/settings and is organized into three audience-aligned sections — Account, Workspace, and Platform — each page rendered only when your identity and capabilities reach it. There is no separate “Admin Console” application; administration is a set of pages inside Settings. Ready to dive in? Set up your first integration.
Roles
Aperium recognizes three system roles. They are defined in code and cannot be customized (tenant-custom roles are deferred).
Roles are granted as assignment records, not picked from a single dropdown — a user can hold several grants, each scoped to one tenant or platform-wide. See Access control overview.
The Settings console
Every page is capability-gated, so an administrator only sees the pages their role reaches.1
Account — every signed-in user
Personal preferences: Profile, Agent context, Appearance, Language, and About. These are not administrative.
2
Workspace — tenant administrators
Tenant-wide configuration:
- Members — the users in your tenant, their roles, and account status. See Users.
- Access — a tabbed hub for roles, permission groups, group mappings, preassignments, policy audit, and the tenant catalogs. See Access control overview.
- Guardrails — tenant guardrail policies and templates. Rendered only when you hold the
guardrail.readcapability. - Personalization — workspace-wide rules and glossary that bind every member.
3
Platform — super administrators
Tenants — cross-tenant management and provisioning. The tenant a super admin acts within is chosen here or from the impersonation popover in the app shell.
Guardrails are a preview. Admin-authored guardrail policies can be created and stored, but they do not enforce at runtime yet. Treat them as configuration you are staging, not an active control.
What to set up first
Most administrators bring a tenant online in this order:1
Connect your business systems
Add the integrations Aperium will use. Tenant-wide systems like Salesforce, NetSuite, and Odoo are configured once by an admin. OAuth connectors like Google Workspace, Slack, Atlassian, and Microsoft 365 are linked per user. See Integrations overview.
2
Set up access control
Create permission groups, attach per-server MCP policies, and map your identity-provider groups to Aperium roles. See Access control overview.
3
Preassign access for incoming users
Use Access › Preassignments to prepare a role and group memberships for an email before that person has ever signed in. The preassignment is consumed on their first login. See Preassignments.
Useful admin actions
- Impersonation. Act as a specific non-admin user to reproduce their view. Started from a popover in the app shell or from a member’s detail page; gated by the
impersonation.startcapability. See Impersonation. - Edit integrations. Tenant integration edits open a confirmation dialog that lists how many users are affected; changing the auth method invalidates affected credentials so users re-link.
- Policy audit. The Access › Policy audit tab shows recent MCP permission-group policy changes. See Policy audit.