Admin Users

Instance-wide operators. Once approved, they can manage any tenant (Sources, Config). Tenant data for consumers still requires that tenant’s consumer secret. Admins review pending access requests here.

Add admin user

Role Admin

Admin users

EmailRoleStatusAdded

Break-glass operator secret

Instance-wide escape hatch for admin APIs when Microsoft sign-in is unavailable. Rotating replaces env EM_ADMIN_SECRET for break-glass auth immediately. Day-to-day access should remain Microsoft sign-in. Save the new value in your vault and update .env for disaster recovery — it is shown only once.