Active users with role-based access
Administrative Domains
Each configuration area should have an owner, review cadence, and audit trace.
| Domain | What It Controls | Owner | Review Pattern |
|---|---|---|---|
| Users and roles | Audience visibility, admin rights, service-owner permissions, approver scopes | Platform admin | Monthly access review |
| AI policy and routing | Eligible tiers, blocked actions, approved sources, escalation rules | IT leadership + governance | Quarterly policy review |
| Knowledge governance | Published source sets, owner approval, confidence thresholds, review dates | Knowledge owner | 30-day source review |
| Notifications and escalation | Stakeholder updates, bridge notifications, approver nudges, vendor alerts | Service desk lead | Monthly service test |
| Service ownership | Catalog ownership, dependency accountability, budget and reporting responsibility | IT manager | Quarterly service review |
Settings Panels
Representative controls from the admin experience.
Users And Role Management
Control who can view, approve, configure, and administer across the platform.
Executive, stakeholder, service owner, IT operator, platform admin
Separate admin privilege from daily operator visibility
Quarterly role attestation for managers and admins
AI Policy Controls
Define what the models can access, which tiers are allowed, and what actions are blocked.
Lowest-cost eligible tier for routine demand
Approvals, service-impacting changes, autonomous sends, unsourced policy output
Every governed AI action records source, tier, and operator context
Knowledge Governance
Keep self-service answers tied to approved, current, and owned content.
Policies, FAQs, service definitions, runbook excerpts, approved guidance
Flag stale content before it remains eligible for AI retrieval
Knowledge owner approves publication and retirement
Notifications And Service Ownership
Make accountability and operational communication explicit.
Severity-based notification templates and approval path
Auto-remind owner when response SLA or bridge cadence slips
Each published service has named operational and business ownership
Recent Administrative Change Activity
Settings changes should behave like governed work, not hidden configuration drift.
Raised required confidence threshold for policy-answer routing after stale-source review.
Added named backup owner for Teams workspace services and linked escalation notifications.
Restricted premium AI tier access to approved incident command and leadership scenario paths.
Completed quarterly admin-role attestation and removed two expired platform-admin grants.