Administration
Console guide
Find the tenant-scoped views for access, resources, security, identities, integrations, audit, and settings.
The console is role-aware: it displays only the tenant data and actions returned for the current session.
| View | Use it for |
|---|---|
| Overview | Host, request, credential, and audit-export summary |
| Access | Requests, approvals, policies, and access-review campaigns |
| Resources | Projects, host groups, hosts, enrollment tokens, and SSH policy |
| Credentials | Personal and break-glass credential inventory |
| Security | TOTP, WebAuthn, recovery codes, password, sessions, tokens, and linked OIDC identities |
| Identities | Tenant actors, invitations, SCIM users/groups, role mappings, and emergency disable |
| Integrations | OIDC providers, SCIM connector rotation, and signed SIEM webhooks |
| Audit | Hash-chained events, immutable export status, downloads, and dead letters |
| Settings | Current tenant and account context |
Search and filtering
The top-level filter applies to the active view. Directory objects use server-backed pagination; large inventories are not loaded into the browser all at once.
Reauthentication
If an action reports that recent MFA is required, sign in again and return to the console. Tenvyr does not silently weaken the control because a browser session remains otherwise valid.
Tenant switching
An account may belong to more than one tenant. Switching tenant creates or uses a tenant-bound session; it does not make authorization global.