Current administration surface
Platform Administrators can list users and Organizations, provision pending users with an initial Organization, resend invitations, and grant or revoke Platform Privilege with a reason. Privilege changes reject no-ops, self-revocation, and removal of the final Platform Administrator.
Current oversight data
Platform View includes allowlisted Organization and user identity detail, Membership drill-downs, current Agent counts, cross-Organization chat volume, and Agent activity statistics. Period and filters can narrow by Organization, Agent, creator, or chat Platform. Sender identity and tenant content are excluded.
Event Delivery monitoring
A read-only global monitor shows Event Delivery counts, stale/unknown ages, and a filtered explorer. It reads PostgreSQL rather than raw Redis and exposes safe operational metadata, not the event envelope or full payload. Retry, replay, remapping, and deletion are intentionally absent.
Deferred platform work
The backlog proposes Organization suspension with immediate access denial and asynchronous runtime cleanup, a unified searchable Security Audit explorer, and deeper Agent, Tool Call, model, and cost oversight. Suspension must commit before cleanup and reactivation must wait for cleanup completion; these are accepted design constraints for future implementation, not shipped controls.
Data boundary
Platform oversight must never expose conversation content, tool arguments or results, logs, prompts, Templates, Skills, Agent configuration, credentials, or raw Telemetry. New fields require explicit data-classification and authorization review.