Working With The Society Secret Club
I ran into issues with The Society Secret Club when I was setting up access controls for a small team. The documentation is sparse and the onboarding process assumes you already know what you are doing, which is annoying if you are coming in cold. I spent about three hours trying to get the initial configuration right before figuring out what was actually required. The core workflow is straightforward once you understand the sequence. You need a valid invitation code before anything else. Without one, you cannot register an account or access the dashboard. These codes are distributed through verified channels only, and the platform does not allow self-signup. I learned that the hard way when I tried to create a test account with a placeholder email address. After you obtain the invitation, you will need to verify your identity through their KYC pipeline. This is not optional. The system will ask for a government ID and a live photo capture. Processing typically takes between 20 minutes and 48 hours depending on workload. I submitted my documents on a Friday evening and had access by Monday morning. Weekend submissions seem to pile up.
Once verified, you get assigned a tier level. Most people start at Tier 2. Tier 1 has limited features and strict rate limits. Tier 3 unlocks the advanced routing and bulk operations. To reach Tier 3, you need to maintain a minimum activity threshold over a rolling 30 day window. I found that hitting that threshold required consistent daily usage, not just a burst of activity one week and then silence the next.
Configuration Details
The settings panel is organized into four sections: Access Control, Notification Preferences, Data Retention, and Integration Points. The Access Control section is where most problems occur. The default permissions are overly broad, which creates friction when you need to restrict what certain users can do. I had to manually tighten permissions for about a dozen roles because the preset bundles did not match our actual workflow. Notification preferences can be adjusted at the user level or at the group level. Group level settings override individual preferences, which is the opposite of what most people expect. If you are managing a large team, set your group defaults first before you start tweaking individual accounts. Otherwise you will spend hours adjusting settings that get overwritten the next time an admin updates the group policy. Data retention defaults to 90 days for audit logs and 12 months for activity history. You can extend this, but there is no way to retroactively change retention for data that already exists. I lost a few months of logs when our storage policy was updated by a previous admin, and we had no way to recover them. Make sure you export whatever you need before any policy change goes live.
Get the Full Details

Common Pitfalls and Workarounds
One issue that catches people off guard is the session timeout behavior. The platform forces a re-authentication after 4 hours of inactivity, but it does not warn you before it happens. I have lost work multiple times because I left a configuration tab open overnight and came back to a logged out session with no autosave. The workaround is simple: keep a browser extension or script that monitors for inactivity and saves your state periodically. I wrote a quick Python script using Selenium that auto-refreshes the page every 23 minutes to prevent the timeout from firing. Another problem is the API rate limiting. The free tier allows 100 requests per minute, but the documentation does not clearly state what counts as a request. A single page load can trigger up to eight separate API calls behind the scenes. If you are doing heavy automation, your effective rate is much lower than advertised. I reduced my throughput by implementing a queue with exponential backoff, which cut my failed requests from roughly 40 percent down to under 5 percent. The integration endpoints are RESTful but they return different error codes depending on whether you are authenticated via OAuth or API key. I spent an afternoon debugging a 403 error only to realize that the OAuth token had expired mid-request while the API key was still valid. The fix was to implement token refresh logic before each batch operation instead of assuming the token stays good for the duration of a script run.
Download and Resources
There is no standalone download for The Society Secret Club since it is a web-based platform. However, there is a companion desktop client available through their developer portal. The desktop client is useful for offline configuration and batch operations. It syncs changes back to the cloud whenever a connection is established. I use it primarily for scheduling repetitive tasks that need to run during off-peak hours when the web interface tends to be slow. For those looking for an alternative, the ecosystem has a few competing platforms. AccessGate and CloudVault both offer similar functionality with better documentation and more generous free tiers. I would recommend evaluating those first if you are just starting out. The Society Secret Club has some advantages in terms of community support and third-party integrations, but the learning curve is steeper than it should be.