diff --git a/docs/employee-guide/employee-portal/my-card.mdx b/docs/employee-guide/employee-portal/my-card.mdx
new file mode 100644
index 0000000..77a6df0
--- /dev/null
+++ b/docs/employee-guide/employee-portal/my-card.mdx
@@ -0,0 +1,133 @@
+---
+title: 'My Digital Card'
+sidebar_label: 'My Digital Card'
+description: 'Activate, edit, and share your digital business card from the ShiftControl employee portal — a live link and QR code that stay up to date.'
+keywords: ['ShiftControl', 'employee portal', 'my card', 'digital business card', 'QR code', 'share contact', 'vCard', 'PIN']
+---
+
+import Admonition from '@theme/Admonition';
+import ModeScreenshot from '@site/src/components/ModeScreenshot';
+
+
Share your contact details instantly — no app to install, no paper to run out of.
+
+
+ Digital cards is an optional feature your IT team switches on for the whole organization. If My digital card isn't in your employee-portal sidebar, your admin hasn't turned it on — ask them if you think you should have it.
+
+
+## Why this exists
+
+Paper business cards are out of date the day they're printed, and you never have one when you need it. Standalone card apps want a monthly subscription and don't know anything about you.
+
+Your digital card solves both. It's already built from your directory profile, so your name, title, and department are right without you typing them. You get a short link and a QR code you can show on your phone, put in your email signature, or print on a lanyard — and when your title changes, the card follows.
+
+## Activating your card
+
+Open **My digital card** from your employee-portal sidebar. The first time, you'll see a preview of your card built from your profile, with an **Activate my card** button.
+
+Some details in that first preview may be sample values — the page tells you which ones — because your profile doesn't have everything a card can show. You'll set the real values right after activating.
+
+Choose **Activate my card**. That creates your card as a draft and drops you straight into the edit screen to review it.
+
+
+ Activating creates a private draft. Your card isn't on the internet until you publish it, which is a separate step on the Manage tab.
+
+
+Your company may also present card activation as a step during onboarding — if you did it there, your card is already activated and you'll land straight on it.
+
+## The four tabs
+
+Once your card exists, the page has four tabs.
+
+### My card
+
+Your live card as other people see it, with everything you need to share it.
+
+
+
+- **Your card link** — **Copy** puts it on your clipboard, ready for an email signature or a chat message.
+- **Your QR code** — hold your phone up and someone can scan it to save you as a contact.
+- **QR downloads** — four sizes, labelled for what they're good for: **256×256** for web and chat, **512×512** for an email signature, **1024×1024** print-ready, and **2048×2048** for large format. There's also **Download SVG** if whoever's doing your print work wants a vector.
+- **A status badge** tells you whether the card is **Live**.
+
+The card itself has **Save contact**, **Call**, and **Email** buttons — those are for the person you're sharing with, so they can save you to their phone in one tap.
+
+On a narrow screen, a **Share my card** button opens a share sheet with the same QR code, copy-link, and downloads.
+
+### Edit my card
+
+Your photo and details.
+
+
+
+**Photo** — **Replace photo** uploads a new one, **Remove** clears it, and **Reset to profile photo** puts your directory photo back. Square works best, at least 400×400; it gets resized to fit.
+
+**Card details** — what you can change here depends on how your admin set the card up:
+
+- A field with a **lock** icon is controlled by your company. You can see it, but not change it.
+- A field marked **Synced** comes from your directory profile. If you'd rather show something different, choose **Customize** — the field becomes yours to edit, and your directory value stays visible underneath for reference. **Re-sync** reconnects it.
+- Everything else you can just type into. Fields marked *optional* are ones you can choose to leave blank.
+
+Nothing is saved until you press **Save changes**. **Discard** throws away your edits.
+
+
+ If your directory says "Senior Manager, Commercial Partnerships" and you introduce yourself as something shorter, choose Customize on the title and set the version you actually use. It won't be overwritten the next time your profile syncs.
+
+
+### My QR code
+
+Changes what sits in the middle of your QR code.
+
+
+
+Pick **Company logo**, **None**, **My photo**, or **Custom image** and press **Save medallion**. Your company sets a default, but your choice wins.
+
+
+ The change applies everywhere your code appears, but a QR image you already downloaded still shows the old medallion. Grab a new download from the My card tab after saving.
+
+
+Sharing and downloading live on the **My card** tab — this tab only changes the code's appearance.
+
+### Manage
+
+Publishing and your card's PIN.
+
+
+
+- **Card status** — whether your card is live, with a button to **publish** or **unpublish** it. Unpublishing takes the card off the internet without deleting anything, so you can publish again whenever you like. *(Your admin can turn this off, in which case they control publishing.)*
+- **Card PIN** — require a code before your card shows its contents. It doesn't have to be numbers; a word or short phrase works, up to 24 characters. You can change or remove it at any time, and you can see the current value.
+- **Your card link** — if your admin has allowed it, you can regenerate your link here. Most organizations keep this with admins.
+
+## Common questions
+
+### Who can see my card?
+
+Anyone with the link. Your card link is long and random, so nobody can guess it or find your colleagues by changing the URL — and cards aren't listed in any public directory or indexed by search engines. But treat the link as public: anyone you give it to can pass it on.
+
+If that's a concern, set a **PIN** on the **Manage** tab, or **unpublish** the card when you're not using it.
+
+### Can I have more than one card?
+
+No — one card per person.
+
+### What happens to my card if I leave?
+
+Your company sets that policy in advance. Depending on what they chose, your link will either show a neutral "no longer with the company" card, redirect to a company page, or stop working. Your admin may also apply a grace period first.
+
+### My title on the card is wrong
+
+If the field is **locked**, your admin controls it — ask them to change it. If it's **synced**, either get your directory profile corrected or use **Customize** to set the value yourself.
+
+### Why can't I edit some fields?
+
+Your admin locked them so that cards across the company always match the directory. It's not personal — name, title, and department are the usual ones.
+
+### I changed my photo but the card still shows the old one
+
+Photo changes save with the rest of the form. Make sure you pressed **Save changes** on the **Edit my card** tab.
+
+## Related pages
+
+- [Your Apps](/employee-guide/employee-portal/your-apps) — the applications you have access to.
+- [My Devices](/employee-guide/employee-portal/my-devices) — the hardware assigned to you.
+- [Org Chart](/employee-guide/employee-portal/org-chart) — who's who, and where you fit.
+- [Account Security](/employee-guide/employee-portal/account-security) — your sign-in and MFA settings.
diff --git a/docs/using-shiftcontrol/Devices/Device-actions.mdx b/docs/using-shiftcontrol/Devices/Device-actions.mdx
index 038492e..30b8b2a 100644
--- a/docs/using-shiftcontrol/Devices/Device-actions.mdx
+++ b/docs/using-shiftcontrol/Devices/Device-actions.mdx
@@ -98,6 +98,33 @@ Removes the device from JumpCloud management.
If a device isn't checking in when you un-manage it, the agent and policies **can't be removed remotely** — someone has to uninstall the agent on the machine itself. Otherwise you've removed the record while an agent keeps running on the endpoint.
+#### Un-managing several devices at once
+
+Retiring a batch of devices — a hardware refresh, a closed office, a stack of returned laptops — used to mean repeating the single-device flow once per machine. You can now do it in one pass from the [Device Inventory](/using-shiftcontrol/Devices/Viewing-devices).
+
+Select the devices with the checkboxes on the inventory grid, then open **Bulk Actions** in the toolbar and choose **Un-manage**.
+
+
+
+Un-manage is deliberately the **only** bulk device action. Lock, restart, shut down, and erase all carry too much blast radius to expose behind a single click on a multi-row selection — those stay one device at a time, on the device's own page.
+
+**How the batch behaves:**
+
+- **Type-to-confirm.** Like the single-device flow, you type `unmanage` to enable the confirm button. A misclick can't retire your fleet.
+- **Per-device results.** When the batch settles you get a list naming which devices were un-managed and which failed, with a reason for each failure. One error doesn't abort the rest and doesn't hide what happened.
+- **Throttled.** ShiftControl works through the selection a few at a time rather than firing everything at JumpCloud at once, so a large selection takes a little longer but doesn't get rate-limited.
+- **Same permission as single un-manage.** Anyone who can un-manage one device can un-manage several — there's no separate bulk permission. That's worth knowing when you grant the **Destructive** tier.
+
+Everything in [Un-manage](#un-manage) above still applies to every device in the batch: data is left intact, active devices uninstall the agent themselves, inactive devices need a manual agent removal, and re-managing means re-enrolling from scratch.
+
+
+ Recovery keys are only retrievable for about 30 days after a device is deleted from JumpCloud, and there's no bulk reveal. If you might need the FileVault or BitLocker key for any device in your selection, reveal and save it before you run the batch — afterward the clock is already running on all of them at once.
+
+
+
+ Multi-select and bulk actions live on the Device Inventory grid. The Needs Attention and Device Health views are read-only triage surfaces — filter or search the inventory to build the selection you want.
+
+
### Erase device
Wipes all data and returns the device toward factory state. This is the most destructive action in ShiftControl.
@@ -111,7 +138,7 @@ ShiftControl adds guardrails on top of JumpCloud:
- **Type the device name to confirm.** Erase won't proceed on a misclick — you have to type the exact device name.
- **Capture the recovery key first.** Reveal and save the FileVault/BitLocker key *before* erasing; the wipe destroys it. ShiftControl prompts you toward this, but it's on you to actually save it.
- **macOS PIN.** Erase surfaces a 6-digit PIN. On Intel Macs without a T2 chip, that PIN is required to recover the device and **cannot be recovered if lost** — record it. On Apple Silicon and T2 Macs, recovery is protected by Activation Lock instead, and the PIN may be ignored — that's expected.
-- **No bulk erase.** You erase one device at a time, on purpose.
+- **No bulk erase.** You erase one device at a time, on purpose — [bulk un-manage](#un-managing-several-devices-at-once) exists, bulk erase does not.
- **Warn the user.** The erase doesn't warn the person using the device — you do.
Platform behavior differs:
@@ -141,6 +168,7 @@ When someone leaves, do device steps in this order so you never destroy somethin
- **Everything is logged**, including recovery-key reveals, in an append-only audit trail.
- **Erase queues when offline** and runs on reconnect — treat a queued erase as already committed.
- **Un-manage ≠ erase.** Un-manage leaves data intact; erase destroys it. Choose deliberately.
+- **Un-manage is the only bulk action**, and it uses the same permission as the single-device version. Every other action stays one device at a time.
## Related Features
diff --git a/docs/using-shiftcontrol/Devices/Viewing-devices.mdx b/docs/using-shiftcontrol/Devices/Viewing-devices.mdx
index df8156e..b3975c2 100644
--- a/docs/using-shiftcontrol/Devices/Viewing-devices.mdx
+++ b/docs/using-shiftcontrol/Devices/Viewing-devices.mdx
@@ -36,6 +36,16 @@ Each row shows the fields IT actually uses to make decisions:
Click any row to open the [device's detail page](/using-shiftcontrol/Devices/Device-details).
+### Selecting several devices
+
+Each row has a checkbox, and the header checkbox selects everything currently showing. With a selection made, a **Bulk Actions** menu appears in the toolbar.
+
+The only bulk action today is **Un-manage** — the batch version of retiring a device from JumpCloud management. It's the lowest-risk, highest-volume thing admins actually need to do to many devices at once; the destructive actions like erase stay deliberately one-at-a-time. See [bulk un-manage](/using-shiftcontrol/Devices/Device-actions#un-managing-several-devices-at-once) for how the batch behaves and what to save first.
+
+
+ Combine the filters and search to get exactly the devices you mean — say Dormant plus Windows for a batch of retired machines — then use the header checkbox. It's faster and safer than hunting rows by hand.
+
+
### Filtering and search
Filter the list by **status** (online, offline, dormant), **platform** (macOS, Windows, Linux, iPadOS), **encryption** (encrypted / unencrypted), and **assignment** (assigned / unassigned). Combine filters to narrow quickly — for example, *unencrypted* + *macOS* — and use search to jump to a specific name, hostname, or serial.
diff --git a/docs/using-shiftcontrol/DigitalCards/Card-domain.mdx b/docs/using-shiftcontrol/DigitalCards/Card-domain.mdx
new file mode 100644
index 0000000..21db030
--- /dev/null
+++ b/docs/using-shiftcontrol/DigitalCards/Card-domain.mdx
@@ -0,0 +1,67 @@
+---
+title: 'Card Domain'
+sidebar_label: "Domain"
+description: 'Serve your digital business cards from your own hostname instead of cards.shiftcontrol.io, with DNS verification and a permanent ShiftControl fallback.'
+keywords: ['ShiftControl', 'digital business cards', 'custom domain', 'hostname', 'DNS', 'CNAME', 'branding', 'cards.shiftcontrol.io']
+icon: 'globe'
+---
+
+import ModeScreenshot from '@site/src/components/ModeScreenshot';
+import Admonition from '@theme/Admonition';
+
+Put your own hostname on the links your team hands out — without invalidating anything already printed.
+
+## Overview
+
+By default your cards are served from `cards.shiftcontrol.io`. That works, and it's what every card falls back to. But the URL is part of the card: someone scanning a code or reading an email signature sees the hostname, and `cards.yourcompany.com` reads as yours in a way that a vendor domain doesn't.
+
+The **Domain** tab lets you add a hostname you control and serve cards from it. Find it under **Settings → Digital cards → Domain**.
+
+
+
+## How It Works
+
+Exactly one hostname on this tab carries the cyan **Primary** badge, so "which hostname do my links use right now?" is answerable at a glance.
+
+- **Before you add a custom domain**, `cards.shiftcontrol.io` holds the primary slot.
+- **Once your custom domain is verified and serving**, it takes the primary slot and the ShiftControl hostname drops below it as a smaller, muted **Fallback** row.
+
+The ShiftControl hostname is never turned off. Every card always works there, including while a custom domain is mid-setup and after one is live. That's the property that makes this safe to adopt at any point: **cards already printed with the ShiftControl URL keep working forever.**
+
+### Adding your domain
+
+Enter a subdomain you control — something like `cards.acme.com` — and choose **Add domain**. ShiftControl then gives you the DNS records to add at your DNS provider so it can verify you own the hostname and issue a certificate for it.
+
+Once the records resolve and verification completes, the domain starts serving and takes over as primary. New links and newly generated QR codes use it.
+
+
+ Point a dedicated subdomain such as cards.acme.com at ShiftControl. Don't try to serve cards from your root domain — that's where your website lives, and the two can't share the hostname.
+
+
+
+ Verification can't complete until your new records have propagated. If it doesn't verify immediately, that's usually propagation rather than a mistake — re-check after your provider's TTL has elapsed. Meanwhile every card keeps working on the ShiftControl hostname.
+
+
+## Common Scenarios
+
+### Scenario: Moving to your own hostname after a pilot
+
+You rolled cards out to the sales team on `cards.shiftcontrol.io` and it went well. Now you want the company hostname. You add `cards.yourcompany.com`, add the DNS records, and wait for verification. When it goes live, it becomes primary and new shares use it — and the QR codes from the pilot, printed on the ShiftControl hostname, keep resolving. Nothing gets reissued.
+
+### Scenario: Deciding whether it's worth it
+
+You're a ten-person company and nobody looks closely at the URL under a QR code. The ShiftControl hostname is fine and requires no DNS work — skip it. Revisit if you start printing cards at volume or your brand team asks.
+
+## Things to Know
+
+- **The ShiftControl hostname is permanent.** It stays a working fallback for every card, forever. Adding a custom domain never breaks an existing link.
+- **One hostname is primary at a time**, and it's the one badged **Primary**.
+- **Verification needs DNS access.** You'll need someone who can add records for the domain.
+- **Existing QR codes don't change.** A code encodes the URL it was generated with. Regenerate a QR code from a card if you specifically want the new hostname on it.
+- **View-only admins see this page read-only.** Without *Manage card settings*, the controls render disabled.
+
+## Related Features
+
+- [Digital cards overview](/using-shiftcontrol/DigitalCards/Digital-cards-overview) — how cards are served and why links are unguessable.
+- [Card template](/using-shiftcontrol/DigitalCards/Card-template) — the rest of your card branding.
+- [My digital card (Employee Guide)](/employee-guide/employee-portal/my-card) — where employees copy their link and download QR codes.
diff --git a/docs/using-shiftcontrol/DigitalCards/Card-fields.mdx b/docs/using-shiftcontrol/DigitalCards/Card-fields.mdx
new file mode 100644
index 0000000..ecf5533
--- /dev/null
+++ b/docs/using-shiftcontrol/DigitalCards/Card-fields.mdx
@@ -0,0 +1,117 @@
+---
+title: 'Card Fields'
+sidebar_label: "Fields"
+description: 'Choose which fields appear on your digital business cards, whether the org or the employee controls each one, which stay synced to the directory, and what employees may do to their own card.'
+keywords: ['ShiftControl', 'digital business cards', 'card fields', 'field governance', 'locked', 'editable', 'optional', 'directory sync', 'employee self-service']
+icon: 'shield-check'
+---
+
+import ModeScreenshot from '@site/src/components/ModeScreenshot';
+import Admonition from '@theme/Admonition';
+
+Decide what can appear on a card, who controls each field, and which fields must always match your directory.
+
+## Overview
+
+The **Template** tab decides how a card looks. The **Fields** tab decides what's on it — and, more importantly, *who gets to change it*.
+
+This is the tab that makes company-managed cards different from a card app your team signs up for individually. You can guarantee that everyone's name, title, and department match the directory, while still letting people add their own mobile number or LinkedIn if they want to.
+
+Find it under **Settings → Digital cards → Fields**.
+
+
+
+## How It Works
+
+The table lists exactly the fields that can appear on a card. Anything not in the table isn't on the card at all — **removing a row is how you hide a field**, and the **+** button in the table header is how you add one back or add something new.
+
+Each row has three controls:
+
+- **Mode** — who controls the field (below).
+- **Allow sync** — whether the field tracks the directory, for the fields that have a directory equivalent.
+- **Icon** — the small icon shown on that contact line. Click it to pick a different one.
+
+Contact rows can be dragged to reorder them, which sets the order they appear on the card. The identity block at the top of the card — photo, name, title, department — has a fixed position.
+
+Like the Template tab, edits are staged until you press **Save**.
+
+### The three modes
+
+| Mode | What it means for the employee |
+|---|---|
+| **Locked** | Always on the card, and the organization controls the value. The employee sees it read-only and can't remove it. |
+| **Editable** | On the card by default, and the employee can change or clear the value. |
+| **Optional** | Off the card by default. The employee can choose to add it. |
+
+If you do nothing to a field, it behaves as **Editable**.
+
+The useful mental model: **Locked** is for facts about the person's role that the company is asserting. **Editable** is for details the company supplies but the person may correct. **Optional** is for anything personal enough that it should be their choice — a mobile number is the classic case.
+
+
+ Most organizations lock Full name, Job title, and Department — those should match the directory, and a card that disagrees with your directory is worse than no card. Then leave phone and location editable and make mobile optional.
+
+
+### Directory sync
+
+For fields that exist in your directory — name, job title, department, work email, and location — the **Allow sync** toggle keeps the card following the directory. Change someone's title in ShiftControl and their card follows.
+
+An employee (or an admin acting for them) can still break that link on a specific field by choosing **Customize** on their card. That field then holds a custom value, stops tracking the directory, and shows the directory value underneath for comparison, with a **Re-sync** link to reconnect it. A sync will never silently overwrite a value someone deliberately customized.
+
+If a field is **Locked**, employees don't get the Customize option — but an admin editing the card [from the user's record](/using-shiftcontrol/DigitalCards/Managing-a-users-card) still can.
+
+## The Fields You Can Put on a Card
+
+**Identity** — photo, full name, job title, department. These render as the card's header block.
+
+**Contact** — work email, phone, mobile phone, location.
+
+**Everything else** comes from the **+** menu, grouped by category:
+
+- **General** — Website, Office address
+- **Social** — LinkedIn, X (Twitter), Instagram, Facebook, YouTube, TikTok, Threads
+- **Messaging** — WhatsApp, Signal, Telegram
+- **Business** — GitHub, Booking link
+
+The same menu lets you define a **custom field** if you need something that isn't on the list.
+
+
+ Fields like LinkedIn and WhatsApp show a friendly action line on the card — "Connect with me on LinkedIn" — rather than a naked URL, and tapping it opens the right app. The employee enters just their handle or number.
+
+
+## Employee Self-Service
+
+Below the table, two switches control what employees may do to their own card. They're separate from field-level control because they're about the card's *lifecycle*, not its content.
+
+- **Publish and unpublish their own card** — whether an employee can take their own card live and offline. On by default.
+- **Regenerate their own link** — whether an employee can rotate their own card link. **Off by default**: link rotation is a kill-switch, and most organizations want that with admins.
+
+Turning both off leaves employees able to edit their card content while admins own whether it's live and what its address is.
+
+## Common Scenarios
+
+### Scenario: The directory is the source of truth, with room for personal choice
+
+You lock **Full name**, **Job title**, **Department**, and **Work email** with sync on, so no card can contradict the directory. You leave **Phone** and **Location** editable — the directory has them, but people fix them. You add **Mobile phone** and **LinkedIn** as **Optional**, so sharing either is a personal decision. Sales adds their mobile; engineering mostly doesn't.
+
+### Scenario: Someone's job title needs to differ from the directory
+
+Your directory has a formal title ("Senior Manager, Commercial Partnerships") but the person introduces themselves with a shorter one. You leave **Job title** editable with sync on. They open their card, choose **Customize** on the title, and set the version they use. Their card now shows their preferred title, keeps showing the directory value beneath it in the editor for reference, and won't be reverted by the next sync.
+
+### Scenario: Locking down a regulated team
+
+Compliance needs every outward-facing detail approved. You set every field on the card to **Locked**, remove the optional social and messaging fields entirely, and turn off both self-service switches. Employees can see their card and share it; they can't change anything about it, and admins own publication.
+
+## Things to Know
+
+- **Removing a row hides the field.** There's no separate "hidden" mode — take it off the table and it's off the card.
+- **Unlisted fields behave as Editable.** If you want a field genuinely locked down, set it explicitly.
+- **Customized values survive syncs.** That's intentional; it's also why a stale custom value stays stale until someone re-syncs it.
+- **Admins can override locked fields; employees can't.** Useful for corrections, and worth remembering when someone asks why you could change something they couldn't.
+- **Field order is the card's order.** Drag the contact rows to control what a scanner sees first.
+
+## Related Features
+
+- [Card template](/using-shiftcontrol/DigitalCards/Card-template) — how the card looks.
+- [Managing a user's card](/using-shiftcontrol/DigitalCards/Managing-a-users-card) — edit an individual card, including locked fields.
+- [My digital card (Employee Guide)](/employee-guide/employee-portal/my-card) — how these rules appear to your employees.
+- [Editing a user](/using-shiftcontrol/Users/Editing-a-user) — the directory values that synced fields follow.
diff --git a/docs/using-shiftcontrol/DigitalCards/Card-offboarding.mdx b/docs/using-shiftcontrol/DigitalCards/Card-offboarding.mdx
new file mode 100644
index 0000000..82bb223
--- /dev/null
+++ b/docs/using-shiftcontrol/DigitalCards/Card-offboarding.mdx
@@ -0,0 +1,91 @@
+---
+title: 'Card Offboarding'
+sidebar_label: "Offboarding"
+description: "Decide what happens to an employee's digital business card when they leave — a generic company card, a redirect, or a hard 404 — plus an optional grace period."
+keywords: ['ShiftControl', 'digital business cards', 'offboarding', 'grace period', 'redirect', '404', 'deprovisioning', 'leaver']
+icon: 'power-off'
+---
+
+import ModeScreenshot from '@site/src/components/ModeScreenshot';
+import Admonition from '@theme/Admonition';
+
+Every card someone hands out lives on after they leave. Decide now what those links do — so nobody has to remember later.
+
+## Overview
+
+A digital card is only as good as its cleanup story. A card handed out at a conference last year is still in someone's phone, still in an email signature, still on a printed lanyard. When the person leaves, that link has to do *something* — and the worst answer is "keep showing their contact details indefinitely because nobody remembered."
+
+The **Offboarding** tab sets that behavior in advance, once, for the whole organization. When someone is offboarded in ShiftControl, their card follows this policy automatically. There's no extra step in your deprovisioning flow and nothing to remember.
+
+Find it under **Settings → Digital cards → Offboarding**.
+
+
+
+## How It Works
+
+Offboarding a user in ShiftControl emits an event that the card system picks up. Once the grace period (if any) has elapsed, the person's card switches to the policy you chose here. You don't publish, unpublish, or delete anything by hand.
+
+Pick one of three defaults.
+
+### Generic card
+
+The card stays live but strips the personal details, showing a neutral "no longer with the company" message in your branding.
+
+The live link keeps working, and existing QR codes and email-signature links stay valid — they just resolve to the generic card instead of a person. Whoever scans an old card gets a coherent, branded answer rather than an error.
+
+This is the right default for most organizations. It's the least confusing outcome for the person on the other end of the card.
+
+### Redirect
+
+The old link forwards to a single URL you choose — your careers page, your company homepage, or a "contact us" page.
+
+Existing QR codes and links follow the redirect. Use this when you'd rather capture the visitor than explain the departure: someone scanning a departed salesperson's card lands on your site instead of a dead end.
+
+### Hard 404
+
+The link dies completely. Visitors get a generic 404 with no hint that a card ever existed there.
+
+This is the strictest option and the right one when even acknowledging that a person worked for you is something you'd rather not do — some regulated and security-sensitive environments require exactly this.
+
+
+ Every QR code and email-signature link for that person stops working, with no explanation to whoever scans it. Choose it deliberately, not by default.
+
+
+## Grace Period
+
+The grace period keeps the live card working, unchanged, for a set number of days after offboarding — then the policy above takes effect.
+
+It's set in days, up to a year, and **Off** means the policy applies immediately. Press and hold the stepper buttons to move quickly.
+
+A grace period is worth setting when handovers are real: a departing account manager's clients may keep scanning their card for weeks, and a short window means those people reach a working card while the relationship is transferred. Set it to Off when the departure needs to be clean and immediate — for a for-cause exit, for example.
+
+The tab shows a banner spelling out exactly what happens once the grace period ends, worded for whichever policy you've selected, so you can sanity-check the combination before saving.
+
+## Common Scenarios
+
+### Scenario: A normal departure with a handover
+
+Your default is **Generic card** with a **30-day** grace period. A salesperson leaves. For 30 days their card works exactly as before, so clients mid-conversation aren't cut off while accounts are reassigned. After that, the same link shows your branded "no longer with the company" card — and it keeps doing so indefinitely, so no scan ever fails.
+
+### Scenario: Turning departures into pipeline
+
+You set **Redirect** to your careers page with no grace period. Every card a departed employee ever handed out now points at your open roles. The links stay useful to you instead of just being tidy.
+
+### Scenario: A security-sensitive exit
+
+Someone leaves under circumstances where you don't want their association with the company discoverable. The org default is Generic card, but for this person you don't want that — so alongside setting the org policy, you go to [their user record's Digital card tab](/using-shiftcontrol/DigitalCards/Managing-a-users-card) and permanently delete the card. The link code is purged and never reissued.
+
+## Things to Know
+
+- **This is the organization-wide default.** For a specific person you need something different for, act on their card directly from their user record.
+- **It's automatic.** The policy runs off the offboarding event — there's no card step in your deprovisioning checklist.
+- **Generic card and Redirect keep the link alive.** Only Hard 404 breaks existing QR codes.
+- **A grace period delays the policy, it doesn't soften it.** When the window closes, the full policy applies.
+- **Deleting a card is different from offboarding one.** Offboarding applies a policy; [hard delete](/using-shiftcontrol/DigitalCards/Managing-a-users-card) purges the card, its images, and its link code permanently.
+
+## Related Features
+
+- [Managing a user's card](/using-shiftcontrol/DigitalCards/Managing-a-users-card) — unpublish or permanently delete one person's card.
+- [Digital cards overview](/using-shiftcontrol/DigitalCards/Digital-cards-overview) — how cards are served and secured.
+- [Editing a user](/using-shiftcontrol/Users/Editing-a-user) — the rest of the offboarding picture for a person.
+- [Device actions](/using-shiftcontrol/Devices/Device-actions) — the device side of offboarding, including the safe order of operations.
diff --git a/docs/using-shiftcontrol/DigitalCards/Card-template.mdx b/docs/using-shiftcontrol/DigitalCards/Card-template.mdx
new file mode 100644
index 0000000..08bb382
--- /dev/null
+++ b/docs/using-shiftcontrol/DigitalCards/Card-template.mdx
@@ -0,0 +1,106 @@
+---
+title: 'Card Template'
+sidebar_label: "Template"
+description: 'Design your organization-wide digital business card: pick a layout, set your brand color and logo, add legal links, and choose the default QR medallion.'
+keywords: ['ShiftControl', 'digital business cards', 'card template', 'branding', 'brand color', 'logo', 'card layout', 'QR medallion', 'legal links']
+icon: 'palette'
+---
+
+import ModeScreenshot from '@site/src/components/ModeScreenshot';
+import Admonition from '@theme/Admonition';
+
+One template, every card. Set your layout and branding here and every published card in the organization re-renders to match.
+
+## Overview
+
+The **Template** tab is where your cards get their look. It's deliberately not a freeform design tool — you choose from four curated layouts and supply your brand color, logo, and legal links. That constraint is the point: it keeps every card in the organization visually consistent without you reviewing anyone's individual card.
+
+Find it under **Settings → Digital cards → Template**. A live preview sits beside the controls and updates as you edit, so you can see the real card before you save.
+
+
+
+## How It Works
+
+Changes are staged locally while you edit — the preview reflects them immediately, but nothing reaches your employees' cards until you press **Save**. **Reset** discards your unsaved edits and returns to the saved template.
+
+When you do save, the change propagates to every published card in the organization. There's no per-card republish step and no reissued links: the same URL and the same QR code now render the new design. This is what makes a rebrand a two-minute job rather than a reissue project.
+
+
+ Because the design is resolved at serve time, QR codes on lanyards, business cards, and email signatures keep working after a template change. Only the appearance changes.
+
+
+## Card Layout
+
+Four layouts, all built to read well on a phone held up to someone else's camera:
+
+| Layout | Character |
+|---|---|
+| **Classic Centered** | The default. Balanced, centered photo and details — closest to what people expect from a digital card. |
+| **Banner Hero** | A brand banner across the top, with details below. Best when your logo or brand color is the thing you want noticed. |
+| **Bold Brand Header** | A high-contrast brand block at the top with the photo and name inset. The most assertive of the four. |
+| **Minimal Flat** | Editorial and understated. Least brand-forward; good for firms where restraint is the brand. |
+
+Pick one and watch the preview — the differences are easier to see than to describe.
+
+## Brand Color
+
+Choose from the swatch row or click the **+** to enter a specific hex value. This colour drives accents across the card: the department line, the contact-row icons, and the primary action button.
+
+Use your actual brand hex rather than an approximate swatch. The field accepts standard six-digit hex.
+
+## Logo
+
+Upload your organization's logo, then choose where it sits:
+
+- **With avatar** — the logo appears near the employee's photo. The default, and the most balanced choice.
+- **In header** — the logo anchors the top of the card. Pairs naturally with **Banner Hero** and **Bold Brand Header**.
+- **Hidden** — no logo on the card. Use this when the card is meant to read as personal rather than corporate.
+
+Replace the logo at any time; like everything else here, the change reaches published cards on save.
+
+
+ A logo with a transparent background can disappear against a dark brand color, and one with a baked-in white box can look like a sticker. Look at the live preview with your actual brand color set before saving.
+
+
+## Legal Links and Disclaimer
+
+Turn this on to put your own policy links in the card footer — typically **Privacy** and **Terms**, though the label is yours to set. Each row is a label plus a URL; **Add link** adds another.
+
+The **Disclaimer** field below is free text shown above the links. It's the right place for a line like "Contact details are provided for professional networking purposes only." If your legal or privacy team has an opinion about publishing staff contact details on a public page, this is where that opinion goes.
+
+## Branding
+
+**Powered by ShiftControl** controls whether the ShiftControl badge appears in the footer of your public cards. On higher tiers you can turn it off to ship unbranded cards; on the Starter tier the switch is locked on and shows a **Starter** chip.
+
+## Default QR Medallion
+
+The medallion is what sits in the middle of the QR code. This setting picks the organization's **default**:
+
+- **Logo** — your company logo in the centre of the code.
+- **None** — a plain code with no centre graphic.
+- **Photo** — the employee's own photo.
+
+This is a starting point, not a rule. Each employee can pick their own medallion on the [My QR code](/employee-guide/employee-portal/my-card) tab of their card — including a custom image — and their choice wins over this default.
+
+## Common Scenarios
+
+### Scenario: Standing up the template for the first time
+
+You're switching the org on. Leave the layout on **Classic Centered**, set your brand hex, upload your logo with **With avatar** placement, add your Privacy and Terms URLs, and paste in the networking-purposes disclaimer your legal team asked for. Save. Every card activated from now on renders in your branding without anyone else making a design decision.
+
+### Scenario: Rebranding mid-year
+
+The company changes its primary colour and logo. You update the brand color and replace the logo here, then save. Every published card — including the ones on printed lanyards from last quarter's conference — renders in the new brand the next time it's opened. Nothing to reissue.
+
+## Things to Know
+
+- **Save is required.** Edits are staged locally; the preview updates before you save, your employees' cards don't.
+- **The preview uses sample values.** It shows representative details so you can judge the design, not a specific person's real card.
+- **The template is organization-wide.** There's no per-department or per-region variant.
+- **View-only admins see this page read-only.** Without *Manage card settings*, the controls render disabled.
+
+## Related Features
+
+- [Digital cards overview](/using-shiftcontrol/DigitalCards/Digital-cards-overview) — how the whole feature fits together.
+- [Card fields](/using-shiftcontrol/DigitalCards/Card-fields) — decide *what* appears on the card, not just how it looks.
+- [Card domain](/using-shiftcontrol/DigitalCards/Card-domain) — serve cards from your own hostname.
diff --git a/docs/using-shiftcontrol/DigitalCards/Digital-cards-overview.mdx b/docs/using-shiftcontrol/DigitalCards/Digital-cards-overview.mdx
new file mode 100644
index 0000000..4267276
--- /dev/null
+++ b/docs/using-shiftcontrol/DigitalCards/Digital-cards-overview.mdx
@@ -0,0 +1,95 @@
+---
+title: 'Digital Cards Overview'
+sidebar_label: "Overview"
+description: 'Company-managed digital business cards for your team — one branded template you control, a live link and QR per employee, and automatic cleanup when someone leaves.'
+keywords: ['ShiftControl', 'digital business cards', 'vCard', 'QR code', 'contact sharing', 'employee portal', 'branding', 'offboarding']
+icon: 'id-card'
+---
+
+import ModeScreenshot from '@site/src/components/ModeScreenshot';
+import Admonition from '@theme/Admonition';
+
+Give everyone a branded digital business card that shares their contact details with a tap or a scan — and that you can retire the moment they leave.
+
+
+ Digital cards is enabled per organization. An admin turns it on under Settings → Features → Digital Business Cards. If you don't see Digital cards under Settings, the feature isn't enabled for your organization yet — talk to your ShiftControl contact.
+
+
+## Overview
+
+Your team meets people. At a conference, in a client meeting, over a coffee — they need to hand over their name, title, email, and phone number. Paper cards go out of date the day they're printed, and per-seat card apps charge you monthly for something that already lives in your directory.
+
+Digital cards closes that gap. You design **one** branded template for the whole organization. Each employee activates their own card, which comes pre-filled from their directory profile. They get a short public link and a QR code they can show on a phone, drop into an email signature, or print on a lanyard. When they leave, the card follows a policy you set in advance — no one has to remember to clean it up.
+
+
+
+## How It Works
+
+There are three surfaces, and they map to three different jobs.
+
+**1. You design the template — once.** Under **Settings → Digital cards** you pick a layout, set your brand color and logo, add your legal links, and decide which fields can appear on a card and who controls each one. This is org-wide: every card in your organization renders from this one template.
+
+**2. Employees activate and fill in their own card.** In the Employee Portal, each person opens **My digital card**, activates it, reviews the details ShiftControl pre-filled from the directory, and publishes. Nothing is public until they publish.
+
+**3. You can drive any individual card yourself.** Every user record has a **Digital card** tab where an admin can activate, edit, publish, unpublish, or permanently delete that person's card on their behalf — useful for executives, for anyone who won't do it themselves, and for offboarding.
+
+### Where cards are served from
+
+Published cards are served from ShiftControl's edge network at `cards.shiftcontrol.io/{code}`, not from the app. Two consequences worth knowing:
+
+- **Cards stay fast and available** wherever they're scanned, and they don't depend on anyone being signed in to ShiftControl.
+- **A template change is effectively instant and global.** Rebrand the template and every published card in your organization re-renders — you don't reissue links or reprint QR codes.
+
+You can serve cards from [your own hostname](/using-shiftcontrol/DigitalCards/Card-domain) instead, and links already in the wild on the ShiftControl hostname keep working.
+
+### What keeps a card from being a privacy problem
+
+A digital card is a public web page with someone's work contact details on it, so the link itself is the security boundary:
+
+- **The link is unguessable.** Each card gets a long random code — you can't walk the URL space to enumerate your colleagues, and there's no public directory of cards.
+- **Cards aren't indexed.** Published cards tell search engines not to index them.
+- **A wrong guess looks like nothing.** A bad code returns a plain 404 with no hint that a card ever existed there.
+- **Links can be rotated.** If a card leaks somewhere you don't want it, regenerate the link. The old code dies permanently and is never reissued — and if you rotate by mistake, you can restore the previous link.
+- **A card can require a PIN** before it shows anything.
+
+## Common Scenarios
+
+### Scenario: Kitting out the team before a conference
+
+Three people are going to a trade show next week. You set the template to your brand color and logo, lock **Full name**, **Job title**, and **Department** so they always match the directory, and make **Mobile phone** optional so people can choose whether to share it. The three of them activate their cards, add their mobiles, and publish. At the booth they hand out a QR code instead of paper — and when one of them changes title next month, the card updates from the directory instead of being wrong.
+
+### Scenario: An executive who won't set up their own card
+
+Your CEO isn't going to log into a portal to fill in a form. You open their user record, go to the **Digital card** tab, activate the card on their behalf, correct the title to the version they actually use, and publish. They get a link and QR without touching anything.
+
+### Scenario: Someone leaves and you don't want a dead link
+
+You set the org offboarding default to **Generic card** with a 30-day grace period. When someone is offboarded in ShiftControl, their card keeps working for 30 days, then automatically switches to a neutral "no longer with the company" card in your branding. Every business card they ever handed out still resolves to something sensible, and nobody had to remember to do it.
+
+## Who Can Do What
+
+| Capability | What it controls |
+|---|---|
+| **View card settings** | See **Settings → Digital cards** at all. Without it the page doesn't appear. |
+| **Manage card settings** | Change the template, fields, offboarding policy, and domain. With view-only access the controls render read-only. |
+| **Manage organization cards** | Activate, edit, publish, unpublish, and delete cards on behalf of individual users, from a user record. |
+
+Employees don't need any admin permission to manage their own card — that's governed by the **Employee Portal Cards** feature and by the two self-service switches on the [Card fields](/using-shiftcontrol/DigitalCards/Card-fields) tab.
+
+## Things to Know
+
+- **One card per person.** There's no second card for a different role or a different language.
+- **Nothing is public until it's published.** Activating creates a draft. Publishing is the step that puts a card on the internet.
+- **Field values are stored separately from the directory.** A card field that's been customized isn't overwritten by a directory sync — deliberately, so a manual correction sticks.
+- **The template is org-wide, not per-person.** Individual cards differ in their *content*, not their design.
+- **Deleting a card is permanent.** The admin-only hard delete purges the card, its images, and its link code, and the code is never reissued.
+- **A person needs a ShiftControl login to own a card.** A directory user who has never signed in can't have one yet — the card tab on their record explains this rather than failing.
+
+## Related Features
+
+- [Card template](/using-shiftcontrol/DigitalCards/Card-template) — layout, brand color, logo, legal links, and the default QR medallion.
+- [Card fields](/using-shiftcontrol/DigitalCards/Card-fields) — which fields appear, who controls each one, and what employees may do to their own card.
+- [Card offboarding](/using-shiftcontrol/DigitalCards/Card-offboarding) — what happens to a card when someone leaves.
+- [Card domain](/using-shiftcontrol/DigitalCards/Card-domain) — serve cards from your own hostname.
+- [Managing a user's card](/using-shiftcontrol/DigitalCards/Managing-a-users-card) — drive an individual card from their user record.
+- [My digital card (Employee Guide)](/employee-guide/employee-portal/my-card) — what your employees see.
diff --git a/docs/using-shiftcontrol/DigitalCards/Managing-a-users-card.mdx b/docs/using-shiftcontrol/DigitalCards/Managing-a-users-card.mdx
new file mode 100644
index 0000000..1d68d92
--- /dev/null
+++ b/docs/using-shiftcontrol/DigitalCards/Managing-a-users-card.mdx
@@ -0,0 +1,108 @@
+---
+title: "Managing a User's Card"
+sidebar_label: "Managing a user's card"
+description: "Activate, edit, publish, unpublish, or permanently delete an individual employee's digital business card from their user record."
+keywords: ['ShiftControl', 'digital business cards', 'admin', 'activate card', 'publish', 'unpublish', 'delete card', 'card PIN', 'link rotation', 'GDPR']
+icon: 'user-gear'
+---
+
+import ModeScreenshot from '@site/src/components/ModeScreenshot';
+import Admonition from '@theme/Admonition';
+
+Set up and run any employee's card on their behalf — for the people who won't do it themselves, and for the ones who are leaving.
+
+## Overview
+
+Employees can manage their own cards in the Employee Portal, but you shouldn't have to depend on that. Executives won't log into a portal to fill in a form. New starters haven't got round to it. Departing employees need their card dealt with whether they cooperate or not.
+
+Every user record has a **Digital card** tab that gives an admin the whole lifecycle for that one person: activate, edit every field, choose their QR medallion, set a PIN, rotate their link, publish, unpublish, and permanently delete.
+
+Open any user from [Users](/using-shiftcontrol/Users/User-management) and select the **Digital card** tab.
+
+
+
+
+ This tab only appears for admins with Manage organization cards. Without it the surface doesn't render at all.
+
+
+## How It Works
+
+The tab has three sub-tabs — **Edit card**, **QR code**, and **Manage** — which are the same surfaces the employee sees, pointed at this person's card instead of your own.
+
+### If they don't have a card yet
+
+Activation is deliberately two steps, so you can back out until you commit:
+
+1. You get a preview and an **Activate their card** button. Nothing is created yet.
+2. Choosing it opens the edit surface, pre-filled from the person's directory profile. **Only pressing Save creates the card.** Discard — or simply navigating away — leaves no card behind, and your next visit starts from the intro again.
+
+
+ A card needs an existing user to belong to. On a brand-new user who hasn't been saved yet, the tab tells you to save the user first.
+
+
+### Editing the card
+
+The **Edit card** tab is the same editor the employee gets, with one important difference: **you can override locked fields.** A field the org locked in [Card fields](/using-shiftcontrol/DigitalCards/Card-fields) is read-only for the employee but editable for you — which is exactly what you need when a locked value is wrong for a specific person.
+
+The field indicators tell you what you're looking at:
+
+- A **lock** icon means the field is locked at the org level.
+- A **sync** icon means the field tracks the directory. **Customize** switches it to a custom value; the chip flips to *Custom · sync off*, the directory value is shown underneath for comparison, and a **Re-sync** link reconnects it.
+
+**Photo** sits at the top: **Replace photo** uploads a new one, **Remove** clears it, and **Reset to profile photo** restores the person's directory avatar. Photos want to be square and at least 400×400 — ShiftControl resizes to fit.
+
+Photo and field changes are both local until you press **Save changes**, so a failed save leaves your edits intact rather than half-applying them.
+
+### Publishing and unpublishing
+
+The **Manage** sub-tab shows the card's status and lets you take it live or offline. Publishing is what puts the card on the internet; unpublishing takes it down while keeping the card and its data intact, so you can publish again later.
+
+### The card PIN
+
+Also on **Manage**: an optional PIN that must be entered before the card shows its contents. It doesn't have to be numeric — a word or short phrase works, up to 24 characters. You can set, change, remove, and view the current value.
+
+Use it for a card that needs to exist but shouldn't be readable by anyone who happens to get the link.
+
+### Rotating the link
+
+If a card ends up somewhere you don't want it, regenerate the link. The old code stops working **permanently and is never reissued**, so this is a genuine kill-switch rather than a rename. If you rotate by mistake, you can restore the previous link.
+
+Rotation is an admin capability by default. You can hand it to employees with the *Regenerate their own link* switch on the [Card fields](/using-shiftcontrol/DigitalCards/Card-fields) tab, but most organizations shouldn't.
+
+### Deleting the card
+
+Hard delete is admin-only and sits behind a confirmation that states plainly that the deletion is permanent. It purges the card, its stored images, and its link code — the code is never reused.
+
+
+ If you want the card off the internet but recoverable, unpublish it. Delete exists for the cases where the data itself has to go — a GDPR erasure request, or a departure where you don't want the card to have existed. It cannot be undone.
+
+
+## Common Scenarios
+
+### Scenario: Setting up an executive's card for them
+
+Your CEO is speaking at a conference next week and won't be filling in a portal form. You open their record, go to **Digital card**, choose **Activate their card**, and get the edit surface pre-filled from the directory. Their locked job title reads *Chief Executive Officer* but they introduce themselves as *Co-Founder & CEO* — you override the locked field, save, and publish. You send them the link and a print-ready QR download.
+
+### Scenario: A card leaked into a scraped contact list
+
+A salesperson's card link starts attracting spam. You open their record's **Digital card → Manage** tab and regenerate the link. The old code dies immediately and permanently. You tell them to update their email signature and regenerate their QR code — and if they'd already printed cards, you consider setting a PIN as well.
+
+### Scenario: A GDPR erasure request from a former employee
+
+Someone who left last year asks for their data to be removed. Offboarding already switched their card to your generic policy, but the underlying card record still exists. You open their user record, go to **Digital card**, and hard delete the card. Its images and link code are purged and the code is never reissued.
+
+## Things to Know
+
+- **The person needs a ShiftControl login.** A directory user who has never signed in can't own a card — the tab explains this rather than failing with an error.
+- **You can override locked fields; the employee can't.** Expect the occasional "why could you change that and I couldn't?"
+- **Every change is Save-gated.** Nothing is written until you save, and a failed save keeps your edits.
+- **Unpublish ≠ delete.** Unpublish is reversible; delete is not.
+- **A regenerated link is gone for good.** Old codes are retired permanently — the only recovery is the restore-previous undo, immediately after.
+- **Offboarding runs on its own.** You don't need to visit this tab for a normal departure; the [offboarding policy](/using-shiftcontrol/DigitalCards/Card-offboarding) handles it.
+
+## Related Features
+
+- [Card fields](/using-shiftcontrol/DigitalCards/Card-fields) — what's locked, synced, and self-service.
+- [Card offboarding](/using-shiftcontrol/DigitalCards/Card-offboarding) — the automatic policy for leavers.
+- [My digital card (Employee Guide)](/employee-guide/employee-portal/my-card) — the same surfaces as your employees see them.
+- [Editing a user](/using-shiftcontrol/Users/Editing-a-user) — the rest of the user record, including their profile photo.
diff --git a/docs/using-shiftcontrol/Users/Editing-a-user.mdx b/docs/using-shiftcontrol/Users/Editing-a-user.mdx
index 7131eec..94cccfd 100644
--- a/docs/using-shiftcontrol/Users/Editing-a-user.mdx
+++ b/docs/using-shiftcontrol/Users/Editing-a-user.mdx
@@ -29,6 +29,37 @@ To view a user's security posture, app permissions, and SaaS costs without editi
- **Primary Email** — The user's SSO login identity. **Changing this affects all connected services** — do so with caution
- **Personal Email** — Non-work email for activation emails and recovery
+
+
+### Profile Photo
+
+You can set a user's **Google Workspace profile picture** directly from ShiftControl. Hover the avatar beside their name at the top of their record and click the pencil badge, then pick an image.
+
+
+
+The image is written straight to that person's Google Workspace profile, so it appears wherever Google shows them — Gmail, Calendar, Drive, Chat, and the Google directory. There's no separate ShiftControl-only photo to keep in sync.
+
+This matters more than it sounds. A directory full of blank grey initials is the normal state at most companies, because setting a profile picture is a task nobody assigns to anyone. Being able to do it from the same screen where you manage everything else about a person is what makes it actually happen — particularly during onboarding, while you're already in their record.
+
+**Requirements:**
+
+- Your organization has a **Google Workspace directory** connected, and
+- the user is **linked in that Google directory**, and
+- you have permission to update users.
+
+
+ If your org has Google connected but this particular user isn't linked in it, the control is visible but disabled, with a tooltip explaining why. That's because JumpCloud has no profile-picture surface for ShiftControl to write to — there's nowhere to put the image. If your organization has no Google directory at all, the control doesn't appear.
+
+
+**Things to know:**
+
+- **Images only, up to 10 MB.** Anything larger or non-image is rejected before it reaches Google.
+- **Google resizes the image.** It's stored as a small square thumbnail, so upload something square and reasonably tight on the face — a wide group photo will crop badly.
+- **Save the user first.** The control isn't available while you're still creating a new user; add them, then set their picture.
+- **This is the same photo digital cards start from.** A card's photo defaults to the person's directory picture, so setting it here gives them a proper [digital card](/using-shiftcontrol/DigitalCards/Digital-cards-overview) photo too.
+
+
+
### Organizational Details
These fields drive dynamic group memberships and therefore app access:
diff --git a/package-lock.json b/package-lock.json
index 2821801..7088ebc 100644
--- a/package-lock.json
+++ b/package-lock.json
@@ -1,12 +1,12 @@
{
"name": "shiftcontrol-docs",
- "version": "1.3.0",
+ "version": "1.3.1",
"lockfileVersion": 3,
"requires": true,
"packages": {
"": {
"name": "shiftcontrol-docs",
- "version": "1.3.0",
+ "version": "1.3.1",
"dependencies": {
"@docusaurus/core": "^3.10.2",
"@docusaurus/plugin-client-redirects": "^3.10.2",
@@ -19,8 +19,8 @@
"lunr": "^2.3.9",
"posthog-docusaurus": "^2.0.5",
"prism-react-renderer": "^2.4.1",
- "react": "^19.2.7",
- "react-dom": "^19.2.7"
+ "react": "^19.2.8",
+ "react-dom": "^19.2.8"
},
"devDependencies": {
"@docusaurus/module-type-aliases": "^3.10.2",
@@ -6708,9 +6708,9 @@
}
},
"node_modules/body-parser": {
- "version": "1.20.5",
- "resolved": "https://registry.npmjs.org/body-parser/-/body-parser-1.20.5.tgz",
- "integrity": "sha512-3grm+/2tUOvu2cjJkvsIxrv/wVpfXQW4PsQHYm7yk4vfpu7Ekl6nEsYBoJUL6qDwZUx8wUhQ8tR2qz+ad9c9OA==",
+ "version": "1.20.6",
+ "resolved": "https://registry.npmjs.org/body-parser/-/body-parser-1.20.6.tgz",
+ "integrity": "sha512-p5tAzS57i5MV9fZFDj9LeIiTZEufbSe2eDozP+ElheSUq1m74CRq1jI4mYNDdVs9vQztXFLuk/Gd6BWTdwRJ5g==",
"license": "MIT",
"dependencies": {
"bytes": "~3.1.2",
@@ -6823,15 +6823,15 @@
}
},
"node_modules/brace-expansion": {
- "version": "5.0.6",
- "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.6.tgz",
- "integrity": "sha512-kLpxurY4Z4r9sgMsyG0Z9uzsBlgiU/EFKhj/h91/8yHu0edo7XuixOIH3VcJ8kkxs6/jPzoI6U9Vj3WqbMQ94g==",
+ "version": "5.0.8",
+ "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.8.tgz",
+ "integrity": "sha512-JZyDyq3D4AUifKTPOB7DELf6XsB3WdPuNxCtob1vFXPsSXhdAiHBWJ/tJ8HAc9aH84BK+5JFZLNkJKx3G9kzQg==",
"license": "MIT",
"dependencies": {
"balanced-match": "^4.0.2"
},
"engines": {
- "node": "18 || 20 || >=22"
+ "node": "20 || >=22"
}
},
"node_modules/braces": {
@@ -9242,9 +9242,9 @@
"license": "MIT"
},
"node_modules/fast-uri": {
- "version": "3.1.2",
- "resolved": "https://registry.npmjs.org/fast-uri/-/fast-uri-3.1.2.tgz",
- "integrity": "sha512-rVjf7ArG3LTk+FS6Yw81V1DLuZl1bRbNrev6Tmd/9RaroeeRRJhAt7jg/6YFxbvAQXUCavSoZhPPj6oOx+5KjQ==",
+ "version": "3.1.4",
+ "resolved": "https://registry.npmjs.org/fast-uri/-/fast-uri-3.1.4.tgz",
+ "integrity": "sha512-8JnbkQ4juDyvYs4mgFGQqg4yCYtFDtUtmp2QIQq11ZZe5CFQ5wcqm1rqDgAh/QdMySuBnPzMUiJUNZG5N/AiQw==",
"funding": [
{
"type": "github",
@@ -11157,9 +11157,9 @@
"license": "MIT"
},
"node_modules/js-yaml": {
- "version": "4.2.0",
- "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.2.0.tgz",
- "integrity": "sha512-ePWsvanv0DWuDRsW8dnt+R4jQ31SCRCQ7hhNcPXZPsoBZiemuZNYGf7adZdqX2D86j6rvKp3RpCxVTSb8WQlOw==",
+ "version": "4.3.0",
+ "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.3.0.tgz",
+ "integrity": "sha512-1td788aAnnZ5qs7V2QIRl1owjtYpbKt749Y3xauqQgwIIGF/xXWz1wMTEBx5O3LK3lXLVuqXPdPxj2BoFHaW9Q==",
"funding": [
{
"type": "github",
@@ -13904,9 +13904,9 @@
}
},
"node_modules/nanoid": {
- "version": "3.3.11",
- "resolved": "https://registry.npmjs.org/nanoid/-/nanoid-3.3.11.tgz",
- "integrity": "sha512-N8SpfPUnUp1bK+PMYW8qSWdl9U+wwNWI4QKxOYDy9JAro3WMX7p2OeVRF9v+347pnakNevPmiHhNmZ2HbFA76w==",
+ "version": "3.3.16",
+ "resolved": "https://registry.npmjs.org/nanoid/-/nanoid-3.3.16.tgz",
+ "integrity": "sha512-bzlKTyNJ7+LdGIIwy8ijFpIqEQIvafahV7eYykJ8Cvh42EdJeODoJ6gUJXpQJvej1BddH8OqTXZNE/KfbWAu8Q==",
"funding": [
{
"type": "github",
@@ -14590,9 +14590,9 @@
}
},
"node_modules/postcss": {
- "version": "8.5.14",
- "resolved": "https://registry.npmjs.org/postcss/-/postcss-8.5.14.tgz",
- "integrity": "sha512-SoSL4+OSEtR99LHFZQiJLkT59C5B1amGO1NzTwj7TT1qCUgUO6hxOvzkOYxD+vMrXBM3XJIKzokoERdqQq/Zmg==",
+ "version": "8.5.25",
+ "resolved": "https://registry.npmjs.org/postcss/-/postcss-8.5.25.tgz",
+ "integrity": "sha512-DTPx3RWSSnWyzLxQnlH0rJP+EW5ekl16ZU4/psbIhA0e53kJfdgaN5vKM+xP7yJtXVu+nfdVFmlgFDEKAe4Pyw==",
"funding": [
{
"type": "opencollective",
@@ -14609,7 +14609,7 @@
],
"license": "MIT",
"dependencies": {
- "nanoid": "^3.3.11",
+ "nanoid": "^3.3.16",
"picocolors": "^1.1.1",
"source-map-js": "^1.2.1"
},
@@ -16346,24 +16346,24 @@
}
},
"node_modules/react": {
- "version": "19.2.7",
- "resolved": "https://registry.npmjs.org/react/-/react-19.2.7.tgz",
- "integrity": "sha512-HNe9WslTbXmFK8o8cmwgAeJFSBvt1bPdHCVKtaaV+WlAN36mpT4hcRpwbf3fY56ar2oIXzsBpOAiIRHAdY0OlQ==",
+ "version": "19.2.8",
+ "resolved": "https://registry.npmjs.org/react/-/react-19.2.8.tgz",
+ "integrity": "sha512-PWaYA1L/q9u2u7xYQi+Y3L3Yfnie7XyLeaJICV1MGD6LprsBxcAqGjYyr0eY3p+QdsA+x/Irkt4Qif8D63+Sbw==",
"license": "MIT",
"engines": {
"node": ">=0.10.0"
}
},
"node_modules/react-dom": {
- "version": "19.2.7",
- "resolved": "https://registry.npmjs.org/react-dom/-/react-dom-19.2.7.tgz",
- "integrity": "sha512-t0BRVXvbiE/o20Hfw669rLbMCDWtYZLvmJigy2f0MxsXF+71pxhR3xOkspmsO8h3ZlNzyibAmtCa3l4lYKk6gQ==",
+ "version": "19.2.8",
+ "resolved": "https://registry.npmjs.org/react-dom/-/react-dom-19.2.8.tgz",
+ "integrity": "sha512-rVprimfGBG3DR+Tq0IQG2DT5PxKth1WIGDmj5yPmlzr4YBe7uyE+Du4oVqTDXZSHGGGXRtTJEGSSePyQCMBglQ==",
"license": "MIT",
"dependencies": {
"scheduler": "^0.27.0"
},
"peerDependencies": {
- "react": "^19.2.7"
+ "react": "^19.2.8"
}
},
"node_modules/react-fast-compare": {
@@ -17661,9 +17661,9 @@
}
},
"node_modules/shell-quote": {
- "version": "1.8.4",
- "resolved": "https://registry.npmjs.org/shell-quote/-/shell-quote-1.8.4.tgz",
- "integrity": "sha512-VsC6n6vz1ihYYyZZwX7YZSF5l5x36ca17OC+a69h94YqB7X6XLwf+5MOgynYir2SLFUbl8gIYvBo8K8RoNQ6bQ==",
+ "version": "1.10.0",
+ "resolved": "https://registry.npmjs.org/shell-quote/-/shell-quote-1.10.0.tgz",
+ "integrity": "sha512-w1aiOKwKuRgtwAReIIj89puqg+I7GvX4IbLrvmhXbzQsj1+Zwi4VO3+fa6ZF91TWSjIxoEkKnMeHcLEODK5ZXA==",
"license": "MIT",
"engines": {
"node": ">= 0.4"
diff --git a/package.json b/package.json
index 2fac44c..2f253b2 100644
--- a/package.json
+++ b/package.json
@@ -1,6 +1,6 @@
{
"name": "shiftcontrol-docs",
- "version": "1.3.0",
+ "version": "1.3.1",
"private": true,
"scripts": {
"docusaurus": "docusaurus",
@@ -27,8 +27,8 @@
"lunr": "^2.3.9",
"posthog-docusaurus": "^2.0.5",
"prism-react-renderer": "^2.4.1",
- "react": "^19.2.7",
- "react-dom": "^19.2.7"
+ "react": "^19.2.8",
+ "react-dom": "^19.2.8"
},
"devDependencies": {
"@docusaurus/module-type-aliases": "^3.10.2",
diff --git a/screenshot-manifest.json b/screenshot-manifest.json
index e2d9ebc..cb4e37e 100644
--- a/screenshot-manifest.json
+++ b/screenshot-manifest.json
@@ -25,6 +25,8 @@
"_comment": "Direct-navigable IDs from mock data. Use these in URLs instead of clicking AG Grid rows.",
"user": "66b42ef6693525dd6b48d7ed",
"user_first_in_list": "66b417c8b170fe888e997f27",
+ "_note_user_ids_are_mode_specific": "The `user` ids above are JumpCloud Mongo ids and are only valid in jc_gws / jc_only. In gws_only, directory users are keyed by Google numeric ids (see mocks/data/gws_only/api/user/) — use 100000000000000000001. Reusing a JumpCloud id in gws_only silently resolves a record with no Google directory linkage, which hides Google-dependent affordances such as the avatar pencil badge.",
+ "user_gws_only": "100000000000000000001",
"group": "01912fd8-6663-7e31-b98b-9355bcc868be",
"group_with_dynamic": "01912fd8-c595-7dbf-b18d-bd9ea9f17574",
"app_aws": "01912fe5-9dd5-754c-9bfa-4d5f3a160ceb",
@@ -58,7 +60,11 @@
"app_discovery": "/admin/org/apps/discovery",
"dashboard_oauth": "/admin/dashboards/oauth",
"dashboard_spend": "/admin/dashboards/app-spend",
- "reports_assignments": "/admin/org/reports/apps/assignments"
+ "reports_assignments": "/admin/org/reports/apps/assignments",
+ "digital_cards_settings": "/settings/digital-cards",
+ "employee_my_card": "/my-card",
+ "user_detail_digital_card": "/admin/org/users/view/{user_id}?tab=digitalCard",
+ "device_inventory": "/admin/org/devices"
},
"modes": {
"jc_gws": { "folder": "jc-google", "params": "?mode=jc_gws", "label": "JumpCloud + Google Workspace" },
@@ -463,6 +469,93 @@
"modes": ["jc_gws", "jc_only", "gws_only"],
"component": "Screenshot",
"usedIn": ["docs/using-shiftcontrol/task-management.mdx"]
+ },
+ "DigitalCards/Card-template": {
+ "route": "/settings/digital-cards",
+ "tab": "Template",
+ "description": "Digital cards designer, Template sub-tab. Tab state is component-local — click the tab, there is no URL param. Panel is identical across modes; only the settings sidebar differs.",
+ "modes": ["jc_gws", "jc_only", "gws_only"],
+ "component": "ModeScreenshot",
+ "usedIn": ["docs/using-shiftcontrol/DigitalCards/Card-template.mdx", "docs/using-shiftcontrol/DigitalCards/Digital-cards-overview.mdx"]
+ },
+ "DigitalCards/Card-fields": {
+ "route": "/settings/digital-cards",
+ "tab": "Fields",
+ "description": "Digital cards designer, Fields sub-tab — per-field mode, sync toggles, and the employee self-service switches. Click the tab; there is no URL param.",
+ "modes": ["jc_gws", "jc_only", "gws_only"],
+ "component": "ModeScreenshot",
+ "usedIn": ["docs/using-shiftcontrol/DigitalCards/Card-fields.mdx"]
+ },
+ "DigitalCards/Card-offboarding": {
+ "route": "/settings/digital-cards",
+ "tab": "Offboarding",
+ "description": "Digital cards designer, Offboarding sub-tab — Generic card / Redirect / Hard 404 plus the grace-period stepper. Click the tab; there is no URL param.",
+ "modes": ["jc_gws", "jc_only", "gws_only"],
+ "component": "ModeScreenshot",
+ "usedIn": ["docs/using-shiftcontrol/DigitalCards/Card-offboarding.mdx"]
+ },
+ "DigitalCards/Card-domain": {
+ "route": "/settings/digital-cards",
+ "tab": "Domain",
+ "description": "Digital cards designer, Domain sub-tab — the always-on ShiftControl hostname and the custom-domain form. Click the tab; there is no URL param.",
+ "modes": ["jc_gws", "jc_only", "gws_only"],
+ "component": "ModeScreenshot",
+ "usedIn": ["docs/using-shiftcontrol/DigitalCards/Card-domain.mdx"]
+ },
+ "DigitalCards/User-card-panel": {
+ "route": "/admin/org/users/view/{user}?tab=digitalCard",
+ "description": "Digital card tab on a user record (admin-on-behalf). Sub-tabs are Edit card / QR code / Manage — no My card tab on this surface. Demo mock renders a different person on the card than in the record header, so keep alt text generic.",
+ "modes": ["jc_gws", "jc_only", "gws_only"],
+ "component": "ModeScreenshot",
+ "usedIn": ["docs/using-shiftcontrol/DigitalCards/Managing-a-users-card.mdx"]
+ },
+ "EmployeePortal/My-card": {
+ "route": "/my-card",
+ "tab": "My card",
+ "description": "Employee portal My card tab — live card, QR, copy link, and QR download sizes. Sidebar label is 'My digital card'. Click the tab; there is no URL param.",
+ "modes": ["jc_gws", "jc_only", "gws_only"],
+ "component": "ModeScreenshot",
+ "usedIn": ["docs/employee-guide/employee-portal/my-card.mdx"]
+ },
+ "EmployeePortal/My-card-edit": {
+ "route": "/my-card",
+ "tab": "Edit my card",
+ "description": "Employee portal Edit my card tab — photo controls and card details with locked / synced / customized field states.",
+ "modes": ["jc_gws", "jc_only", "gws_only"],
+ "component": "ModeScreenshot",
+ "usedIn": ["docs/employee-guide/employee-portal/my-card.mdx"]
+ },
+ "EmployeePortal/My-card-qr": {
+ "route": "/my-card",
+ "tab": "My QR code",
+ "description": "Employee portal My QR code tab — centre medallion picker (Company logo / None / My photo / Custom image).",
+ "modes": ["jc_gws", "jc_only", "gws_only"],
+ "component": "ModeScreenshot",
+ "usedIn": ["docs/employee-guide/employee-portal/my-card.mdx"]
+ },
+ "EmployeePortal/My-card-manage": {
+ "route": "/my-card",
+ "tab": "Manage",
+ "description": "Employee portal Manage tab — card status with publish/unpublish and the card PIN. Link regeneration only appears when the org allows it.",
+ "modes": ["jc_gws", "jc_only", "gws_only"],
+ "component": "ModeScreenshot",
+ "usedIn": ["docs/employee-guide/employee-portal/my-card.mdx"]
+ },
+ "Devices/Device-bulk-unmanage": {
+ "route": "/admin/org/devices",
+ "action": "Select 2+ device rows, then open the Bulk Actions toolbar button (4th icon after the search box). AG Grid checkboxes are NOT in the accessibility tree — click them by coordinate. The trigger is disabled below 2 selected rows. Close the Columns panel if a stray click opened it.",
+ "description": "Device Inventory with devices selected and the Bulk Actions menu open on Un-manage. Requires JumpCloud, so no gws_only variant.",
+ "modes": ["jc_gws", "jc_only"],
+ "component": "ModeScreenshot",
+ "usedIn": ["docs/using-shiftcontrol/Devices/Device-actions.mdx", "docs/using-shiftcontrol/Devices/Viewing-devices.mdx"]
+ },
+ "Users/User-avatar-upload": {
+ "route": "/admin/org/users/view/{user}",
+ "action": "Cropped region around the record-header avatar. The pencil badge renders ONLY when the user is linked in an enabled Google directory (AddOrEditUser.tsx gates it on isEligibleForAvatarUpload) — so you MUST use a mode-appropriate user id: a JumpCloud Mongo id such as 66b42ef6693525dd6b48d7ed for jc_gws, and a Google numeric id such as 100000000000000000001 for gws_only. Using the jc_gws id in gws_only resolves a record with no Google linkage: initials, no photo, no pencil. Note interceptor --region coordinates are in 2x CSS space, not CSS pixels.",
+ "description": "Avatar edit affordance that writes a user's Google Workspace profile photo. Requires a Google directory, so no jc_only variant.",
+ "modes": ["jc_gws", "gws_only"],
+ "component": "ModeScreenshot",
+ "usedIn": ["docs/using-shiftcontrol/Users/Editing-a-user.mdx"]
}
}
}
diff --git a/sidebars.ts b/sidebars.ts
index 8a969cb..34a60c0 100644
--- a/sidebars.ts
+++ b/sidebars.ts
@@ -147,6 +147,25 @@ const sidebars: SidebarsConfig = {
'using-shiftcontrol/Devices/Device-actions',
],
},
+ {
+ type: 'category',
+ label: 'Digital Cards',
+ link: {
+ type: 'generated-index',
+ title: 'Digital Cards',
+ description: 'Company-managed digital business cards — design one branded template, let employees activate their own card, and retire cards automatically when people leave.',
+ slug: '/using-shiftcontrol/DigitalCards',
+ keywords: ['digital cards','business cards','vcard','qr code'],
+ },
+ items: [
+ 'using-shiftcontrol/DigitalCards/Digital-cards-overview',
+ 'using-shiftcontrol/DigitalCards/Card-template',
+ 'using-shiftcontrol/DigitalCards/Card-fields',
+ 'using-shiftcontrol/DigitalCards/Card-offboarding',
+ 'using-shiftcontrol/DigitalCards/Card-domain',
+ 'using-shiftcontrol/DigitalCards/Managing-a-users-card',
+ ],
+ },
{
type: 'category',
label: 'Reports',
@@ -387,6 +406,7 @@ const sidebars: SidebarsConfig = {
'employee-guide/employee-portal/org-chart',
'employee-guide/employee-portal/app-permissions',
'employee-guide/employee-portal/my-devices',
+ 'employee-guide/employee-portal/my-card',
'employee-guide/employee-portal/account-security',
],
},
diff --git a/static/img/ShiftControl/Devices/jc-google/dark/Device-bulk-unmanage.webp b/static/img/ShiftControl/Devices/jc-google/dark/Device-bulk-unmanage.webp
new file mode 100644
index 0000000..86c203c
Binary files /dev/null and b/static/img/ShiftControl/Devices/jc-google/dark/Device-bulk-unmanage.webp differ
diff --git a/static/img/ShiftControl/Devices/jc-google/light/Device-bulk-unmanage.webp b/static/img/ShiftControl/Devices/jc-google/light/Device-bulk-unmanage.webp
new file mode 100644
index 0000000..672ad8b
Binary files /dev/null and b/static/img/ShiftControl/Devices/jc-google/light/Device-bulk-unmanage.webp differ
diff --git a/static/img/ShiftControl/Devices/jc-only/dark/Device-bulk-unmanage.webp b/static/img/ShiftControl/Devices/jc-only/dark/Device-bulk-unmanage.webp
new file mode 100644
index 0000000..034356f
Binary files /dev/null and b/static/img/ShiftControl/Devices/jc-only/dark/Device-bulk-unmanage.webp differ
diff --git a/static/img/ShiftControl/Devices/jc-only/light/Device-bulk-unmanage.webp b/static/img/ShiftControl/Devices/jc-only/light/Device-bulk-unmanage.webp
new file mode 100644
index 0000000..af56925
Binary files /dev/null and b/static/img/ShiftControl/Devices/jc-only/light/Device-bulk-unmanage.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/gws-only/dark/Card-domain.webp b/static/img/ShiftControl/DigitalCards/gws-only/dark/Card-domain.webp
new file mode 100644
index 0000000..b55ea3b
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/gws-only/dark/Card-domain.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/gws-only/dark/Card-fields.webp b/static/img/ShiftControl/DigitalCards/gws-only/dark/Card-fields.webp
new file mode 100644
index 0000000..f475489
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/gws-only/dark/Card-fields.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/gws-only/dark/Card-offboarding.webp b/static/img/ShiftControl/DigitalCards/gws-only/dark/Card-offboarding.webp
new file mode 100644
index 0000000..99fffdc
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/gws-only/dark/Card-offboarding.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/gws-only/dark/Card-template.webp b/static/img/ShiftControl/DigitalCards/gws-only/dark/Card-template.webp
new file mode 100644
index 0000000..071b4c0
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/gws-only/dark/Card-template.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/gws-only/dark/User-card-panel.webp b/static/img/ShiftControl/DigitalCards/gws-only/dark/User-card-panel.webp
new file mode 100644
index 0000000..9ac6958
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/gws-only/dark/User-card-panel.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/gws-only/light/Card-domain.webp b/static/img/ShiftControl/DigitalCards/gws-only/light/Card-domain.webp
new file mode 100644
index 0000000..0c00f59
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/gws-only/light/Card-domain.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/gws-only/light/Card-fields.webp b/static/img/ShiftControl/DigitalCards/gws-only/light/Card-fields.webp
new file mode 100644
index 0000000..1beb5b4
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/gws-only/light/Card-fields.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/gws-only/light/Card-offboarding.webp b/static/img/ShiftControl/DigitalCards/gws-only/light/Card-offboarding.webp
new file mode 100644
index 0000000..e24e5f4
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/gws-only/light/Card-offboarding.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/gws-only/light/Card-template.webp b/static/img/ShiftControl/DigitalCards/gws-only/light/Card-template.webp
new file mode 100644
index 0000000..8919596
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/gws-only/light/Card-template.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/gws-only/light/User-card-panel.webp b/static/img/ShiftControl/DigitalCards/gws-only/light/User-card-panel.webp
new file mode 100644
index 0000000..b12396a
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/gws-only/light/User-card-panel.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/jc-google/dark/Card-domain.webp b/static/img/ShiftControl/DigitalCards/jc-google/dark/Card-domain.webp
new file mode 100644
index 0000000..6551910
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/jc-google/dark/Card-domain.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/jc-google/dark/Card-fields.webp b/static/img/ShiftControl/DigitalCards/jc-google/dark/Card-fields.webp
new file mode 100644
index 0000000..2dfb0e4
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/jc-google/dark/Card-fields.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/jc-google/dark/Card-offboarding.webp b/static/img/ShiftControl/DigitalCards/jc-google/dark/Card-offboarding.webp
new file mode 100644
index 0000000..073b0cc
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/jc-google/dark/Card-offboarding.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/jc-google/dark/Card-template.webp b/static/img/ShiftControl/DigitalCards/jc-google/dark/Card-template.webp
new file mode 100644
index 0000000..ad7ec33
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/jc-google/dark/Card-template.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/jc-google/dark/User-card-panel.webp b/static/img/ShiftControl/DigitalCards/jc-google/dark/User-card-panel.webp
new file mode 100644
index 0000000..c489779
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/jc-google/dark/User-card-panel.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/jc-google/light/Card-domain.webp b/static/img/ShiftControl/DigitalCards/jc-google/light/Card-domain.webp
new file mode 100644
index 0000000..a34f416
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/jc-google/light/Card-domain.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/jc-google/light/Card-fields.webp b/static/img/ShiftControl/DigitalCards/jc-google/light/Card-fields.webp
new file mode 100644
index 0000000..124b3ea
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/jc-google/light/Card-fields.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/jc-google/light/Card-offboarding.webp b/static/img/ShiftControl/DigitalCards/jc-google/light/Card-offboarding.webp
new file mode 100644
index 0000000..fe40d43
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/jc-google/light/Card-offboarding.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/jc-google/light/Card-template.webp b/static/img/ShiftControl/DigitalCards/jc-google/light/Card-template.webp
new file mode 100644
index 0000000..f89b98f
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/jc-google/light/Card-template.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/jc-google/light/User-card-panel.webp b/static/img/ShiftControl/DigitalCards/jc-google/light/User-card-panel.webp
new file mode 100644
index 0000000..b806627
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/jc-google/light/User-card-panel.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/jc-only/dark/Card-domain.webp b/static/img/ShiftControl/DigitalCards/jc-only/dark/Card-domain.webp
new file mode 100644
index 0000000..f4ace4d
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/jc-only/dark/Card-domain.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/jc-only/dark/Card-fields.webp b/static/img/ShiftControl/DigitalCards/jc-only/dark/Card-fields.webp
new file mode 100644
index 0000000..855fa5c
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/jc-only/dark/Card-fields.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/jc-only/dark/Card-offboarding.webp b/static/img/ShiftControl/DigitalCards/jc-only/dark/Card-offboarding.webp
new file mode 100644
index 0000000..9c56c52
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/jc-only/dark/Card-offboarding.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/jc-only/dark/Card-template.webp b/static/img/ShiftControl/DigitalCards/jc-only/dark/Card-template.webp
new file mode 100644
index 0000000..d8d08ac
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/jc-only/dark/Card-template.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/jc-only/dark/User-card-panel.webp b/static/img/ShiftControl/DigitalCards/jc-only/dark/User-card-panel.webp
new file mode 100644
index 0000000..b375831
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/jc-only/dark/User-card-panel.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/jc-only/light/Card-domain.webp b/static/img/ShiftControl/DigitalCards/jc-only/light/Card-domain.webp
new file mode 100644
index 0000000..c715bc1
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/jc-only/light/Card-domain.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/jc-only/light/Card-fields.webp b/static/img/ShiftControl/DigitalCards/jc-only/light/Card-fields.webp
new file mode 100644
index 0000000..4d3eabe
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/jc-only/light/Card-fields.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/jc-only/light/Card-offboarding.webp b/static/img/ShiftControl/DigitalCards/jc-only/light/Card-offboarding.webp
new file mode 100644
index 0000000..1895270
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/jc-only/light/Card-offboarding.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/jc-only/light/Card-template.webp b/static/img/ShiftControl/DigitalCards/jc-only/light/Card-template.webp
new file mode 100644
index 0000000..6ea89a6
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/jc-only/light/Card-template.webp differ
diff --git a/static/img/ShiftControl/DigitalCards/jc-only/light/User-card-panel.webp b/static/img/ShiftControl/DigitalCards/jc-only/light/User-card-panel.webp
new file mode 100644
index 0000000..baa79b6
Binary files /dev/null and b/static/img/ShiftControl/DigitalCards/jc-only/light/User-card-panel.webp differ
diff --git a/static/img/ShiftControl/EmployeePortal/gws-only/dark/My-card-edit.webp b/static/img/ShiftControl/EmployeePortal/gws-only/dark/My-card-edit.webp
new file mode 100644
index 0000000..85014fd
Binary files /dev/null and b/static/img/ShiftControl/EmployeePortal/gws-only/dark/My-card-edit.webp differ
diff --git a/static/img/ShiftControl/EmployeePortal/gws-only/dark/My-card-manage.webp b/static/img/ShiftControl/EmployeePortal/gws-only/dark/My-card-manage.webp
new file mode 100644
index 0000000..c8a92fd
Binary files /dev/null and b/static/img/ShiftControl/EmployeePortal/gws-only/dark/My-card-manage.webp differ
diff --git a/static/img/ShiftControl/EmployeePortal/gws-only/dark/My-card-qr.webp b/static/img/ShiftControl/EmployeePortal/gws-only/dark/My-card-qr.webp
new file mode 100644
index 0000000..450bc08
Binary files /dev/null and b/static/img/ShiftControl/EmployeePortal/gws-only/dark/My-card-qr.webp differ
diff --git a/static/img/ShiftControl/EmployeePortal/gws-only/dark/My-card.webp b/static/img/ShiftControl/EmployeePortal/gws-only/dark/My-card.webp
new file mode 100644
index 0000000..31567fd
Binary files /dev/null and b/static/img/ShiftControl/EmployeePortal/gws-only/dark/My-card.webp differ
diff --git a/static/img/ShiftControl/EmployeePortal/gws-only/light/My-card-edit.webp b/static/img/ShiftControl/EmployeePortal/gws-only/light/My-card-edit.webp
new file mode 100644
index 0000000..7efa79e
Binary files /dev/null and b/static/img/ShiftControl/EmployeePortal/gws-only/light/My-card-edit.webp differ
diff --git a/static/img/ShiftControl/EmployeePortal/gws-only/light/My-card-manage.webp b/static/img/ShiftControl/EmployeePortal/gws-only/light/My-card-manage.webp
new file mode 100644
index 0000000..903cb8c
Binary files /dev/null and b/static/img/ShiftControl/EmployeePortal/gws-only/light/My-card-manage.webp differ
diff --git a/static/img/ShiftControl/EmployeePortal/gws-only/light/My-card-qr.webp b/static/img/ShiftControl/EmployeePortal/gws-only/light/My-card-qr.webp
new file mode 100644
index 0000000..91680e4
Binary files /dev/null and b/static/img/ShiftControl/EmployeePortal/gws-only/light/My-card-qr.webp differ
diff --git a/static/img/ShiftControl/EmployeePortal/gws-only/light/My-card.webp b/static/img/ShiftControl/EmployeePortal/gws-only/light/My-card.webp
new file mode 100644
index 0000000..ddbf303
Binary files /dev/null and b/static/img/ShiftControl/EmployeePortal/gws-only/light/My-card.webp differ
diff --git a/static/img/ShiftControl/EmployeePortal/jc-google/dark/My-card-edit.webp b/static/img/ShiftControl/EmployeePortal/jc-google/dark/My-card-edit.webp
new file mode 100644
index 0000000..62b0170
Binary files /dev/null and b/static/img/ShiftControl/EmployeePortal/jc-google/dark/My-card-edit.webp differ
diff --git a/static/img/ShiftControl/EmployeePortal/jc-google/dark/My-card-manage.webp b/static/img/ShiftControl/EmployeePortal/jc-google/dark/My-card-manage.webp
new file mode 100644
index 0000000..c895a4a
Binary files /dev/null and b/static/img/ShiftControl/EmployeePortal/jc-google/dark/My-card-manage.webp differ
diff --git a/static/img/ShiftControl/EmployeePortal/jc-google/dark/My-card-qr.webp b/static/img/ShiftControl/EmployeePortal/jc-google/dark/My-card-qr.webp
new file mode 100644
index 0000000..ebfa4ee
Binary files /dev/null and b/static/img/ShiftControl/EmployeePortal/jc-google/dark/My-card-qr.webp differ
diff --git a/static/img/ShiftControl/EmployeePortal/jc-google/dark/My-card.webp b/static/img/ShiftControl/EmployeePortal/jc-google/dark/My-card.webp
new file mode 100644
index 0000000..03c8c6f
Binary files /dev/null and b/static/img/ShiftControl/EmployeePortal/jc-google/dark/My-card.webp differ
diff --git a/static/img/ShiftControl/EmployeePortal/jc-google/light/My-card-edit.webp b/static/img/ShiftControl/EmployeePortal/jc-google/light/My-card-edit.webp
new file mode 100644
index 0000000..211a0d0
Binary files /dev/null and b/static/img/ShiftControl/EmployeePortal/jc-google/light/My-card-edit.webp differ
diff --git a/static/img/ShiftControl/EmployeePortal/jc-google/light/My-card-manage.webp b/static/img/ShiftControl/EmployeePortal/jc-google/light/My-card-manage.webp
new file mode 100644
index 0000000..0a0da21
Binary files /dev/null and b/static/img/ShiftControl/EmployeePortal/jc-google/light/My-card-manage.webp differ
diff --git a/static/img/ShiftControl/EmployeePortal/jc-google/light/My-card-qr.webp b/static/img/ShiftControl/EmployeePortal/jc-google/light/My-card-qr.webp
new file mode 100644
index 0000000..df657a1
Binary files /dev/null and b/static/img/ShiftControl/EmployeePortal/jc-google/light/My-card-qr.webp differ
diff --git a/static/img/ShiftControl/EmployeePortal/jc-google/light/My-card.webp b/static/img/ShiftControl/EmployeePortal/jc-google/light/My-card.webp
new file mode 100644
index 0000000..72d4a6d
Binary files /dev/null and b/static/img/ShiftControl/EmployeePortal/jc-google/light/My-card.webp differ
diff --git a/static/img/ShiftControl/EmployeePortal/jc-only/dark/My-card-edit.webp b/static/img/ShiftControl/EmployeePortal/jc-only/dark/My-card-edit.webp
new file mode 100644
index 0000000..3a0c2d4
Binary files /dev/null and b/static/img/ShiftControl/EmployeePortal/jc-only/dark/My-card-edit.webp differ
diff --git a/static/img/ShiftControl/EmployeePortal/jc-only/dark/My-card-manage.webp b/static/img/ShiftControl/EmployeePortal/jc-only/dark/My-card-manage.webp
new file mode 100644
index 0000000..0118efa
Binary files /dev/null and b/static/img/ShiftControl/EmployeePortal/jc-only/dark/My-card-manage.webp differ
diff --git a/static/img/ShiftControl/EmployeePortal/jc-only/dark/My-card-qr.webp b/static/img/ShiftControl/EmployeePortal/jc-only/dark/My-card-qr.webp
new file mode 100644
index 0000000..85529c4
Binary files /dev/null and b/static/img/ShiftControl/EmployeePortal/jc-only/dark/My-card-qr.webp differ
diff --git a/static/img/ShiftControl/EmployeePortal/jc-only/dark/My-card.webp b/static/img/ShiftControl/EmployeePortal/jc-only/dark/My-card.webp
new file mode 100644
index 0000000..de2de1c
Binary files /dev/null and b/static/img/ShiftControl/EmployeePortal/jc-only/dark/My-card.webp differ
diff --git a/static/img/ShiftControl/EmployeePortal/jc-only/light/My-card-edit.webp b/static/img/ShiftControl/EmployeePortal/jc-only/light/My-card-edit.webp
new file mode 100644
index 0000000..ce34cf4
Binary files /dev/null and b/static/img/ShiftControl/EmployeePortal/jc-only/light/My-card-edit.webp differ
diff --git a/static/img/ShiftControl/EmployeePortal/jc-only/light/My-card-manage.webp b/static/img/ShiftControl/EmployeePortal/jc-only/light/My-card-manage.webp
new file mode 100644
index 0000000..ed0e712
Binary files /dev/null and b/static/img/ShiftControl/EmployeePortal/jc-only/light/My-card-manage.webp differ
diff --git a/static/img/ShiftControl/EmployeePortal/jc-only/light/My-card-qr.webp b/static/img/ShiftControl/EmployeePortal/jc-only/light/My-card-qr.webp
new file mode 100644
index 0000000..09b7ffe
Binary files /dev/null and b/static/img/ShiftControl/EmployeePortal/jc-only/light/My-card-qr.webp differ
diff --git a/static/img/ShiftControl/EmployeePortal/jc-only/light/My-card.webp b/static/img/ShiftControl/EmployeePortal/jc-only/light/My-card.webp
new file mode 100644
index 0000000..6b9f6ff
Binary files /dev/null and b/static/img/ShiftControl/EmployeePortal/jc-only/light/My-card.webp differ
diff --git a/static/img/ShiftControl/Users/gws-only/dark/User-avatar-upload.webp b/static/img/ShiftControl/Users/gws-only/dark/User-avatar-upload.webp
new file mode 100644
index 0000000..fc478d6
Binary files /dev/null and b/static/img/ShiftControl/Users/gws-only/dark/User-avatar-upload.webp differ
diff --git a/static/img/ShiftControl/Users/gws-only/light/User-avatar-upload.webp b/static/img/ShiftControl/Users/gws-only/light/User-avatar-upload.webp
new file mode 100644
index 0000000..4a57b7b
Binary files /dev/null and b/static/img/ShiftControl/Users/gws-only/light/User-avatar-upload.webp differ
diff --git a/static/img/ShiftControl/Users/jc-google/dark/User-avatar-upload.webp b/static/img/ShiftControl/Users/jc-google/dark/User-avatar-upload.webp
new file mode 100644
index 0000000..124e7f7
Binary files /dev/null and b/static/img/ShiftControl/Users/jc-google/dark/User-avatar-upload.webp differ
diff --git a/static/img/ShiftControl/Users/jc-google/light/User-avatar-upload.webp b/static/img/ShiftControl/Users/jc-google/light/User-avatar-upload.webp
new file mode 100644
index 0000000..b86b633
Binary files /dev/null and b/static/img/ShiftControl/Users/jc-google/light/User-avatar-upload.webp differ