Administrator Guide
Manage tenants, users, roles, quotas, security, and platform settings.
22 min read Updated 2026-07-18
Administrator Guide
For platform admins and tenant admins. Covers user management, RBAC, quotas, security posture, and operational hygiene.
Access levels
| Role | Scope | |------|-------| | Super Admin | Global, cross-tenant | | Tenant Admin | Single tenant, all modules | | Manager | Assigned team, most modules | | Agent | Assigned conversations | | Viewer | Read-only |
Roles live in public.user_roles and are checked by the has_role(uuid, app_role) security-definer function. Never store roles on the profile table.
Managing tenants
- Super Admin → Tenants — create, suspend, or delete tenants
- Tenant → Users — invite, remove, or promote users
- Billing → Plan — set plan, seat count, quotas
- Quotas — 17 resource meters; overages trigger alerts and (optionally) hard caps
Security posture
- Enable MFA for all admins under Security Center → Access Controls
- Configure IP allowlists per tenant
- Review the audit timeline weekly
- Rotate API keys every 90 days
Health hygiene
- Weekly: check Monitoring Center for red status
- Weekly: verify backups completed (see Backup Management)
- Monthly: review Compliance Center privacy requests