Admin Guide
Configuring a tenant
Nine guides to configuring a tenant: users and access, item types, custom lists, templates, data, AI, sign-on, settings, and the audit trail.
Administrators decide what a tenant tracks, who can see it, how work moves through it, and which agents are allowed to help. Almost every choice here is visible to somebody else as a page they can or cannot open, a field they must fill, or a button that is not there. These guides are written around that: what you change, and what your colleagues see afterwards.
The Admin entry appears in the top navigation only for administrators.
The Administration page
Section titled “The Administration page”Six cards, one per configuration area:
| Card | Route | What it governs | Guide |
|---|---|---|---|
| User Permissions | /admin/permissions |
Accounts, page access, item access, the admin flag. | Users and access |
| Item Types | /admin/item-types |
The record types your tenant tracks and their fields. | Item types and fields |
| AI Integrations | /admin/oauth-clients |
Which AI platforms may connect, and on what terms. | AI integrations |
| System Settings | /admin/settings |
Sign-in providers, allowed domains, document validation, branding. | Tenant settings |
| Data Management | /admin/bulk-import |
Exports, JSON imports, CSV user imports. | Imports and exports |
| Admin Activity | /admin/activity |
The audit trail for everything above. | Activity log |
Three more surfaces are yours to govern without being cards on that page:
| Surface | Where it is | Guide |
|---|---|---|
| Custom lists | /admin/custom-lists, reached directly |
Custom lists |
| Workflow templates | The Templates page in the top navigation | Workflow templates |
| Single sign-on | The System Settings card, plus support for SAML | Single sign-on |
Start from what you need to do
Section titled “Start from what you need to do”| I need to | Read |
|---|---|
| Add somebody, or fix what they can see | Users and access |
| Model a new kind of record | Item types and fields |
| Fix a dropdown that is missing an option | Custom lists |
| Standardize a process people keep improvising | Workflow templates |
| Load a dataset, or take a copy of the configuration | Imports and exports |
| Let people connect Claude, ChatGPT, Gemini, or Copilot | AI integrations |
| Turn on Google, Microsoft, or SAML sign-in | Single sign-on |
| Change something that affects the whole tenant | Tenant settings |
| Work out who changed something, and when | Activity log |
Your first hour on a new tenant
Section titled “Your first hour on a new tenant”Configuration has real dependencies, and the order below respects them. Jumping to an import before any item types exist leaves nothing to import into.
- Sign-in. Confirm you can get in, then decide how everyone else will: providers, allowed domains, or accounts you create by hand. Single sign-on
- Custom lists. Create the shared vocabularies your fields will reference, before the fields reference them. Custom lists
- Item types and fields. Model the records the tenant will track. Slugs and field keys are the decisions that outlive everything else here. Item types and fields
- People and access. Create the accounts and grant the pages, now that there are pages worth granting. Users and access
- Workflow templates. Build the repeatable processes that run against those records. Workflow templates
- Data. Import what you already have, once the shape it lands in exists. Imports and exports
- AI integrations. Enable the platforms your organization uses, once there is something for an agent to be useful about. AI integrations
Editions
Section titled “Editions”Some configuration is gated by edition. On Studio, the Item Types card is hidden and its editor shows an upgrade notice, and on the Custom Lists page creating and deleting values are unavailable while editing labels and toggling values active still work. Enterprise SAML is licensed separately. Each guide notes its own gating where it applies.
What administrators cannot do
Section titled “What administrators cannot do”Two limits are worth knowing before somebody asks you to work around them:
- You cannot see more than your permissions allow by accident. The admin flag grants access to every page deliberately and visibly, and every use of it is recorded.
- No agent can configure the tenant. Creating a user, granting a page, registering a client, and reshaping an item type are not proposable by an agent at all. Agents read your configuration and propose changes to records, which a person then approves. See Reviewing suggestions.