Skip to content

Administrator Guide

This guide is intended for Enterprise Administrators who manage Treasure AI Voice deployments across their organization. It covers authentication, device management, user management, and security features.

Initial Setup

Before you can access the Admin Dashboard, your organization must be activated. Treasure AI will send you an invitation link — follow the steps in Organization Activation to complete the one-time setup.

Use a separate browser for each email address

If the same person uses more than one email address, activate each email address in a different browser. If one of those accounts is the organization owner, complete the organization activation afterward in a different browser from the one used for email activation. Using the same browser can create an unintended relationship between the email address and organization.

Web Admin Dashboard

The Web Admin Dashboard provides centralized management of your organization's Treasure AI Voice deployment.

RegionURL
Japan (AP01)voice-console.ap01.treasure.ai

Dashboard Menu

  • Devices — View and manage all PLAUD devices and their assigned users.
  • Recordings — Browse, review, and delete recordings.
  • Audit Logs — View a complete audit trail of all activity.
  • Members — Manage users — invite, remove, and assign roles.
  • AI Lens (optional) — AI-powered analytics and insights.
  • Export (optional) — Configure manual and recurring exports of recordings, transcripts, summaries, and device inventory to your Treasure Data CDP.
  • Legal — Access Treasure Data's Terms of Service, privacy statement, and other legal documents.

Authentication

Treasure AI Voice supports two authentication methods:

MethodDescription
Sign in with GoogleAuthenticate using your organization's Google Workspace account.
Email / PasswordSign in with credentials provided by your administrator.

Supported identity providers

Direct integrations with SAML 2.0, Microsoft Entra ID (Azure AD), Okta, and other enterprise identity providers are not currently supported. The only built-in social identity provider is Google.

For the time being, organizations that gate Google Workspace sign-in through their corporate IdP can use Sign in with Google to inherit that gate at authentication time. This only affects new sign-ins — it does not terminate active sessions or remove the Treasure AI Voice user record when you deprovision the user upstream. To fully revoke access, an Enterprise Admin must also remove the user from the Members page.

Devices

The Devices page (also called Device Fleet) provides a real-time overview of all PLAUD devices deployed across your organization.

Device Fleet page listing PLAUD devices by serial number with owner, battery, last sync, firmware, and lock status

Fleet Summary

At the top of the page, summary cards display:

  • Total Devices: Total number of devices registered to your organization.
  • Active: Devices that are currently active and operational.
  • Locked: Devices that have been remotely locked by an administrator.
  • Low Battery: Devices reporting low battery levels.

Device List

Devices are grouped by assigned user (name and email). Each device row displays:

ColumnDescription
SerialThe unique serial number of the device.
BatteryCurrent battery level percentage, or "Unreachable" if the device has not synced recently.
Last SyncHow long ago the device last synced with the mobile app.
FirmwareThe firmware version currently installed on the device.
StatusCurrent device status (Active, Locked).
ActionsLock or unlock the device remotely.

Locking a Device

If a device is lost or stolen, you can remotely lock it:

  1. Navigate to Devices.
  2. Locate the device by serial number or assigned user.
  3. Click the Lock button in the Actions column.
  4. The device status will change to Locked. The action is recorded in the audit log.
Software Lock, Not a Hardware Lock

Locking a device doesn't disable the hardware itself — it locks the device's account and connection in software. If a locked device is later recovered, an Enterprise Admin must unlock it (from the Devices page) before it can be used again.

Recordings

The Recordings page displays all transcriptions from organization members.

Recordings page listing organization recordings with user, device, duration, recorded date, and status

Use the search bar to find recordings by user email or name. Each recording row displays:

ColumnDescription
MeetingRecording title and a preview of the transcription content. Click the play button to listen.
UserName and email of the user who created the recording.
DeviceSerial number of the PLAUD device used for the recording.
DurationLength of the recording.
RecordedDate and time the recording was captured.
StatusProcessing status (e.g., Completed).
ActionsDelete the recording.

Click a row to open the recording's detail view, where you can view and copy the transcript, summary, action items, and Key Topics (tags). Enterprise Admins can also edit tags directly from this view — see Key Topics (Tags) in the User Guide.

Filtering by Tag

Click any tag chip in the Recordings list to filter it down to recordings carrying that tag. The filter operates across the entire organization's recording set, not just the current page.

Audit Logs

The Audit Logs page provides a complete audit trail of all activity on the platform. Logs are retained for 7 years.

Audit Logs page showing device serial, event type, actor, and timestamp for each recorded action

Each log entry displays:

ColumnDescription
Device SerialSerial number of the related device (if applicable).
Event TypeType of event — see the Event Types reference below.
DetailsAdditional context for the event (if available).
ActorEmail address of the user who performed the action.
TimestampWhen the event occurred.

Filtering

Narrow the log using the filters above the table — by date range, event type, and user — so you can answer an audit or compliance question on demand, such as everything a specific user did in a given period, or every occurrence of a single event type across the organization.

Event Types

The audit log tracks the following events, grouped by category:

Identity & access

EventDescription
User LoginA user signed in successfully.
User LogoutA user signed out.
User InvitedAn Enterprise Admin invited a new user. Details include the invited email and assigned role.
User Accepted InviteAn invited user completed account setup.
User Accepted TermsA user accepted the in-app Terms of Service.
User DeactivatedA user account was deactivated.
User RemovedA user was removed from the organization. Details include the removed user's email and prior role.
Role ChangedA user's role was updated.

Device lifecycle

EventDescription
Device ProvisionedA device was added to the organization's inventory. Details include the provisioning source and firmware version.
Device AssignedA device was assigned to a specific user.
Device BoundA user paired the device with their mobile app. If the device was not previously provisioned, this event also triggers auto-provisioning.
Device UnboundA device was unbound from a user account.
Device DepairedA device was forcibly de-paired (for example, by Enterprise Admin action).
Device LockedA device was remotely locked by an Enterprise Admin.
Device UnlockedA previously locked device was unlocked.
Device HeartbeatA device reported its health status. The dashboard only surfaces heartbeat events that include a low battery alert.
Firmware UpdatedA device's firmware version changed.

Recording lifecycle

EventDescription
Recording CreatedA new recording was uploaded and persisted.
Recording TranscribedTranscription and AI summarization completed successfully.
Recording FailedProcessing failed. Details include the failure reason — for example, TRANSCRIBE_JOB_FAILED or PROCESSING_ERROR.
Recording DeletedA recording was deleted from cloud storage. Details include the recording file name.

Treasure Data CDP export

EventDescription
TD CDP ExportA manual or scheduled CDP export reached a terminal state. Details include the run ID, status, destination database, row counts, and export scope.
TD CDP Export Settings UpdatedThe CDP export destination or other export settings were changed.
TD CDP Export Key SetA write-only API key was added or replaced. The key itself is never recorded.
TD CDP Export Key RemovedThe saved write-only API key was removed.

Members

The Members page allows you to manage users and team assignments.

Members page showing name, email, role, assigned device, status, and last login for each user

Member List

ColumnDescription
NameDisplay name of the user.
EmailUser's email address.
RoleUser role — Regular User or Enterprise Admin.
StatusCurrent account status — for example, whether the user has completed activation.
Last LoginDate of the user's most recent login.
ActionsDelete the user (available for Regular Users).

Filtering

Narrow the member list using the filters above the table:

  • Days since last login — surfaces members who haven't used the app recently, which is useful for tracking adoption or following up on inactive accounts.
  • Status — quickly find users who were invited but haven't yet activated their account.
  • Role — Regular User or Enterprise Admin.
Display Name Editing Not Yet Available

The Name column reflects what the user entered during account activation and can't be edited from the Members page. Support for editing display names is planned for a future release.

Inviting Users

  1. Click the Invite User button in the top-right corner.
  2. Enter the user's email address.
  3. Assign a role (Regular User or Enterprise Admin).
  4. An invitation email is sent to the user automatically.
Invite Link Expiration

Invite links expire after 6 days. If the user hasn't accepted the invite within that window, generate a new invite for them from the Members page.

Roles

RolePermissions
Regular UserCan access only their own recordings and transcripts.
Enterprise AdminFull organizational access — manage devices, members, recordings, security settings, and audit logs via the Web Admin Dashboard.
Note

Enterprise Admin accounts cannot be deleted from the Members page.

AI Lens (optional)

AI Lens allows administrators to ask natural language questions about their organization's meeting data, devices, and activity.

AI Lens page with a natural-language question field, analysis scope summary, and generated insights

Type a question in the text field — for example, "What were the key decisions from last week?" — and click Ask AI. AI Lens analyzes your organization's recordings and returns an executive summary with insights.

The analysis scope is displayed below the search field (e.g., "Analyzed: 75 recordings, 11 users, 15 devices, 500 events (last 30 days)").

Click Configure in the top-right corner to adjust analysis settings.

Export (optional)

The Export page lets Enterprise Administrators send recordings, transcript segments, summaries, and device inventory to a Treasure Data CDP database. The data can then be joined with other customer data for analytics, segmentation, and activation.

Treasure AI Voice supports both manual and recurring exports. Exports run in the background, so the console returns control after creating an export run. Use the History tab to monitor the run and review its result.

Japan region only

The CDP export currently writes to the Japan (AP01) region of Treasure Data CDP. The destination database must be in that region.

Prerequisites

Before configuring an export, make sure you have:

  • An Enterprise Administrator account in Treasure AI Voice.
  • CDP export enabled for your organization.
  • A destination database in the Japan (AP01) region of Treasure Data CDP.
  • A dedicated Treasure Data CDP API key with Import Only or General Access permission on the destination database.
Use a write-only API key

Use a dedicated write-only API key. Do not use a Master API key, because a Master key grants more access than this integration requires.

Enable CDP Export

CDP export is disabled by default. To enable it:

  1. Sign in to the AI Voice Console as an Enterprise Administrator.
  2. Open the Export page.
  3. Select Treasure Data CDP.
  4. Click Enable export.

If the option is unavailable, contact your Treasure AI representative.

Save Export Settings

Save the destination and credential before running a manual or recurring export:

  1. Open the Settings tab on the Export page.
  2. Enter the destination Database.
  3. Enter a dedicated Write-only API Key.
  4. Optionally expand Advanced and change the Recordings table and Transcript segments table names.
  5. Click Save settings.

The database and table settings are restored when you return to the Export page. A saved API key is shown only as a masked value. The full key is not returned to the console, included in an export run payload, or written to the audit log.

Export Settings tab showing a saved write-only API key, destination database, and advanced table settings

To replace the credential, click Replace and save a new key. To remove it, click Remove. Removing the saved key disables an enabled recurring schedule.

The destination database name must be 3–64 characters, begin with a lowercase letter, use only lowercase letters, digits, or underscores, and must not be export. Table names must be 3–128 characters and use only lowercase letters, digits, or underscores.

Run an Export Manually

  1. Confirm that the destination database and saved API key are shown on the Settings tab.
  2. Optionally expand Advanced and set a From and To date range.
  3. Optionally select Re-export previously exported recordings.
  4. Click Run export now.
  5. Open the History tab to monitor the run.

The date range filters recordings by their recorded date. The To date includes the entire day. The range applies to recordings, transcript segments, and summaries. It does not filter devices by recording date.

A manual export does not need to remain open in the browser. The export continues in the background after the run starts.

Configure a Recurring Export

Recurring exports use the saved destination, table settings, and write-only API key. Save and verify those settings before enabling a schedule.

  1. Open the Schedule tab.
  2. Turn on Scheduled export.
  3. Select an Interval:
    • Every hour
    • Every 6 hours
    • Every 12 hours
    • Every 24 hours
    • Weekly
  4. Select the behavior for the first scheduled run.
  5. Save the schedule.

The shortest available interval is one hour. AI Voice CDP export uses the listed intervals; it does not provide a custom cron expression. Saving an enabled schedule starts an export immediately. Subsequent exports run at the selected interval from that initial run. For example, if an hourly schedule is saved at 10:23, the initial export starts immediately, followed by scheduled exports at 11:23, 12:23, and so on.

A manual or scheduled export cannot start while another export is running for the same organization. A recurring schedule is configured at the organization level and uses the saved credential without requiring an administrator to be signed in when the run starts.

Export Schedule tab showing the scheduled export toggle, interval options, and first scheduled run setting

Choose the First Scheduled Run

Select one of the following options when enabling a schedule:

  • Only recordings from now on: Starts the export boundary when the schedule is enabled. Historical recordings are not backfilled automatically, but records updated after that point are included.
  • Send everything not yet exported first: Starts with the organization's existing exportable data and then continues with incremental exports. A large recording history may require multiple runs.

Monitor Exports and Review Run History

The History tab lists recent manual and scheduled export runs. Each row shows:

  • Start time
  • Trigger type
  • Status
  • Accepted recording rows
  • Accepted transcript segment rows
  • Rejected rows
  • Duration
  • Run ID

Select a row to view the destination database, accepted and rejected counts by table, failure information, and recordings rejected because their event was too large.

Export History tab showing manual and scheduled runs with status, row counts, duration, and run IDExport run detail showing the run status, destination database, table-level accepted and rejected counts, and rejected recordings
StatusMeaning
QueuedThe export has been accepted and is waiting to start.
RunningThe export worker is processing the run.
SuccessThe run completed without reported row rejections.
PartialThe run completed with rejected rows or stopped at the worker time limit. Data not reached by the run is handled by a later export run.
FailedThe run could not complete because of an authentication, permission, configuration, or system error.
Nothing to sendNo recording or device events were accepted for the run.

Invalid credentials and insufficient Treasure Data CDP database permissions can appear as a failed run because the export runs asynchronously. Grant the key's user Import Only or General Access permission on the destination database, then run the export again.

A recording whose serialized event exceeds the 1 MB per-event limit is listed in the run details. The recording row is rejected, but its transcript segments and summary may still be exported. The recording is retried by later runs for a limited number of attempts. The console does not show the serialized event size before export. If the limit is exceeded, review the rejected recording in the run details.

Understand Incremental Exports

Each exported event includes the following fields:

  • unique_id: A stable identifier for the source record.
  • updated_at: The source record's last-updated timestamp, in Unix epoch seconds.
  • time: The timestamp used for Treasure Data time partitioning.

time and updated_at have different purposes. Use time for partition filtering and updated_at to determine which copy of a record is current.

Scheduled and undated exports use an incremental checkpoint. Recordings and devices updated at or after that checkpoint are included in the next run. A date range narrows recording candidates by recording date while preserving the incremental check.

Treasure Data CDP appends incoming events instead of replacing existing rows. Repeated exports can therefore contain multiple rows with the same unique_id. Deduplicate downstream by unique_id, keeping the row with the greatest updated_at.

Audit Logging

Every export run is recorded in Audit Logs under the TD CDP Export event type. Run status and row counts are available in History and the run details, not in Audit Logs. Changes to the destination settings and saved credential are also recorded. The API key itself is never written to the audit log.

Limits and Troubleshooting

  • The minimum recurring-export interval is one hour.
  • Only one export can run at a time for an organization.
  • A single recording event cannot exceed 1 MB.
  • A batch cannot exceed 4 MB.
  • A run can finish with Partial when it reaches the worker time limit or when Treasure Data rejects rows.
  • If a run fails, review its failure information in History and verify the destination database, API key, and database permission.
  • If a run reports Nothing to send, verify the date range and whether previously exported recordings should be included.

For the exported table schemas, data relationships, and querying examples, see Treasure Data CDP Integration.

The Legal page provides direct links to Treasure Data's legal documents that govern the use of Treasure AI Voice:

  • Terms of Service
  • Voice Supplemental Terms
  • AI Terms
  • AI Acceptable Use Policy
  • Privacy Statement

Each link opens the current version of the document on the Treasure Data website.