Tenant Administration
This guide covers the current tenant-administration workflows that are available in the Pavri dashboard.
Current readiness
| Area | Status | Notes |
|---|---|---|
| Member list, invite, revoke, and role changes | Live | Admin workflows are available in the dashboard. |
| Tenant settings | Live | The current settings surface is intentionally narrow and admin-only. |
| Role-aware access states | Live | Signed-in users now see explicit denied/read-only states instead of silent redirects. |
| Advanced identity-provider administration | Preview | Some provider/auth configuration remains deployment-specific. |
Roles
Pavri currently exposes three tenant roles in the dashboard:
| Role | What it can do today |
|---|---|
| Admin | Full tenant access, including members, tenant settings, detection configuration, policies, alert rules, protection profiles, discovery/MCP review, API keys, and audit log |
| Security Analyst | Operational and governance access, including policies, alert rules, protection profiles, discovery, MCP review, and reports browse/export |
| Viewer | Read-only access to inventory, sessions, activity, alerts, discovery, MCP, and analytics surfaces |
Inviting users
Only Admins can invite new members.
To invite a member:
- Navigate to Admin → Members.
- Click Invite member.
- Enter the invitee email address.
- Select the role the user should receive on acceptance.
- Send the invitation.
Pending invitations remain visible in the members workflow until they are accepted or revoked.
Changing roles
Admins can change roles from the members workflow.
Common role transitions:
- Viewer → Security Analyst when a stakeholder moves into active triage work
- Security Analyst → Admin when a trusted operator needs tenant-management capabilities
- Security Analyst → Viewer when a user should retain visibility but lose governance/write access
Role changes take effect immediately on the user’s next page load.
Removing users
Admins can revoke a member from the tenant. Removal immediately ends dashboard access while preserving historical audit trails and product records.
Tenant settings
The current admin settings surface is intentionally focused. Use it for:
- tenant metadata and display settings
- current member administration
- current admin-only security and access settings already exposed in the dashboard
Broader billing, quota, and advanced plan management remain outside the tenant dashboard today.
Password recovery and SSO recovery
- SSO / WorkOS deployments: password or recovery flows are owned by your identity provider.
- Local credential deployments: use the Pavri reset/recovery flow if it is enabled in your environment.
If your SSO flow fails at sign-in, Pavri now presents a retry/support state instead of a local credential fallback that cannot succeed.