Skip to content

Superuser

Open in product: preshos.com/agent-ops/superuser

Platform-admin-only. Superuser is the elevated mode for platform operations work: diagnosis and recovery that needs broader reach than a standard run. It is entitled to org 1 with the platform ops role — not to tenant members, and not inside normal Agent Ops sessions, where it does not bypass approvals or policy.

Availability is entitlement-gated to org 1 with the platform ops role. If superuser controls are not visible, the identity does not hold that entitlement — there is no tenant-side switch to request. Inside normal Agent Ops sessions, superuser does not apply: approvals, environment policy, and the recorded outcome hold exactly as elsewhere. Tenant admins manage tenant-side elevated access through RBAC in Agent Ops.

Superuser mode in session: elevated scope indicator with approval and audit record
  • Elevated reach still runs inside the sandbox under an environment policy. Superuser widens the lane; it does not leave the road.
  • The transcript and outcome record apply in full. Broader actions produce broader audit lines, not quieter ones.
  • Approval gates still fire on irreversible, customer-visible, or cross-system steps — and normal Agent Ops sessions never inherit superuser reach. Elevation earns scrutiny, not exemption.
  • One bounded goal per session still holds. Superuser on a sprawling goal is how incidents get written up.
  • Platform diagnosis the standard run cannot reach: inspection across systems the normal scope excludes.
  • Platform recovery work where the fix outranks the pause: still recorded, still reviewable, still owned by a named identity.
  • Never as a shortcut around missing configuration. If tenant sessions routinely need reach they do not have, the environments or agents are misconfigured — fix those instead.