PlcConsole
Remote Manual · Platform

Platform and tenant administration

Create organizations, invite their first administrators and control tenant lifecycle without mixing platform and tenant operations.

Tenant Directory

Manage organizations from the platform boundary

The tenant directory is available to platform administrators. It is separate from the tenant-scoped operational catalogs.

Onboarding

Invitation activates the tenant

Tenant creation generates a single-use invitation for the nominated tenant administrator. The tenant remains disabled until that invitation is accepted. Acceptance creates the tenant administrator account, seeds tenant role templates when required and activates the tenant.

Expired or already-used invitations cannot be replayed. Standard invitation and user-creation flows always create tenant users rather than platform administrators.

Current Tenant

Verify organization details and local administrators

Lifecycle

Disable is temporary, archive is terminal

Use Disabled when access should pause but the tenant may return. Use archive when the tenant should be hidden from normal administration and excluded from active-session flows. Both choices preserve history; archive is a soft-delete style terminal state rather than physical deletion.

Responsibility Boundary

Use platform authority only for platform work

ResponsibilityPlatform administratorTenant administrator
Tenant directoryCreate, inspect, select, disable, re-enable and archive tenant records.No cross-tenant directory access.
Tenant onboardingNominate the first tenant administrator and resend a pending invitation.Accept the invitation and continue tenant-local administration.
Tenant catalogsMay enter a tenant context for support or administration.Manage users, sites, PLCs, roles, permissions, policies, agents and audit within their own tenant.
Platform-admin identityMay explicitly create or edit platform administrators where the gated UI permits it.Ordinary create-user and invite flows always create tenant users.
Context rule: the tenant directory remains a platform surface. Tenant-scoped changes should be performed only after the header confirms the intended Acting on behalf of tenant.
Procedure

Create, invite and hand over a tenant

Before you begin

  • Confirm the tenant name and company details.
  • Confirm the first administrator's email.
  • Know whether SMTP invitation delivery is enabled.
  • Check that the tenant does not already exist under a similar name.

Expected result

The tenant is created with an invitation pending and remains disabled until acceptance. Acceptance creates the tenant administrator, seeds missing tenant role templates and activates the tenant.

Steps

  1. Choose Create tenant and enter the organization details plus invited administrator email.
  2. Submit and verify Invite pending in the directory.
  3. If email delivery is disabled, retrieve and deliver the logged invitation URL through a trusted private channel. Do not place it in ordinary tickets or public chat.
  4. Resend only when needed; the recipient should use the newest valid invitation.
  5. After acceptance, switch to the tenant and verify the local administrator from the Tenant page.
  6. Create sites, connectivity and PLC records only after the ownership boundary is confirmed.
Lifecycle Safety

Pause access differently from ending the tenant relationship

Disable

Use Disabled for a temporary suspension where the tenant may return. Preserve the record, investigate the reason and re-enable only after the access condition is resolved.

Archive

Use archive as the terminal soft-delete style action. The tenant disappears from normal lists and active-session flows while historical evidence remains.

Before archive

  1. Confirm that a temporary disable is not sufficient.
  2. Review active administrators, users, agents, PLCs and service integrations.
  3. Export or retain required evidence according to the applicable retention policy.
  4. Read the confirmation count, especially after filtering or bulk selection.
  5. Archive and verify that the tenant is absent from the normal directory.
If onboarding appears stuck: verify whether the problem is message delivery, an expired link or an already-used invitation. Do not create duplicate tenants to work around an invitation problem.