Loading...
Help Center / Apps & Extensions / Platform Admin Agent FAQ

Platform Admin Agent FAQ

Platform Admin Agent FAQ

Answers to common setup and operating questions about the Platform Admin Agent.
For what the agent is and how to set it up from scratch, see the
Platform Admin Agent Overview.


Setup

What do I need to set up before the agent works?

Four things must be in place. First, a Platform Admin Agent licence must be granted to your organisation — without it you cannot enable the app. Second, the app must be enabled in Admin → All Apps. Third, the Enable Platform Admin Agent toggle must be on in the app’s Settings page. Fourth, Enable Action Execution must be on in Apps → Ask AI → Settings: with it off, Ask AI answers without running any of the agent’s tools, so it can neither look anything up nor make changes. The licence and the app are off until someone grants and enables them, so a new licence does nothing until an admin deliberately turns the app on. The Enable Platform Admin Agent toggle defaults to on once the app is enabled, and Enable Action Execution is on unless someone has turned it off.

Who can use the Platform Admin Agent?

Only users with an Admin or Super Admin role in your organisation. The agent is hidden from the sidebar and Apps grid for everyone else, and any non-admin who reaches it through a direct link is redirected to the dashboard. Inside Ask AI, the Platform Admin Agent mention does not appear in the autocomplete for non-admins.

What are write tools and should I turn them on?

Write tools let the agent activate or deactivate users, change roles, resend invitations, send password-reset links, and stage records from pasted text for import. They are off by default — enabling the agent gives it read access to your user directory, org structure, audit log, and system health, plus the remediation scans described below. Turn them on only when you want conversational admin actions. They also need Enable Action Execution, which is on by default in Ask AI settings. Every write shows a diff preview and requires confirmation before anything changes.


Permissions and access

Can the agent modify Super Admin accounts?

No. Only a Super Admin can deactivate, change the role of, send an invitation to, or trigger a password reset for another Super Admin. If an Admin asks the agent to do any of those things to a Super Admin account, the agent refuses and tells you to ask a Super Admin. The controller behind the action enforces the same restriction, so this cannot be bypassed.

Can I change my own role or deactivate my own account through the agent?

No. The agent refuses both operations and explains why. Changing your own role could lock you out of administration, and deactivating your own account would end your session with no way to reverse it.

Why does the agent refuse to demote or deactivate someone even though I’m a Super Admin?

The agent prevents any change that would leave your organisation with no active Super Admin, or with no active administrator at all. If the person you are trying to demote or deactivate is the last one holding that role, promote another user first, then retry.


Day-to-day

What write operations does the agent support?

Five, and each requires confirmation before it executes:

  1. Activate or deactivate a user account.
  2. Change a user’s role to Member, Manager, or Admin. Only Super Admins can promote someone to Admin.
  3. Resend an invitation email to an existing user who has not yet signed in to this business. Someone who has never signed in gets a temporary password; someone who has signed in before gets just their sign-in link, and their password is unchanged. Refused while Welcome Emails are turned off.
  4. Trigger a password reset — the user receives a self-serve reset link by email. Refused while Password Reset Emails are turned off, and a reset link they already have keeps working. Both switches are in Admin → General Settings → Notifications (System & Broadcasts).
  5. Stage an import — records from text you paste are staged for a Smart Import target; nothing is written until you commit the import on its review page.

For the four account changes, identify the target user by email or user ID. The agent shows exactly what will change before you approve.

How do remediation scans work?

The agent can scan for two kinds of risk: stale invitations (users invited more than 7 days ago who never accepted) and stale privileged accounts (admins who have not signed in for more than 90 days). Both thresholds are configurable per scan. Each scan returns a list of findings with evidence and recommended next actions. If autonomous operations and write tools are both on for your organisation, and Enable Action Execution is on in Ask AI settings, each finding that someone could act on also queues a pending-approval action and notifies the admins who could approve it. With autonomous operations or write tools off, you get the same findings as evidence only — nothing is queued and no notifications are sent. With Enable Action Execution off, the scans do not run at all.

Who is asked to approve a remediation finding?

Only people who could make the recommended change themselves. Approving a finding runs its change as the person who approved it, so a finding about a Super Admin account goes to Super Admins only, and other findings go to every active Admin and Super Admin. The person a finding is about can never approve or reject it, and neither can a service account. Who may decide is worked out from each account’s current role, so a finding about someone who has become a Super Admin since the scan ran is a Super Admin’s decision. The same rule applies wherever the decision is made — AI Operations, the daily approvals email, and AI Home — so you will not see an Approve button for a change you are not allowed to make; you see the reason instead.

When approving could not make the change right now — the agent or its write tools are turned off, Enable Action Execution is off in Ask AI settings, or the account is no longer part of your organisation — the people who may decide the finding can still reject it to close it. AI Operations and AI Home show the reason in place of Approve, and the daily approvals email lists the finding as Reject only, with a link that opens the Reject form.

A finding is returned for manual review instead of being queued when there is no recommended step to run (an active Super Admin who has not signed in recently is always a manual review), when nobody could run the step (for example, resending an invitation to someone with no email address), or when no one other than the person under review is allowed to approve it. The agent tells you which.

What are autonomous operations?

Autonomous operations let automation playbooks use the agent’s unattended tools without a conversation — sentinel metric alerts, webhooks, email, tasks, notifications, and AI analysis; all but AI analysis also need Enable Action Execution on in Ask AI settings. The remediation scans are not among them: you run those from Ask AI, and with autonomous operations and write tools both on they also queue the findings someone could act on for approval. The feature has its own toggle in Settings (Allow autonomous operations, off by default) and a separate pause/unpause control on the Autonomous Operations page. Pausing stops autonomous actions immediately; unpausing resumes them. Autonomous actions that need approval wait in the queue until an admin approves or rejects them.

What happens when I ask the agent a how-to question?

The agent works with live data only. If you ask how to use a feature or where to find a setting, it tells you to ask the Platform Help assistant instead. It does not answer documentation questions.


When something looks wrong

“The agent says write tools are disabled — how do I turn them on?”

Go to the Platform Admin Agent app → Settings and check the Allow write tools toggle. It is off by default. Only users with an Admin or Super Admin role can change this setting. Once enabled, every write still requires per-action confirmation. If the agent instead says action execution is turned off or disabled, or answers without looking anything up, turn on Enable Action Execution in Apps → Ask AI → Settings.

“I get ‘access denied’ when I try to use the admin agent”

Your current role does not have access. The Platform Admin Agent is restricted to Admin and Super Admin roles. Ask an existing admin to check your role under Admin → Users. If your role shows Member or Manager, the admin must promote you before you can use the agent.

“The agent says it can’t find a user I know exists”

The agent searches within your organisation only. If the user belongs to a different organisation (business), they will not appear. Also check that you are using the correct email address — the agent matches on email case-insensitively, but a typo will return no results.


Licensing and limits

Does the Platform Admin Agent require a licence?

Yes. The app requires a licence before it can be enabled. It is included in the Platform Enterprise package. On other tiers it is available only through a licence grant from your account team — it is not sold as a separate line item.

What are the search and query limits?

What Default Maximum
Users per search 20 50
Audit log entries per query 25 100
Admin users listed 20 50
Pending invitations listed 20 50
Remediation bundle findings 20 50

What are the default thresholds for remediation scans?

The stale-invitation scan surfaces invitations older than 7 days by default. The privileged-access scan flags admins who have not signed in for 90 days. Both thresholds can be overridden per scan by asking the agent to use a different number of days.


More help