Platform administration
Create and manage tenants, their services and members, and the platform-wide accounts, email, security, identity providers, storage, subscriptions, licence and Robot releases.
Platform administration covers the whole Orchestrator installation rather than one tenant. Only platform administrators see it. The first platform administrator is the bootstrap administrator created when the Orchestrator first starts (see Install on-premises). Open Platform administration# Select the app launcher (grid icon, top left) ▸ Admin, or go to /admin on your Orchestrator address. The home page lists the Tenants on the left (with search and Create tenant) and cards for the platform-wide settings: Card What you do there Accounts Invite platform users, make users administrators, resend or revoke invitations. Email settings Configure SMTP and send a test email. Security Password policy, sign-in lockout and session lifetime. Identity providers Single sign-on with Microsoft Entra ID, another OpenID Connect provider or SAML 2.0. See Users and roles. Storage Where packages and files are kept: local folder, S3-compatible or Azure Blob. Test the connection or change its credentials. Subscription Assign and renew tenant plans. Licence The signed licence file of this installation. See Licensing. Robot releases Upload signed Robot installers that tenants roll out under Robot updates. Create a tenant# Open Platform administration. Next to Tenants, select Create tenant (+). Enter the Tenant name. Choose the Environment type: Production, Staging or Development. Select Create tenant. Then set the tenant up: Select the tenant in the Tenants list. Open Manage access and add the tenant's first administrator (an existing account), or invite them from Accounts. Open Services and check what is enabled. Home and Orchestrator are always on. Sign in to the tenant as its administrator, create the first workspace and add a machine. See Workspaces and tenants. Manage a tenant# Select the tenant in the Tenants list to open its cards: Manage access: add or remove users of this tenant. Services: Enable service or Disable service, and Show in launcher or Hide from launcher, for each product the tenant is entitled to. Leave services off that your organization has not adopted. Tenant settings: change the Tenant name, Environment type and the Job execution timeout (seconds) used by processes without their own limit, enable or disable the tenant, or, under Danger zone, Delete tenant. The tenant's own settings (feeds, Robots, retention, alerts and more) are changed inside the tenant. See Tenant settings. Next steps# Settings reference Users and roles Install on-premises
Open Platform administration
Create a tenant
Manage a tenant
Next steps