Platform
Administration overview
Admin Center for users, teams, roles, security, and integrations.
Overview
The Admin Center centralizes organization administration within the Zof Console. Administrators manage the directory, configure identity and access controls, provision developer credentials, export audit evidence, and tune platform behavior affecting all reliability workflows.
Admin Center areas map to enterprise operational functions: Directory for people and teams, Identity & access for authentication policy, Developer for API keys and webhooks, Audit & data for evidence retention, and Platform config for Studio and Console customization.
Effective administration balances enablement, giving teams the access they need, with governance constraints required in regulated industries and large multi-team organizations.
Who should read this
- Organization administrators, IT identity teams, and platform engineers responsible for tenant configuration.
Prerequisites
- Organization administrator role in the Zof Console
- Documented RACI for admin operations across IT, security, and engineering leadership
When to use this workflow
- Onboarding new team members to Zof terminology and workflows
- Authoring internal runbooks aligned with Console labels
- Designing CI/CD or webhook integrations against documented behavior
Step-by-step procedure
Navigate Admin Center sections
Open Platform → Admin Center from the Zof Console left navigation.
Review Directory, Identity & access, Developer, Audit & data, and Platform config groupings.
Note which settings are tenant-wide versus delegable to team administrators.
Audit current configuration baseline
Export or document existing role assignments, team structure, and integration connections.
Identify default settings that differ from your corporate policy requirements.
Create a remediation backlog for misaligned identity, retention, or permission configurations.
Align directory with organizational structure
Mirror engineering team boundaries in Console teams for ownership clarity.
Assign users to teams upon onboarding and remove promptly upon departure.
Link team ownership to applications and projects for operational accountability.
Harden identity and developer surfaces
Enforce SSO and MFA according to corporate standards in Identity & access.
Inventory API keys and webhooks in Developer, revoke unused or orphaned credentials.
Apply naming conventions for keys indicating environment, owner, and purpose.
Configure audit and retention
Review Audit & data settings for log retention aligned with compliance obligations.
Define who may export audit evidence and on what schedule.
Validate export formats meet downstream SIEM or archive system requirements.
Establish ongoing admin operations
Schedule quarterly access reviews with team leads validating role assignments.
Document escalation paths for admin emergencies, lockouts, integration failures, credential compromise.
Include Admin Center changes in your organization change management tooling.
Key concepts
- Organization scope
- All Zof Console and API operations are isolated to your authenticated tenant.
- Governed execution
- Agent output and remediation follow policy packs with human approval when configured.
Best practices
- Maintain at least two organization administrators to avoid single-point lockout.
- Never share organization administrator credentials, use named accounts with MFA.
- Log internal admin runbook changes alongside Console configuration changes.
- Pilot identity policy changes with a small team before tenant-wide enforcement.
- Review Developer surface quarterly as engineering teams spin up and retire automations.
Common issues
- Administrators locked out after SSO misconfiguration
- Maintain break-glass local admin accounts or documented recovery procedures with your account team before changing identity settings.
- Team structure drift from real org chart
- Schedule periodic reconciliation between HR org changes and Console team membership.
- Platform config changes confuse end users
- Communicate Console customization changes in advance with screenshots or brief enablement sessions.
Was this page helpful?