
Elementrix administrators have system-wide capabilities to manage users, applications, data products, and platform configuration.
- Create and manage user accounts
- Assign roles and permissions
- Monitor user activity
- Bulk user operations
- Register and manage consuming applications
- Issue and rotate API credentials
- Monitor application usage
- Enforce rate limits and security policies
- View all data products across the organization
- Override permissions for emergency changes
- Bulk operations on products
- Monitor product health and quality
- Platform branding and customization
- Environment setup (staging, production)
- Identity provider integration (AD, SSO)
- License management and monitoring
-
Managing Data Products
- View and edit all products
- Bulk operations
- System health monitoring
-
Managing Applications
- Application registration
- API credential management
- Usage analytics
-
Managing Users
- User directory
- Role assignment
- Onboarding and offboarding
-
Managing Roles
- Role configuration
- Permission matrix
- Custom role creation
-
Branding
- Company logo and colors
- Theme customization
- Email templates
-
Staging Environment
- Environment configuration
- Data anonymization
- Testing setup
-
Active Directory Integration
- LDAP configuration
- Group mapping
- User synchronization
-
SSO Setup
- Keycloak configuration
- Identity providers
- Session management
-
Licensing
- License information
- Usage monitoring
- Compliance reporting
- Grant minimum permissions necessary
- Use custom roles for specific needs
- Regular permission audits
- Rotate API credentials regularly
- Monitor for suspicious activity
- Enable MFA for admin accounts
- Review access logs frequently
- Track system health metrics
- Set up alerts for issues
- Review unused resources
- Plan capacity growth
- Test changes in staging first
- Document configuration changes
- Maintain audit trail
- Communicate changes to users
- Ensure proper anonymization in staging
- Review data access patterns
- Enforce classification policies
- Monitor compliance requirements
ROOT_ADMIN:
- Complete system access
- Cannot be restricted
- Limited to 1 user
SUPER_ADMIN:
- Broad administrative privileges
- Can manage most system aspects
- Cannot modify ROOT_ADMIN
Custom Admin Roles:
- Tailored permissions
- Domain-specific administration
- Delegated responsibilities
- Monitor system health
- Review access requests (if delegated)
- Check for alerts and issues
- Review usage analytics
- Check inactive users/applications
- Verify backup and sync status
- Generate compliance reports
- Review and rotate credentials
- Audit user permissions
- Update documentation
- License usage review
- Capacity planning
- Security audit
- Process improvement review
- Start with Managing Users for user administration
- Configure Branding to customize the platform
- Set up SSO for seamless authentication