Administrators
Manage the administrators who have access to your Containment.AI dashboard, control their permissions, and invite new team members.
Accessing Administrators
- Go to Settings
- Click the Administrators tab
- View and manage administrators and their permissions
Admin List
The admin list shows:
| Column | Description |
|---|---|
| Administrator | Admin's display name |
| Work email address | |
| Role | Assigned roles/permissions |
| Status | Invitation and account status |
| Joined | When the admin joined |
| Actions | Open the detail drawer |
Inviting Admins
Send Invitation
- Click Invite Admin
- Enter the email address
- Select the role or granular permissions
- Send the invitation
Invitation Status
| Status | Description |
|---|---|
| Pending | Invitation sent, awaiting action |
| Accepted | Admin completed setup |
| Expired | No action after 7 days (default) |
Roles and Permissions
Access is permission-based. An administrator holds either a high-level role or a set of granular permissions.
High-Level Roles
| Role | Capabilities |
|---|---|
| Organization owner | Full access |
| Administrator | Full administrative access |
Selecting a high-level role replaces any granular permissions.
Granular Permissions
Instead of a high-level role, an admin can hold one or more granular permissions:
| Permission | Grants |
|---|---|
| Billing manager | View and manage billing |
| Policy administrator | Create, edit, and manage policies |
| Policy viewer | View policies (read-only) |
| Alert administrator | Manage and resolve alerts |
| Alert viewer | View alerts (read-only) |
| Audit viewer | View audit logs and activity |
| Integration manager | Manage integration configuration |
Team-scoped variants (team administrator, team policy administrator, team alert viewer) exist for organizations using teams.
Custom role creation (defining your own named roles) is a roadmap capability and is not in the product today. Use the granular permissions above to compose least-privilege access.
Managing Admins
Edit Roles
- Click an admin's row to open their detail drawer
- Add or remove roles and granular permissions
- Click Save changes
Notes:
- You cannot modify your own roles
- Only admins with permission management rights can edit roles
View an Admin's Activity
From the detail drawer, click View activity to open the Activity page filtered to that administrator's actions.
Admin Activity
View admin actions:
- Go to Activity
- Filter by actor
- Review configuration changes, alert management, and user actions
Security
Multi-Factor Authentication
MFA enforcement is designed to arrive with enterprise SSO (enforced through your identity provider). SSO is a roadmap capability delivered per engagement — see SSO.
Troubleshooting
Admin Can't Sign In
- Check the admin's status in the list
- Verify the email address
- Try a password reset
Wrong Permissions
- Open the admin's detail drawer
- Review assigned roles and granular permissions
- Contact an organization owner or administrator if changes are needed
Invitation Not Received
- Check the spam folder
- Verify the email address
- Send a new invitation
Best Practices
Least Privilege
- Assign minimal necessary permissions
- Prefer viewer-level permissions when appropriate
- Review permissions regularly
Access Reviews
- Audit the admin list quarterly
- Remove access that is no longer needed
- Verify role appropriateness
Related Topics
- Audit Logs - Track admin actions
- SSO - Enterprise authentication
- Account Settings - Your user account