Enterprise
Enterprise Admin Center
Operate people, policy, identity, billing, integrations, and compliance inside the customer workspace
The Enterprise Admin Center lives inside the organisation workspace. It is for customer administrators; 8rney's internal staff console remains separate.
Administration sections#
| Section | Controls |
|---|---|
| Overview | Adoption, workload, risk, spend, storage, AI usage, seats, and workspace health |
| People | Employees, reporting lines, groups, guests, invitations, access reviews, directory sync, and session revocation |
| Roles & access | Custom roles, permission templates, delegated administrators, matter grants, ethical walls, and temporary access |
| Identity | Enterprise sign-in, directory provisioning, verified domains, MFA, passwords, devices, sessions, and IP restrictions |
| Data governance | Retention, deletion, legal holds, exports, residency, DLP, classification, redaction, watermarking, and downloads |
| AI governance | Approved models, source restrictions, prompt retention, human-review rules, quotas, and cost ceilings |
| Billing | Plans, seats, entitlements, invoices, usage, cost centres, and budget alerts |
| Workflows | Organisation templates, custom fields, automations, deadline rules, and approval policies |
| Integrations | Productivity, document management, collaboration, e-signature, finance, and calendar systems |
| Developer platform | Service accounts, API keys, webhooks, delivery logs, and API documentation |
| Compliance | Audit search, exports, security events, support access, subprocessors, and policy evidence |
Delegated administration#
An administrator sees Manage only when at least one section is permitted. Every administration mutation passes through workspace authorisation, is constrained to the active tenant, and creates an audit event. Delegated roles can therefore manage a narrow domain without gaining unrelated legal access.
People beyond employees#
Guests and service accounts do not receive general workspace scope. They require explicit resource or matter grants. Temporary support access is time-bound, purpose-limited, visible to the customer, and auditable.
Begin with the smallest practical role set. Add custom roles only when a durable responsibility cannot be represented by the built-in templates.
On this page