules are operations-managed. The page reports; it does not control.
  • These are infrastructure settings, closer to deployment configuration than to HR administration. If a value here needs changing and you are not sure what it should be, that is a question for whoever runs the deployment.