Skip to main content
The Admin Console is accessible to users with the Admin persona. It provides controls over the entire workspace, including user management, persona management, connections, and security policies. All changes made in the Admin Console affect the entire workspace.
Only users assigned the Admin persona can access the Admin Console.

User Management

Manage all users in your workspace and control their access. The user management table displays the following columns. Use the + Add User button to invite new users to the workspace. Use the search bar to quickly find users by name or email. User Management table showing users with their groups, roles, status, and last modified dates.

Bulk invite

Admins can now invite multiple users in a single flow instead of one at a time. The Bulk Invite dialog has two steps: Set up the batch and Review and send.

Step 1: Set up the batch

Bulk invite dialog showing role, department, persona, and connector fields, and an email addresses text area.
  1. From the User Management table, click + Add User and choose the bulk invite option.
  2. Select a Role (required).
  3. Optionally fill in:
    • Department — pick an existing one or type a new one.
    • Persona — a starting persona to assign to every invited user.
    • Connector — one or more connectors to recommend to the invited users.
  4. In Email addresses, paste or type the addresses to invite. Separate them with commas, semicolons, spaces, or new lines — you can also paste directly from a spreadsheet.
  5. Click Next: Review.

Step 2: Review and send

The review screen summarizes the role, persona, and connectors selected, and lists the status of each address: If the batch would put the workspace over its plan’s concurrent-user limit, a warning banner explains this is a warning, not a block — accounts are unlimited, and people are only turned away at login if more than the plan’s limit are active at once. Click Invite to send the batch.

Persona assignment

If a persona is attached to the invite, each new user receives their own independent copy of it on first login, including its skills. Editing or deleting the source persona afterward has no effect on copies that have already been distributed.

Admin-initiated password reset

Workspace admins can trigger a password reset directly from a user’s record, without ever generating, seeing, or sending the user’s password.
  1. From the User Management table, open a user’s record to bring up the Edit User dialog.
  2. Under Status, click Reset password.
  3. Confirm in the dialog that appears.
Edit User dialog with a confirmation prompt to send a password reset link to the user's email.
  1. Click Send Reset Link.
The user receives a secure, single-use link, valid for 24 hours, to set their own password. Their current password keeps working until they use the link. No password is ever generated, displayed, or sent by the admin. The existing self-service Forgot password flow remains available to all users at any time, regardless of whether an admin has triggered a reset. Every reset — admin-initiated or self-service — is recorded in the audit log.

Persona Management

Create, edit, and manage workspace personas. The persona management table displays the following columns. Use the + Create New Persona button to add a new persona to the workspace. Each persona defines a distinct role with its own skills, knowledge bases, and data source access. Persona Management table showing personas with descriptions, user counts, status, and last modified dates.

Connection management

Admin-level connection management determines which integrations are visible to users. Only approved connections appear in user Settings > Connections. The header displays the total count of approved connections.

Connection list

The connection list is presented as a table with the following columns. The list is filterable by All, MCP, APIs, and Databases, and includes a search bar for quick lookup.
Approved ON means users can see and connect the integration in their own Settings. Approved OFF hides the integration from all non-admin users.
Action required for existing users: Google Workspace is now a native connector, replacing the previous Google Drive, Gmail, and Google Calendar connectors, which had reliability issues. If you previously connected any of these services, disconnect and reconnect via Google Workspace to migrate and restore full functionality.
Admin connection management table showing all integrations with approved toggles, connection status, category badges, and action buttons.

APIs

Filter by APIs to view all API-based integrations. Each row shows the connection name, category badge, connection status, and an Approved toggle. Use the Connect button to initiate OAuth or API key setup, and Settings to reconfigure existing connections. Admin Connections page filtered by APIs, showing API integrations with status, actions, and approved toggles.

Databases

Filter by Databases to view database providers. Each database connection shows the provider name, category badge, saved connection count, and an Add connection action for configuring additional database instances. Admin Connections page filtered by Databases, showing database providers with saved connection counts and add connection actions.

AI Models

AI Models is currently in Beta.
Choose which AI models people in your workspace can use. Disabled models are hidden from everyone’s model picker and are skipped by Auto routing. Keep at least one model enabled in each category. AI Models page in Admin Console showing Basic and Advanced model categories with quality scores, pricing, and access toggles, and a Bring Your Own Key section below with configuration mode options and provider connections.

Model categories

Models are grouped into two categories, both used by Auto routing. Each model card shows a quality score, price per million tokens, the date it was last rated, who it’s available to, and which role owns the key used for it. Use the toggle on each card to enable or disable a model — disabling it hides the model from everyone’s picker and Auto routing skips it. At least one model must stay enabled in each category. Use Refresh scores to pull the latest quality and pricing ratings for all models.

Manage access

Click Manage access on any model to control exactly who can use it. Manage access modal for a model, showing a role access table with Access and Own Key checkboxes per role, and a user access table below it that overrides role-level access, with an Inherited badge shown on users whose access comes from their role.
  • Role access: Search or filter roles, then check Access to grant a role use of the model, and Own Key to allow that role to use its own connected key for it. A running count (e.g. “25 of 25 selected”) shows how many roles currently have access.
  • User access: Check individual users’ Access and Own Key boxes to override their role-level access. Users are marked Inherited when their access still comes from their role rather than an individual override. Search or filter by user to find someone quickly.
  • Minimum per category: Auto routing only considers models a person may use, so every role and every user must keep at least one enabled model in each category (Basic and Advanced). A change that would leave a role or user with none can’t be saved.
Click Save changes to apply, or Cancel to discard.

Bring Your Own Key (BYOK)

In addition to platform-provided models, connect your own LLM provider credentials — OpenAI, Anthropic, Azure OpenAI, Z.ai, and other OpenAI-compatible endpoints. Once a connection is added and tested, your own models become selectable throughout the platform, in Copilot Chat, Personas, Workflows, and Automations.
  • Encrypted credentials: Credentials are encrypted at rest and are never exposed again after entry.
  • Separate usage tracking: Usage through your own keys doesn’t consume platform credits, and is tracked separately on the Observability page.
  • Your responsibility: You’re responsible for all costs, compliance, and data handling associated with the provider you connect.
Choose a configuration mode to control how your keys are used alongside platform credits.
Keys added here are used by everyone in the workspace. Models running on your own keys don’t use credits, but platform features such as summaries and Auto routing still do. If a key stops working, requests on it fail with an error — they never silently switch to another key.
Connect a provider (OpenAI, Anthropic, Z.ai, and others) using its Connect button; each shows a Not connected / connected status.
Enabling BYOK for a role or user requires explicit confirmation through a popup outlining the financial, privacy, security, and compliance responsibilities that transfer to you once enabled. Read this carefully before confirming.
BYOK access itself is a configurable permission within Roles & Permissions. Users without BYOK permission can’t access the BYOK setup flow or use their own provider credentials, regardless of their model access settings.

Security

Granular access control organized into four tabs: Resources, Policies, Roles, and Groups.

Resources tab

Resources are named groups that represent collections of platform entities. The resources table displays the following columns.

Add resource modal

1

Select entity type

Choose from the available entity types: Dashboard, Knowledge Base, Project, User, Resource, Policy, Role, or Group.
2

Define the resource

Enter a Resource Name and Description.
3

Add conditions (optional)

Build conditional rules using a field dropdown, operator, and value. Combine conditions with AND / OR logic.
Security Resources tab showing named resource groups with entity badges and last modified dates.

Policies tab

Policies define access rules by combining a subject (role), actions (permissions), and a resource. The policies table displays the following columns. Use the + Add Policy button to create a new access rule. Security Policies tab showing policy list with role assignments and last modified dates.

Roles tab

Roles are named permission levels that control what users can do within the workspace. The roles table displays the following columns. Use the + Add Role button to create a new role. Use the Filters button to narrow down the list. Security Roles tab showing default roles with user pills, policy counts, and group counts.

Groups tab

Groups are named collections of users for bulk role assignment. The groups table displays the following columns. Use the + Add Group button to create a new group. Use the Filters button to narrow down the list. Security Groups tab showing group list with user pills, roles, and last modified dates.

Roles and Access (Beta)

Role-based access control — define what each group of users can see and do.

Role list

  1. From the Admin Console, open Roles & Access.
The table lists every role in the tenant, with Description, Pending Invites, Total Users, Created by, and actions to edit or manage each role. Roles and Access table listing each role with description, pending invites, total users, and creator. Two system roles ship by default and can’t be edited or removed:
  • System Admin Role — full access.
  • User — read-only access to everyday content surfaces.

Creating a custom role

  1. Click + New Role.
  2. Optionally, under Base this role on, choose an existing role to copy its permissions as a starting point — otherwise start blank.
  3. Enter a Name (required) and an optional Description (up to 200 characters).
  4. Configure the permission grid. Filter by All, Menu, or Settings, or use Select all / Clear all.
Create New Role form showing base-role selection, name, description, and a permission grid with View, Create, Update, Delete, Share, and Converse columns. Most resources (such as Copilot, Personas, Skills, Knowledge Base, Drive, and Automations) use per-action checkboxes: View, Create, Update, Delete, Share, and Converse, where applicable. A few surfaces — Profile & Usage, Business DNA, Licensing, Billing, Observability, Usage & Cost, Audit log, and Platform console — use a simpler on/off toggle instead.
  1. Click Create New Role. At least one permission must be selected.
Any section a user does not have View access to is hidden from their navigation entirely.

Deleting a role

A role can’t be deleted while users are still assigned to it. You’ll be shown how many users are affected and need to reassign them to another role first.
Roles & Access is in beta. Known limitations in this release:
  • Custom roles with admin-level permissions cannot yet access the Admin Console — only the System Admin Role can.
  • View-only permission does not yet prevent a user from creating or editing content in that section.
  • A section can remain visible in navigation even when a user has no View permission on it.

Branding

Customize the identity, colors, typography, and chat experience for your workspace. Branding changes can be applied at the organization level or overridden for an individual project.
Branding changes require the Admin persona, same as the rest of the Admin Console.
Branding page in the Admin Console showing identity, color, typography, Persona AI, and chat background controls alongside a live preview panel. The Editing dropdown at the top of the page selects which scope you’re changing: Organization applies the settings workspace wide, while selecting a specific project overrides the organization default for that project only. Reset discards unsaved changes, and Save changes applies them.

Identity

Colors

Set separate Primary and Accent colors, each with a swatch picker or a direct hex input.

Typography

Choose a font family from the dropdown. A live sample line updates immediately to preview the selected font.

Persona AI

Personalize the AI assistant itself.

Chat background

Replace the plain chat background with a custom image. Upload a PNG or JPEG, wide images (1600x900 or larger) recommended, up to 5 MB. An opacity slider controls how strong the image appears behind chat content, lower opacity keeps text readable over busy images. If no image is uploaded, chat uses the default background.
A Live Preview panel updates in real time as you make changes, so you can see the effect of your workspace name, colors, and welcome message before saving.

Usage and Cost (Beta)

The Usage and Cost section gives workspace admins tenant-level visibility into how the platform is being used and what it’s costing.

Overview dashboard

  1. From the Admin Console, open Usage and Cost.
  2. Use the filter bar to scope the view by user, persona, project, model, or feature.
  3. Select a time window — 7 days, 30 days, 90 days, 1 year, or a custom range.
Usage and Cost dashboard showing credits consumed, active users, sessions, calls, average credits per active user, a usage-over-time chart, and a breakdown panel. The overview shows credits consumed, active users, sessions, calls, and average credits per active user for the selected window, along with the percent change versus the previous period.

Usage over time

A chart tracks credits consumed over time, grouped by model. Toggle between Credits and Cost, and switch between chart and table view.

Breakdown by model, feature, and provider

The breakdown panel switches between Model, Feature, and Provider tabs, showing exactly where credit spend is going, with both the amount and percentage of total for each.

Drill-down views

Below the chart, switch between Users, Projects, and Personas tabs to explore usage in detail. Each table shows:
  • Last-active timestamp
  • An activity heatmap
  • Credit spend
Search within the list, or click View on any row to open a detailed view for that user, project, or persona.
Usage and Cost is in beta.

AI Models

Choose which AI models people in your workspace can use.
  1. From the Admin Console, open AI Models.
  2. Models are grouped into two categories:
    • Basic — used by Auto Routing for greetings and simple questions.
    • Advanced — used by Auto Routing for data, tools, and complex work.
  3. Toggle any model on or off. Models are further labeled by provider (Anthropic, OpenAI, Bedrock, Z.AI, and others).
AI Models page in the Admin Console showing Basic and Advanced model categories, each with provider-labeled models and on/off toggles.
Disabling a model removes it from everyone’s model picker immediately — no action is needed on each user’s end. Keep at least one model enabled in each category.
This release also expands the platform’s model catalogue with support for additional providers, including Z.AI (GLM 4.6 and others, available via Bedrock).
Bring your own key (BYOK) will let you connect your organization’s own model-provider API keys (for example, your own Anthropic or OpenAI account) so your team can use those models through the platform, with usage billed to your own account instead of your platform credits. This is coming soon and is not yet available — the field in AI Models is a placeholder.