Skip to main content

Tenant admin guide

Tenant admin manages a client group. This role can configure companies, product access, user assignments, approval policies, and shared reference data for the tenant group, but it should not control global platform settings.

Responsibilities

AreaWhat tenant admin controls
Tenant groupName, product subscriptions, companies, and group-level settings.
CompaniesCompany records, document types, product scope, and client profile defaults.
UsersUser assignment, roles, status, invite and reset flows within tenant scope.
Approval governanceThresholds, substitutes, VIP rules, line-level approval availability.
Shared listsDictionaries shared by companies inside the tenant group.
Reports and auditTenant-level process visibility and evidence.

Client hierarchy and governance

Main workflow

  1. Create or select the tenant group.
  2. Add companies and assign product access.
  3. Configure users and roles per company.
  4. Configure approval thresholds and substitutions.
  5. Configure shared lists and field rules.
  6. Review reports and audit trail.

Product-specific behavior

ProductTenant admin focus
Accounting WorkspaceCompany AP setup, accountant/verifier/approver roles, ERP readiness.
Enterprise IDP / OCR OperationsVerifier teams, source routing, quality and SLA visibility.
E-document ArchiveRetention policy ownership, legal hold responsibility, archive user scope.

Screens to use

Client profile fields

Use client profiles to decide company-specific fields, OCR provider, ERP profile, and line-level approval behavior.

Reference data lists

Use Lists to maintain tenant-level dictionaries such as departments, projects, supplier mappings, and currency rates.

Guardrails

  • Tenant admin can manage only the assigned tenant group.
  • It must not see unrelated customer groups.
  • It should not publish global AI provider or model changes.
  • It should not access internal AI Learning unless explicitly granted another role.
  • Its actions must be visible in audit logs.

Demo test path

  1. Enter a product sandbox as an admin-level role.
  2. Open Hierarchy and confirm only the selected product and tenant context is shown.
  3. Change a role assignment or delegation in the sandbox.
  4. Confirm the audit log shows the change with actor, tenant, product, and subject.