Skip to main content
Some administration cannot belong to any one workspace: creating and suspending workspaces, registering a trusted email domain, and deciding who holds platform-operator rights. The Admin Console is where that work happens. This page explains what it covers, how it relates to your workspace’s own settings, and what it records — because for most readers the useful question is not how to use it, but what it can reach.

It is a separate authority

Platform-operator rights are not a workspace role, and no workspace role grants them.
Nothing you can do inside a workspace — not even Owner — grants access to the Admin Console, and holding Admin Console access is not the same as being a member of any workspace. The two authorities are separate on purpose: a workspace administrator governs their own team, and a platform operator governs the platform.

What it covers

What it means for your workspace

Two consequences are worth stating plainly, because they are what a security reviewer will ask about.
  • Workspace-scoped surfaces stay workspace-scoped. Your audit log shows your team’s own actions. Platform-level administration is recorded on the platform side rather than appearing in your log.
  • Operator assistance is tracked, not ambient. When an operator acts inside a workspace to help it, that is a recorded session rather than an untraced login.

Next steps

Accounts & members

What a workspace owner administers themselves.

Audit log

The workspace-scoped record.

Agent isolation & tenancy

The boundary this console sits above.

Roles & permissions

The authority that does live inside a workspace.