Installation & Administration

CardIQ Troubleshooting Guide

Diagnose setup, deployment and integration problems without exposing credentials or weakening production controls.

HTTP 500 and database failures

HTTP 500 and database failures

Review private PHP/web logs without showing stack traces publicly. Confirm config.php exists on hosting, syntax and required PHP capabilities, database connectivity and privileges, migration state and minimal file permissions. Keep production error display disabled. Stop after a migration error and compare the current schema and ordered release instructions before any retry.

Login and invitation email

Login and invitation email

For login, verify user activation and role, company lifecycle state, employee status, session/cookie behavior and HTTPS. For Entra-based enterprise sign-in, confirm company entitlement, Entra configuration and readiness rather than assuming SSO is active. For missing invitations, verify invitation state, SMTP configuration, sender, port/encryption compatibility, spam filtering and safe mail diagnostics/private logs.

Microsoft Entra and SCIM

Microsoft Entra and SCIM

For Entra preview/sync/reconciliation issues, confirm tenant configuration, selected allowlisted groups, Microsoft permissions, dry-run/review state, monitor-only versus auto-apply policy, scheduler execution and circuit-breaker/large-change safeguards. For SCIM Users provisioning, validate the tenant-scoped token, endpoint reachability, filter/pagination behavior, mapping/idempotency and deactivation/reactivation flow. SCIM Groups and Bulk are not supported.

QR/profile and Wallet

QR/profile and Wallet

Confirm employee activation, company lifecycle, public-profile publication, slug and the QR/NFC destination. After deactivation, a stable link may resolve to a controlled inactive experience rather than disappear. For Wallet issuance, confirm lifecycle eligibility, provider configuration, valid HTTPS public URLs and private logs.

API, webhook and operational health

API, webhook and operational health

For API failures, verify the active scoped credential, authorization, company lifecycle and endpoint entitlement without logging full credentials. For webhook failures, confirm the HTTPS callback, signing value, receiving-server status, firewall/egress policy, retries and sanitized delivery logs. Before escalation, confirm public HTTPS, database reachability, SMTP, admin login, public profiles, QR generation, configured integrations, lifecycle enforcement, audit records and verified backups.

Control how employees represent your company externally

Explore the CardIQ platform or review the workflow from verification through identity deactivation.

See how CardIQ works View pricing