Skip to content

Tenant Administrator Guide

This guide defines the administrative responsibilities, configuration workspaces, security boundaries, and governance principles for Tenant Administrators (tenant_admin) managing an OrviQ tenant organization.


1. What This Role Does in OrviQ

The Tenant Administrator is the custodian of the organization's tenant environment. While compliance and risk managers govern substantive GRC content, the Tenant Administrator governs the operational infrastructure and security guardrails:

  • User lifecycle management: provisioning, role assignments, status management (active, suspended).
  • Role-Based Access Control (RBAC) governance and permission validation against active license entitlements.
  • Organizational workflow configuration: defining multi-eye review stages (4-eye, 6-eye, 8-eye) and segregation-of-duties rules.
  • Operational parameters: SLA deadline allocation, notification provider connections, and enterprise audit log oversight.

2. Primary Workspaces

Tenant Administrators operate primarily within the Administration domain:

WorkspaceRouteKey Administrative Activities
Users & Roles/admin/usersProvision users, assign RBAC roles, deactivate accounts, and inspect role permissions.
Enterprise Audit Log/admin/audit-logInspect immutable audit trails across all user actions, logins, and workflow events.
Workflow Settings/settings/workflowConfigure multi-eye workflow templates, approval stages, and segregation-of-duties rules.
SLA & Deadlines/settings/slaConfigure task deadline durations, warning thresholds, and escalation rules.
Taxonomies/settings/taxonomiesConfigure enterprise classification categories for risks, controls, and policies.
Notification Providers/settings/notificationsConfigure SMTP email servers and webhook integrations for system alerts.
Alert Policies/settings/alert-policiesDefine organizational alert distribution rules and recipient groups.
Integrations/settings/integrationsManage API tokens, external security connectors, and third-party webhooks.

3. Typical Administrative Workflow

User Provisioning & RBAC Lifecycle

  1. Provision New User: Navigate to Administration > Users & Roles (/admin/users). Click + Add User.
  2. Assign Organizational Details: Provide full name, enterprise email address, department, and initial role assignment.
  3. Select Role Template: Assign the appropriate canonical role based on least privilege:
    • compliance_manager / compliance_officer
    • risk_manager
    • control_owner
    • auditor
  4. Inspect Effective Permissions: Use the RBAC inspector tab to confirm that assigned permissions match the user's operational needs and active tenant entitlements.
  5. Deprovisioning: When an employee departs or changes roles, immediately update their account status to inactive or reassign their role. Account history and past audit stamps remain preserved.

Workflow & Governance Configuration

  1. Configure Review Stages: Navigate to Administration > Workflow Settings (/settings/workflow). Review default workflow templates (e.g., Policy Publication, Evidence Approval, Risk Acceptance).
  2. Enforce Multi-Eye Archetypes: Select the required review depth:
    • 4-Eye: 1 Maker + 1 Independent Checker.
    • 6-Eye: 1 Maker + 2 Sequential Independent Checkers.
    • 8-Eye: 1 Maker + 3 Independent Checkers (for critical risk acceptance or statutory policy publication).
  3. Set SLA Deadlines: Navigate to Administration > SLA & Deadlines (/settings/sla). Set duration limits (e.g., 5 business days for evidence review, 10 days for policy draft review).

System Health & Audit Inspection

  1. Review Notification Delivery: In /settings/notifications, verify email delivery health and webhook response codes.
  2. Inspect Enterprise Audit Log: Regularly review /admin/audit-log for administrative changes, role modifications, failed login attempts, or abnormal export volumes.

4. Approvals & Segregation-of-Duties (SoD) Boundaries

OrviQ enforces strict administrative guardrails to maintain tenant integrity:

  • Anti-Lockout Protection: The system prevents deleting or deactivating the last active tenant_admin account.
  • Administrative Privileges $\neq$ Operational Bypass: Holding the tenant_admin role does not allow bypassing business segregation-of-duties rules. If an administrator creates a crosswalk mapping or authors a policy draft, they cannot act as the checker/approver for that record.
  • Audit Trail Immutability: Tenant administrators cannot purge, alter, or backdate entries in the Enterprise Audit Log. All database mutations are write-only with immutable sequence timestamps.
  • Tenant Isolation: Tenant administrative privileges are strictly confined to the tenant's cryptographic data boundary. A tenant administrator cannot access other tenant organizations.

5. What the System Does NOT Imply

Tenant Administrators must understand the boundary between configuration and compliance:

Semantic Guardrails

  • Role Provisioned $\neq$ User Competent / Compliant: Granting an employee the control_owner or compliance_officer role enables technical permissions in the software; it does not verify individual competency or legal qualification.
  • Workflows Configured $\neq$ Governance Proven: Setting up 6-eye approval templates provides organizational machinery; governance defensibility requires that reviewers actively inspect evidence and record substantive rationales.
  • SLA Timers Active $\neq$ Controls Timely: SLA configuration monitors process velocity; it does not guarantee that operational controls operated in a timely manner.
  • Admin Access $\neq$ Substantive Sign-Off: Tenant configuration actions do not constitute formal compliance or risk determinations.

6. Where to Learn More

OrviQ Enterprise Governance, Risk & Compliance Platform