Observe and govern
Guide Available

Platform Administration and Oversight

Platform authority is intentionally separate from Organization Membership. Platform View exposes dedicated, allowlisted projections and administrative workflows without turning a Platform Administrator into a tenant user.

For
Platform administrators
On this page
  1. Current administration surface
  2. Current oversight data
  3. Event Delivery monitoring
  4. Deferred platform work
  5. Data boundary
01

Current administration surface

Platform Administrators can list users and Organizations, provision pending users with an initial Organization, resend invitations, and grant or revoke Platform Privilege with a reason. Privilege changes reject no-ops, self-revocation, and removal of the final Platform Administrator.

02

Current oversight data

Platform View includes allowlisted Organization and user identity detail, Membership drill-downs, current Agent counts, cross-Organization chat volume, and Agent activity statistics. Period and filters can narrow by Organization, Agent, creator, or chat Platform. Sender identity and tenant content are excluded.

03

Event Delivery monitoring

A read-only global monitor shows Event Delivery counts, stale/unknown ages, and a filtered explorer. It reads PostgreSQL rather than raw Redis and exposes safe operational metadata, not the event envelope or full payload. Retry, replay, remapping, and deletion are intentionally absent.

04

Deferred platform work

The backlog proposes Organization suspension with immediate access denial and asynchronous runtime cleanup, a unified searchable Security Audit explorer, and deeper Agent, Tool Call, model, and cost oversight. Suspension must commit before cleanup and reactivation must wait for cleanup completion; these are accepted design constraints for future implementation, not shipped controls.

05

Data boundary

Platform oversight must never expose conversation content, tool arguments or results, logs, prompts, Templates, Skills, Agent configuration, credentials, or raw Telemetry. New fields require explicit data-classification and authorization review.

Documentation