Skip to content

Administration

Where to find it: Administration (/admin/users and /settings/*).

Administration is where a tenant is configured: who can do what, how approvals route, what the deadlines are, and how the platform connects to the outside world.


The configuration surfaces

PageRoutePurpose
Users & Roles/admin/usersUser accounts, roles, permissions and organisational units
Workflow Settings/settings/workflowApproval chains, stages and bindings
SLA & Deadlines/settings/slaDeadline policy, reminders and escalation
Taxonomies/settings/taxonomiesClassification trees and entity tagging
Risk Methodology/settings/risk-methodologyScoring, appetite and review cadence
Notification Providers/settings/notificationsDelivery channels
Alert Policies/settings/alert-policiesConditions, recipients and sweeps
Integrations/settings/integrationsAPI keys and webhooks
AI Settings/settingsTenant AI configuration

Articles

ArticleWhat it covers
Users & RolesAccounts, roles, permission scopes and organisational units
EntitlementsWhat each tenant entitlement unlocks
Workflow ConfigurationConfiguring approval chains and their consequences
Tenant SettingsReporting currency, taxonomies and general configuration
SLA & DeadlinesDeadline policy, reminders and escalation
Notification ProvidersDelivery channels and alert policies
AI Provider SettingsTenant AI configuration and what is customer-configurable
IntegrationsAPI keys and webhooks
Security BoundariesTenant isolation and the platform boundary

The separation to understand first

Administering the system is not the same as exercising judgement within it

Certain permissions are never auto-granted, including to Tenant Administrators:

  • tprm.assess — governed third-party risk assessment
  • tprm.classify — regulatory classification
  • tprm.decide — engagement approval
  • assessment.review_self_override — the segregation-of-duties break-glass

A Tenant Administrator can configure the platform completely and still be unable to approve a material outsourcing arrangement.

This is deliberate. Whoever maintains the platform is not thereby qualified to make professional governance decisions inside it.

See Segregation of Duties.


The platform boundary

Tenant administration and platform administration are different things with different audiences.

Tenant administrationPlatform administration
ScopeYour tenantThe service
WhoYour administratorsThe service operator
CoversUsers, roles, workflow, settings, integrationsTenants, provisioning, deployments, platform security
DocumentedHereNot in customer documentation

Platform-console permissions are deliberately outside the tenant permission catalogue and can never be represented in a tenant role.


Permissions

ActionPermission
View tenant settings and policiessettings.read
Edit tenant settings and policiessettings.manage
Configure SLA and deadline policysla.configure
Capture requirement and framework deadlinesdeadline.configure
Configure workflowsworkflow.configure
Manage usersusers.*
Manage rolesroles.*
Manage organisational unitsorg_units.manage
Manage API keys and webhooksapi.manage, webhook.manage
Read the audit trailaudit.read

OrviQ Enterprise Governance, Risk & Compliance Platform