Platform admin
ADMIN — full control of the platform: people, providers, models, governance and security. You can act in any organization or team.
Where you work: Everything, including the full Administration group (Approvals, Spend Governance, Teams, Users, Organizations, Access & Tiers and Audit). Search (Ctrl+K) also jumps to Control Center and Platform recommendations.
1. Manage people
Users: invite users, set platform roles (ADMIN, ADMIN_VIEWER, USER, USER_VIEWER) and suspend accounts. Create organizations and assign org admins under Organizations so day-to-day approvals happen close to the teams.
2. Configure providers and models
Models: add provider credentials (AES-256-GCM encrypted, or akv: Azure Key Vault references), create model deployments with weights, pricing and fallback chains. Group deployments into access groups and define budget tiers under Access & Tiers.
3. Govern spend
Set budgets at any supported scope, grant temporary budget increases, and configure thresholds on Budgets. Create managed cost centers, assign them to organizations, teams, applications, or users, and use FinOps Analytics and Chargeback for finance attribution. Cost centers are not tags: use Tags for request labels and Customers for end-user attribution and per-customer limits.
Platform admins also operate FinOps attribution, cost events, agent costs, chargeback periods, spend-governance policies, and optimization review.
4. Audit and logs
Audit records every portal mutation with actor and before/after. Request Logs is platform-wide for you; payload capture is opt-in under Settings → Control Center → Security.
5. Security operations
Settings → Control Center → Security holds the master-key rotation runbook. Blocking a user, key, application or customer takes effect on the gateway immediately.
Good to know
Grant ADMIN sparingly — ADMIN_VIEWER covers oversight without write access.