Skip to main content
Loading...
Platform Admin Agent
Platform Admin Agent
Platform Admin Agent

Platform Admin Agent

AI-powered admin agent for user management, org structure queries, and system administration.

Overview

Platform Admin Agent is a conversational administrator for your tenant. Ask it a question in plain language — "who has admin rights they haven't used since spring", "which invitations never landed", "compare what Sara and Devon can reach", "why is our HRIS integration unhealthy" — and it answers from live data instead of sending you through half a dozen admin screens. It reads your user directory, roles and permissions, departments and locations, enabled apps and their licensing health, integration status, and the platform audit log.

It can also act, once you let it. Write tools are switched OFF by default and turned on per tenant: activate or deactivate an account, change someone's role, resend an invitation, send a password-reset link, or stage records from pasted text for an import you then commit on the import review page. Every one of those asks for confirmation and shows you a preview of the exact change before anything happens, and none of them can touch a super-admin unless you are one yourself. Writes also need Ask AI's Enable Action Execution setting, which is on by default; turn it off and Ask AI runs none of the agent's tools, reads included. Autonomous operations are a separate opt-in. Only while they and write tools are both on do the stale privileged access and failed invitation scans you run from chat queue an approval request for each finding someone could act on, signed off by a human in the Automation Hub queue and never applied silently; with either off, the scans return evidence only.

The agent is admin-only end to end — there is no view of it for anyone else — and every call it makes is recorded, so My Activity and Analytics show you what was asked, what was changed, what was refused by your own settings, and what it cost. Analytics exports every admin's agent activity to CSV when you need the evidence outside the product.

Ask cross-console questions in plain English and act on the answers — user searches, permission audits, system-health checks, and confirmed account changes that land in the admin audit log.

Highlights

Search and inspect user accounts by name, email, role, status, department, or location using natural language queries.
Audit user permissions and review role assignments across the organization with detailed permission breakdowns.
Monitor system health including active user counts, enabled apps, and department and location statistics.
Perform write operations such as activating or deactivating users, changing roles, resending invitations, sending password-reset links, and staging records from pasted text for import, with confirmation safeguards.
Scan for stale invitations and privileged accounts needing access review with automated remediation bundles.
Audit organization data quality, compare user access, and detect app licensing or integration health issues.
Query the audit log by user, action type, or date range to investigate recent administrative changes.

Capabilities

Conversational Admin
  • Natural-language queries against live org data
  • Multi-turn context within a session
  • Admin-only access enforcement (rejects non-admins)
  • Redirects how-to questions to the Help Agent
  • Per-business enable/disable toggle
User & Account Management
  • Search users by name, email, role, status, department, or location
  • View full user profile (role, department, last login, manager)
  • List all pending invitations
  • Activate or deactivate a user account (with confirmation)
  • Change user role: member, manager, admin, or super admin (with confirmation; only a super admin can grant admin or super admin)
  • Resend an invitation email to an existing user (with confirmation)
  • Send a password-reset link to a user (with confirmation)
  • Stage records from pasted text for import (with confirmation; committed on the import review page)
  • Modify super admin accounts via the agent Super admins only
Org Structure & Roles
  • List all departments with active user counts
  • List all locations with active user counts
  • Role summary (how many users per role)
  • List all admin and super admin accounts
  • Audit missing department, manager, job title, and location data
  • Aggregate stats: active, inactive, recent signups
Permissions & Audit
  • Check permissions for any user by ID or email
  • Compare roles and effective permissions for two users
  • Search audit log by user, action, or date range
  • All account changes are logged to the audit trail
  • Export the agent's activity analytics to CSV
Security & Remediation
  • Scan for stale invitations (configurable age threshold)
  • Scan for privileged accounts with no recent login
  • Remediation bundle with evidence and recommended actions
  • Execute remediation actions from bundle in-agent
  • List enabled marketplace apps for the business
App & System Visibility
  • System overview: active users, total users, enabled apps
  • List enabled marketplace apps with activation dates
  • Detect app licensing and agent-configuration drift
  • Inspect integration health and sync freshness without credentials
  • Check agent harness health: tool coverage and contract integrity
Limits & Specs
  • Max users returned per search: 50 (default 20)
  • Max audit log entries per query: 100 (default 25)
  • Stale invite threshold (configurable): 7 days
  • Stale admin threshold (configurable): 90 days
  • Supported roles for role-change tool: member, manager, admin, super admin (only a super admin can grant admin or super admin)
  • Pricing: License required (included in Platform Enterprise; other tiers by licence grant from your account team)

Use cases

User account investigation
An admin asks "Show me details for jane@company.com" and receives the user's role, department, last sign-in date, manager, and invitation status in a single response.
Privileged access review
An admin asks the agent to scan for stale admin accounts and receives a prioritized list of administrators who have not signed in for over 90 days with recommended actions.
Failed invitation cleanup
An admin requests a scan of failed invitations and the agent surfaces users who were invited more than 7 days ago but never accepted, with options to resend or deactivate.
Department headcount check
An admin asks "How many active users are in Engineering?" and receives a breakdown of user counts by department with role distribution.
Bulk role audit
An admin asks "List all admin users" and receives a table of admin and super admin accounts with their last sign-in dates to verify that privileged access is appropriate.
Configuration health review
An admin asks for app and integration health and receives tenant-scoped licensing, configuration, health-check, and sync-freshness findings without exposing credentials.

FAQ

Only users with admin or super admin roles can interact with the agent. Non-admin users receive an access denied response. Super admin accounts can only be managed by other super admins.

The agent can activate or deactivate user accounts, change user roles (member, manager, admin, or super admin; only a super admin can grant admin or super admin), resend invitations to existing users, send password-reset links, and stage records from pasted text for an import you then commit on the import review page. All write operations require confirmation, and account changes are logged to the audit trail. They stay off until an admin turns on Allow write tools in the agent's Settings, and they also need Enable Action Execution in Ask AI settings, which is on by default.

The agent can build remediation bundles for failed invitations and privileged access reviews. Each bundle includes evidence (e.g., days since last sign-in), a risk assessment, and recommended next actions that can be executed through the agent. With autonomous operations running and write tools on in the agent's Settings, and Enable Action Execution on in Ask AI settings, each finding someone could act on is also queued for approval.

Yes. Every query the agent executes is strictly scoped to the current business. The agent never exposes data from other businesses and never reveals sensitive information like passwords, tokens, or API keys.

Yes. Each account change the agent makes runs through the same admin action as the equivalent click in the admin console, so it is recorded in the admin audit log under the admin who confirmed it, with the action, the target user and the submitted parameters, and marked as performed through the Platform Admin Agent with the tool and the agent run it came from. The agent's own tool calls, reads included, are listed in My Activity and can be exported from Analytics as a CSV.