Tenant admins
You own a tenant: getting it set up, keeping the right people in with the right roles, configuring org identity and security, and unblocking users. This section is your manual. Day-to-day session how-to lives under Tenant users; agent configuration and the core registries (MCP, plugins, skills, tools, models) live under Agent Ops, not Settings. Platform internals live under Platform ops.
Guides
Section titled “Guides”Day-0: new tenant setup: invite, hostname, onboarding, first governed session. The one page every admin reads first.
Roles and membership: who can do what (admin, operator, member) and how to grant it.
Settings: Org: organization identity, domain, and branding. What is required, what is cosmetic, what lands in audit.
Settings: People: inviting members, handling pending invites, offboarding.
Settings: Security: sign-in, session hygiene, least privilege, and what to watch.
My tenants model: one identity, many tenants, and why the hostname always wins.
Switching tenants: moving between tenants with the hostname check before consequential actions.
Troubleshooting: admin-side fixes for invites, onboarding stalls, missing environments, and connector requests.
Admin rhythm
Section titled “Admin rhythm”Do Day-0 once: tenant live, org name set, first session recorded. Then keep this loop: people and roles (invite the team with least privilege), org and security (identity right, sign-in healthy), recurring work (membership reviews, environment and connector requests to the PRESHai team, naming discipline per the naming guide).


