The workspace admin surface is where the person responsible for your Vortex IQ AI OS workspace looks after the people, the roles they hold, the records of what they did, and the security posture of the whole tenant. Most controls live inside Settings → Account. A smaller set — the audit log, SSO configuration, ownership transfer — live in adjacent surfaces or require a support request for the most sensitive changes.Documentation Index
Fetch the complete documentation index at: https://docs.vortexiq.ai/llms.txt
Use this file to discover all available pages before exploring further.
Only users with the Admin role can access the admin panel, invite or remove teammates, change roles, view the full audit log, connect or disconnect data sources, manage subscriptions, or configure SSO. The Member role covers day-to-day operational access but not workspace configuration. If you do not see these controls, ask an Admin to adjust your role.
Admin panel overview
The admin surface is not a separate screen — it is the Account tab in Settings, visible to every user but with admin-only sections shown only to Admins.| Task | Where it lives |
|---|---|
| Invite a team member, assign role, remove access | Settings → Account → Team Members |
| Review your own profile and timezone | Settings → Account → Your Profile |
| Inspect organisation name and type | Settings → Account → Organisation |
| Audit log of every workspace change | Settings → Account → Activity (admin-only view) |
| Configure Google SSO | Settings → Account → Sign-in methods |
| Transfer ownership | Transfer ownership link at the bottom of Settings → Account (support-assisted) |
| Apply security best practice | Across Account, Connected Sources, and your IT policies |
Inviting users
Open Team Members
Sign in, click Settings in the left sidebar, stay on the Account tab, and scroll to the Team Members section.
Fill in the invite row
At the top of the Team Members panel you see three fields: Name (optional — the invitee can fill this in when they accept), Email address, and Role. Member is the safe default; pick Admin only if this person needs to manage other team members, billing, or workspace settings.
Click Invite
The invitee receives an email titled You have been invited to a Vortex IQ workspace. The email includes the workspace name, the role assigned, a Join workspace button carrying a magic-link token, and a note that the link expires after 24 hours.
Roles and permissions
Every member of your workspace holds exactly one role at a time, assigned when invited and changeable at any time from the Team Members table.Built-in roles
| Role | Purpose | Typical user |
|---|---|---|
| Admin | Full access including configuration, billing, and team management | Workspace owner, head of ecommerce, agency principal, IT lead |
| Member | Day-to-day operational access — no configuration or billing rights | Analysts, paid-media operators, merchandisers, customer-service leads |
What each role can do
| Capability | Admin | Member |
|---|---|---|
| Invite, suspend, remove team members | Yes | No |
| Change roles | Yes | No |
| View organisation details | Yes | Yes |
| Update organisation details | Yes | No |
| View and change billing / subscription | Yes | No |
| Connect or disconnect data sources | Yes | No (view only) |
| Create and edit Profiles | Yes | No (view and use only) |
| Configure brand voice and AI guardrails | Yes | No |
| Activate, configure, stop AI agents | Yes | No (view only) |
| Approve or decline agent recommendations | Yes | No |
| Use Ask Viq | Yes | Yes |
| View Nerve Centre dashboards | Yes | Yes |
| Generate and export Vortex Mind reports | Yes | View only |
| Use Vortex Apps | Yes | Yes (view and use) |
| View audit log | Yes | No |
| Configure SSO | Yes | No |
Custom roles
If your team needs an access tier between Admin and Member, an Admin can define a custom role with a precise permission set. Custom roles are built from the samemodule.action permission catalogue that drives the built-ins.
Common patterns:
Read-only Reporter
Read-only Reporter
For stakeholders, board members, or external auditors who need to see what is happening but must not change anything.Permissions granted:
nerve_centre.view, vortex_mind.view, vortex_mind.export, ask_viq.use, agents.view, audit_log.viewOperator
Operator
For senior analysts who run the day-to-day operations of the AI OS but must not manage the team, billing, or organisation-wide settings.Permissions granted: all Member permissions plus
agents.activate, agents.deactivate, agent_approval.approve, agent_approval.decline, monitors.create, monitors.update, monitors.silencePermissions excluded: team.*, billing.*, roles.*, organization.update, brand_ai.*Connector Manager
Connector Manager
For an integrations specialist who lives on the Sources tab.Permissions granted: all Member permissions plus
connector_manager.create, connector_manager.update, connector_manager.delete, audit_log.viewPermissions excluded: team.*, billing.*, agents.activate, roles.*Billing Only
Billing Only
For the finance team who need to view and pay invoices but must never see analytics data.Permissions granted:
organization.view, billing.view, billing.update, audit_log.view (filtered to billing actions)Permissions excluded: everything elseAudit log
The audit log is the searchable, tamper-evident record of every meaningful action taken in your workspace. It lives at Settings → Account → Activity (Admins only). Rows are listed newest first with filters across the top and an Export CSV button on the right.What is recorded
| Category | Examples |
|---|---|
| Team and access | Member invited, invite accepted, role changed, member suspended, member removed |
| Configuration | Organisation name updated, brand voice profile created or edited, guardrail term added or removed |
| Connected sources | Connector connected, connector edited, connector disconnected, OAuth token refreshed |
| Agents | Agent activated, agent deactivated, agent configuration changed |
| Agent approvals | Recommendation approved, recommendation declined, approval timed out |
| Billing and subscription | Plan upgraded or downgraded, payment method changed |
| Single sign-on | SSO enabled, domain restriction applied, SSO disabled |
Reading a log row
Each row shows: Date / Time (in your workspace timezone), Actor (the team member who initiated the action), Action (verb — Invite, Update, Delete, Activate, Approve, etc.), Resource type, Resource (specific item by name), Description (human-readable summary, including previous and new values for configuration changes), and Tags (contextual labels). Click any row to expand the full detail panel with the complete diff.Filtering and exporting
Filter the log by Action, Resource type, Tags, Actor, date range, or resource name. Filters are additive. Any filter combination can be saved and named for re-use. Click Export CSV to download the currently filtered rows — each row carries a stableevent_id you can cite in incident reports or compliance evidence.
Common audit-log workflows
“Who removed this connector?” — filter by Resource type = Connector and Action = Delete, set the date range. “Quarterly access review” — filter by Resource type = Member and Action = Update or Delete, set the date range to the quarter, export the CSV. “Who changed the brand voice last week?” — filter by Tags = Brand & AI and set the date range to the past week. Each row shows previous and new values in the description.SSO configuration
Single sign-on lets your team sign in to Vortex IQ using the identity provider you already use at work, without managing a separate password.Confirm Google SSO is on
Sign in as Admin, open Settings → Account, scroll to Sign-in methods, and confirm the Google SSO toggle is enabled. If your team signed up via Continue with Google, SSO is on by default.
Apply domain restriction
Domain restriction is the single highest-impact SSO control. With it on, only people whose Google identity matches an approved domain can sign in.
- Click Edit on the Google SSO row in Sign-in methods.
- Add one or more Allowed domains (use the apex domain —
yourbrand.com— not subdomains). - Save.
Optionally disable email and password sign-in
If your security policy requires every teammate to sign in via SSO only, toggle Allow email and password to off in Sign-in methods. After this change, new invites can only be accepted via Google, and existing members who used email and password are prompted to bind their Google identity on their next session.
For agencies, domain restriction needs more thought: client contacts may be on different domains. Configure the allow list with both the agency domain and each client domain as needed. For contractors on Gmail addresses, either issue them a Workspace identity on your domain or add
gmail.com to the allow list.Transfer ownership
Every workspace has one master account — the Admin who created the workspace at signup. This account is the legal and billing owner of record.Prerequisites
Before initiating a transfer, confirm:
- The new owner is already an active Admin in the workspace. Promote them first if not.
- The new owner’s email is verified and current — billing receipts and security alerts will be attributed to that email.
- You have read the audit log to know the current state of the workspace.
- Your finance team has been notified if billing-payment details will change.
Initiate the transfer
Sign in as the current owner, open Settings → Account, scroll to the bottom, and click Transfer ownership. The transfer wizard asks you to pick the new owner from the list of current Admins, confirm their email, and acknowledge that the action is permanent and not reversible from the UI.
New owner accepts
Click Send transfer request. The new owner receives an email titled You have been nominated as the new owner of [workspace name]. They click Accept ownership, sign in if not already signed in, and complete the acceptance. Vortex IQ support is copied for higher-tier plans and may ask both parties to confirm by email.
Security settings
Walk this checklist when you set up the workspace, then revisit it quarterly.Identity and sign-in
Identity and sign-in
- Google SSO is enabled for the workspace
- Domain restriction is on with an allow list that matches your organisation
- Email and password sign-in is disabled if your team is fully on Google Workspace
- 2-step verification is enforced at the Google Workspace or upstream IdP level
- Hardware security keys or passkeys are encouraged for Admins
- If you use enterprise SSO (SAML or OIDC), it is connected and tested
Roles and access
Roles and access
- Roles are assigned by responsibility, not seniority — Admin only for those who actually administer the workspace
- At least two Admins for continuity if one is unavailable
- Members hold the lowest role compatible with their job; custom roles fill gaps the built-ins do not cover
- You review the team list on a known cadence (quarterly is reasonable)
- Departing teammates are removed from the workspace within 24 hours of leaving the organisation
Audit and accountability
Audit and accountability
- You have opened the audit log at least once and know how to filter it
- You review configuration-change activity (Tags = Settings) monthly
- You export the audit log to CSV at least once per quarter for your security or compliance lead
- You forward the audit log into your SIEM, if you have one, alongside your IdP sign-in logs
Connected sources
Connected sources
- Every connected source is owned by a known, active person
- OAuth-issued connections are reviewed when the issuer’s role changes or they leave
- API keys and credentials for credential-based connectors are rotated quarterly
AI and agent governance
AI and agent governance
- Brand Voice Profiles reflect your written brand standards; reviewed every six months or after a brand refresh
- Global AI Guardrails reflect your zero-tolerance vocabulary
- Human-in-the-loop approval is on for every write-level agent action (platform-enforced and cannot be disabled)
- Agent activations are visible in the audit log; review the activation list quarterly
Billing and account integrity
Billing and account integrity
- The billing email is reachable by more than one person on your team (a finance shared inbox is a good choice)
- The payment method is in date
- You know which Admin is the master account and have a transfer-ownership plan for when they leave