Scope

This track is for platform administrators: identity, integrations, approvals, audit, and

incident command. It assumes you have completed the End-User guide and hold the

Administrator role.

The admin model

elevation over standing admin.

is blocked by design.

(SHA-256 hash-chain, WORM). Assume your actions will be reviewed.

Standard admin roles

RoleCan doCannot do
User AdminInvite/disable users, reset MFAChange policy, touch data
Security AdminPolicies, controls, integrationsBilling, tenant deletion
Platform AdminEverything within the tenantCross-tenant / billing
AuditorRead-only audit + evidenceAny change

The approval gate

Gated action types (examples): bulk approvals, VM patch application, destructive data operations,

tenant deletion, policy publish, secret rotation. Each flows through the approval queue with:

  1. Justification (why) and blast radius (what it affects).
  2. Evidence attachment (scan result, change ticket, test output).
  3. Two-person approval with rationale recorded.

Change discipline

← Administrator Guide  ·  All guidelines