Administering your organization

Where the administration pages are, which of them you can open, and the role a new organization starts with.

For anyone who holds at least one administrative permission in their organization (tenant). Each area needs its own permission, listed below.

Opening the administration

Keel Platform serves many organizations, each called a tenant, at its own address such as /tenants/hanseatic-shipping. Everything on these pages concerns your own tenant only.

  1. Sign in to your organization (see Signing in).
  2. Open the settings menu, the gear icon at the top right of every page. If you hold no administrative permission, the icon is not there.
  3. Choose Administration (followed by your organization's name), or go straight to one area listed under it.

The page Administration opens at /tenants/<your tenant>/admin. It shows one card for each area you may enter, each with a sentence on what it holds and, for some, one figure worth knowing before you go in.

The administration page: one card per area you may enter.
The administration page: one card per area you may enter.

The areas and the permission each needs

A card appears only to someone who holds its permission, and the page behind it refuses everyone else. Permissions are bundled into roles; see Roles and permissions.

CardWhat you do therePermissionFigure on the card
PeopleAdd members, deactivate them, grant them roles. See People.manage usersActive members, and how many permanently hold access control
Roles and permissionsDefine roles and what they permit. See Roles and permissions.manage rolesNumber of roles
GroupsGather members and grant roles to all of them at once. See Groups.manage groupsNumber of groups
ConfigurationThe organization's settings. See Settings.manage configurationNone
Encryption keysRotate the customer managed key. See The encryption key.manage encryption keysNone
BillingLicenses, subscription, balance, invoices. See Billing and licenses.manage tenant billingWhether a license is in force, and until when
AuditWho changed what, and when. See The audit log.Any of the permissions above, or any permission the application addsNone

The application your organization uses may add its own cards and menu entries, with its own permissions. A custom permission you define yourself (see Custom permissions) does not open the administration.

The role a new organization starts with

When your organization is created, the first person is granted the role Tenant Setup Administrator. It holds every built-in permission: manage users, roles, groups, configuration, tenant billing and encryption keys. Its description reads "Full administration of the tenant, granted to its creator at setup".

The role is an ordinary role. You can rename it, change what it permits, grant it to others, or carve narrower roles out of it, such as a billing manager who holds only manage tenant billing. Giving each person only the permissions their job needs keeps mistakes small and the audit log easy to read.

Keeping someone in charge

Two permissions together make up access control: manage users and manage roles. Whoever holds both can always repair everything else. Keel Platform counts the active members who hold both permanently, that is, through a role granted with no end date. The People card shows that count; when it is one, the card says "grant a second".

To protect your organization from locking itself out, Keel Platform refuses a change that would:

  • leave nobody permanently holding access control. The message reads "This change would leave nobody permanently holding access control (manage users and manage roles)."
  • drop the count from two or more to just one. The message reads "This change would leave a single user permanently holding access control."
  • take access control away from you yourself. The message reads "You would lose the ability to manage users and roles yourself." Ask another administrator to make that change.

The guard applies to deactivating a member, revoking a role from a person or a group, removing a member from a group, archiving a role or a group, and changing a role's permissions.

If everyone who held access control is gone anyway, the operators of your Keel Platform site can grant the Tenant Setup Administrator role to an address you give them.