Skip to main content

Admin and viewer

SPOT SaaS uses tenant roles. The role defines which actions appear in the interface and which changes each user can save.

Tenant admin

Use Tenant console to configure the tenant:

  • Connectors and Add agent guide.
  • SAP connections assigned to connectors.
  • Users & roles.
  • SAML.
  • Thresholds.
  • AI providers.
  • Audit.
Tenant console Connectors with admin role
Tenant console open on Connectors with admin role.

Viewer

The viewer role is used for operational consultation. Review Landing, Operations, and diagnostic views without preparing configuration changes.

SaaS view with viewer role
SaaS view with viewer role for validating read-only experience.

Platform admin

Platform manages tenants without assuming their users' identity. When creating a tenant, provide the initial email and role and SPOT sends an invitation; Platform does not set a password. In tenant details, Platform can change membership status/roles and approve or revoke the verified domain as a SAML identity authority.

Approve the authority only after confirming that the domain belongs to the tenant and the IdP is ready. Approval makes that tenant the identity home for the domain. Revocation invalidates the related SAML access, so treat it as a deliberate security action.

Quick permission check

  1. Sign in with an admin user and open Tenant console.
  2. Review that tenant configuration tabs are visible.
  3. Sign in with a viewer user.
  4. Check visible actions before sharing read-only access.