Skip to content

Platform staff (TenancyEngine)

Manage TenancyEngine operator accounts — people who run the control plane, not tenant end-users or vendor organization members.

Console: TenancyEngine console → Users (/users)

Requires Users read to view; write permissions to create, assign roles, or delete.

Platform roles

RoleTypical use
platform_adminFull platform operations — apps, orgs, audit, settings
platform_impersonatorSupport access to vendor consoles (audited)
app_impersonatorSign in as a tenant user within a registered application
vendor_builderBuild and configure applications without full admin
organization_adminScoped to a vendor org (usually provisioned via org invite, not this page)

Assign roles per user with Add role / Remove on each row. Users can hold multiple roles.

Create a user

  1. Click Add user.
  2. Set email, password (12+ characters per identity policy), and optional display name.
  3. Select initial roles — default is platform_admin for break-glass operators.
  4. Save; the user can sign in at the console login page.

Delete a user

Deletion requires typing the user's email to confirm. Prefer removing roles over deletion when temporarily revoking access.

TenancyEngine platform documentation