Loading...
Help Center / Apps & Extensions / Platform Admin Agent FAQ

Platform Admin Agent FAQ

Platform Admin Agent FAQ

Answers to common setup and operating questions about the Platform Admin Agent.
For what the agent is and how to set it up from scratch, see the
Platform Admin Agent Overview.


Setup

What do I need to set up before the agent works?

Three things must be in place. First, a Platform Admin Agent licence must be granted to your organisation — without it you cannot enable the app. Second, the app must be enabled in Admin → All Apps. Third, the Enable Platform Admin Agent toggle must be on in the app’s Settings page. All three default to off, so a new licence does nothing until an admin deliberately turns it on.

Who can use the Platform Admin Agent?

Only users with an Admin or Super Admin role in your organisation. The agent is hidden from the sidebar and Apps grid for everyone else, and any non-admin who reaches it through a direct link is redirected to the dashboard. Inside Ask AI, the Platform Admin Agent mention does not appear in the autocomplete for non-admins.

What are write tools and should I turn them on?

Write tools let the agent activate or deactivate users, change roles, send invitations, and trigger password resets. They are off by default — enabling the agent gives it read-only access to your user directory, org structure, audit log, and system health. Turn them on only when you want conversational admin actions. Every write shows a diff preview and requires confirmation before anything changes.


Permissions and access

Can the agent modify Super Admin accounts?

No. Only a Super Admin can deactivate, change the role of, send an invitation to, or trigger a password reset for another Super Admin. If an Admin asks the agent to do any of those things to a Super Admin account, the agent refuses and tells you to ask a Super Admin. The controller behind the action enforces the same restriction, so this cannot be bypassed.

Can I change my own role or deactivate my own account through the agent?

No. The agent refuses both operations and explains why. Changing your own role could lock you out of administration, and deactivating your own account would end your session with no way to reverse it.

Why does the agent refuse to demote or deactivate someone even though I’m a Super Admin?

The agent prevents any change that would leave your organisation with no active Super Admin, or with no active administrator at all. If the person you are trying to demote or deactivate is the last one holding that role, promote another user first, then retry.


Day-to-day

What write operations does the agent support?

Four, and each requires confirmation before it executes:

  1. Activate or deactivate a user account.
  2. Change a user’s role to Member, Manager, or Admin. Only Super Admins can promote someone to Admin.
  3. Send or resend an invitation email.
  4. Trigger a password reset — the user receives a self-serve reset link by email.

You can identify the target user by name, email, or user ID. The agent resolves the match and shows exactly what will change before you approve.

How do remediation scans work?

The agent can scan for two kinds of risk: stale invitations (users invited more than 7 days ago who never accepted) and stale privileged accounts (admins who have not signed in for more than 90 days). Both thresholds are configurable per scan. Each scan returns a list of findings with evidence and recommended next actions. If autonomous operations are enabled for your organisation, each finding also queues a pending-approval action and notifies admins. With autonomous operations off, you get the same findings as evidence only — nothing is queued and no notifications are sent.

What are autonomous operations?

Autonomous operations let the agent act on a schedule without a conversation — for example, running a nightly privileged-access scan and alerting admins when a threshold is breached. The feature has its own toggle in Settings (Allow autonomous remediation actions, off by default) and a separate pause/unpause control on the Autonomous Operations page. Pausing stops scheduled actions immediately; unpausing resumes them. Autonomous actions that need approval wait in the queue until an admin approves or rejects them.

What happens when I ask the agent a how-to question?

The agent works with live data only. If you ask how to use a feature or where to find a setting, it tells you to ask the Platform Help assistant instead. It does not answer documentation questions.


When something looks wrong

“The agent says write tools are disabled — how do I turn them on?”

Go to the Platform Admin Agent app → Settings and check the Enable write tools toggle. It is off by default. Only users with an Admin or Super Admin role can change this setting. Once enabled, every write still requires per-action confirmation.

“I get ‘access denied’ when I try to use the admin agent”

Your current role does not have access. The Platform Admin Agent is restricted to Admin and Super Admin roles. Ask an existing admin to check your role under Admin → Users. If your role shows Member or Manager, the admin must promote you before you can use the agent.

“The agent says it can’t find a user I know exists”

The agent searches within your organisation only. If the user belongs to a different organisation (business), they will not appear. Also check that you are using the correct email address — the agent matches on email case-insensitively, but a typo will return no results.


Licensing and limits

Does the Platform Admin Agent require a licence?

Yes. The app requires a licence before it can be enabled. It is available on any platform tier — you do not need to be on a specific tier. Contact your account team to add a licence.

What are the search and query limits?

What Default Maximum
Users per search 20 50
Audit log entries per query 25 100
Admin users listed 20 50
Pending invitations listed 20 50
Remediation bundle findings 20 50

What are the default thresholds for remediation scans?

The stale-invitation scan surfaces invitations older than 7 days by default. The privileged-access scan flags admins who have not signed in for 90 days. Both thresholds can be overridden per scan by asking the agent to use a different number of days.


More help