Deep Dive
Platform administration
Create tenant administrators and govern the shared SQIP platform
The Platform Admin area is visible only to platform administrators. It provides global governance while tenant administrators manage day-to-day resources inside their tenants.
Create a tenant administrator
Open Platform Admin → Manage platform and complete Create tenant administrator.
| Field | What to enter |
|---|---|
| Full name | The administrator's real name |
| Their work email address | |
| Temporary password | A unique password of at least 12 characters |
The new administrator receives the tenant-admin role and must choose a new password at first sign-in.
Warning
Send the temporary password through a trusted private channel. Do not send it in a shared chat room or support ticket.
Tenant governance
The global tenant directory shows each tenant's status and cluster count.
- Suspend prevents normal tenant use while preserving its records and configuration.
- Activate restores a suspended tenant.
- Remove permanently deletes the tenant after confirmation.
Tenant removal requires entering the exact tenant slug. Review dependent topics, connectors, API keys, users, and retained data before confirming.
Shared platform views
Platform Admin contains these sections:
| Section | Purpose |
|---|---|
| Manage platform | Tenant administrators, tenant status, shared cluster status, and provisioning queue |
| Topics | Global topic management across tenants |
| Access and RBAC | Global API-key administration by tenant |
| Audit access | Search the platform audit ledger grouped by tenant |
| Notifications | Control which delivery channels tenants may configure |
Notification channel availability
A tenant can enable email, Slack, or Microsoft Teams only when the channel is available at platform level. Disabling a channel stops tenant deliveries but preserves their saved destination so it can resume later.
Only enable a channel after its delivery service has been configured and tested.
See Notifications for tenant configuration, effective channel state, retry behavior, and dead-letter operations.
Shared capacity
Platform administrators monitor the shared fleet, failed operations, reserved namespace capacity, and current storage pressure. When capacity is constrained:
- Identify tenants and namespaces with the highest quota reservations and usage.
- Review active warnings and critical alerts.
- Coordinate quota changes with tenant administrators.
- Add or adjust managed capacity before accepting large new reservations.
Separation of duties
- Platform administrators manage global identities and governance.
- Tenant administrators manage resources and access inside their tenants.
- Cluster administrators operate streaming resources without receiving tenant-administrator authority.
- Usage administrators receive operational visibility without change access.
Use tenant-scoped roles whenever global authority is not required.