Skip to main content

Tenant administration

Tenant administration controls who can see data, run actions, manage organizations, export portable tenant data, restore tenant data, and request deletion.

Role model

  • Viewer: read-only access to endpoint status, inventory, and logs.
  • Operator: run operational endpoint actions such as scripts, patch scans, patch installs where supported, terminal sessions where supported, agent updates, and reboot workflows where supported.
  • Admin: manage organizations, higher-risk operational settings, redacted tenant exports, and redacted export schedules.
  • Owner: perform tenant-sensitive actions such as Data Storage Connection setup and recovery, encrypted full tenant exports, full-package recurring schedules, tenant restore, billing, and deletion requests.

Operating as

The operating-as selector lets a user voluntarily cap their effective role. This is useful for testing lower-permission behavior before inviting another user.

Data export, restore, and deletion

Portable tenant export and restore are managed from Administration → Tenant Settings → Data Exports in the portal.

Tenant admins and owners can create redacted exports. Tenant owners can create encrypted full exports, configure full-package recurring schedules, and run the restore workflow. Ordinary completed asynchronous export packages remain available from TvRMM for 72 hours.

Google Drive export delivery uses customer-encrypted packages and ready Data Storage Connections. Data Storage Connections are a Policy Center policy type. Direct tenant owners create, authorize or reconnect, choose the storage root, validate, disconnect, and delete Google Drive connections there. Tenant admins can use ready connections for permitted redacted exports and redacted schedules, but they do not authorize or connect Drive accounts.

Tenant restore is owner-only. TvRMM stages and validates the uploaded package, encryption password, and any required redacted-value mappings before the final apply step. The final restore commit atomically replaces the tenant's current portable data, so owners need a mandatory encrypted safety export, external safety evidence, and a reviewed validation result before confirming the operation.

Tenant deletion queues persistent uninstall for real tenant agents before hiding data.

See Tenant export and restore for the task-oriented export, schedule, delivery, and restore workflow.

Billing controls

Tenant owners can manage hosted billing where available. Billing controls may include:

  • starting hosted billing through Stripe Checkout;
  • opening the Stripe billing portal;
  • setting self-service agent limits;
  • reviewing eligible promotion-code inventory and redeeming campaign codes after signup;
  • viewing active, stale-excluded, chargeable, and unlicensed agent counts;
  • reviewing account credit, promotion provenance, pending refunds, invoices, invoice lines, and protected pricing;
  • canceling billing and using the 30-day wind-down period for export, cleanup, uninstall, and migration.

Billing export includes aggregate billing metadata, invoice records, account-credit history, promotion provenance, and Stripe object IDs. It excludes payment method details, Stripe secret keys, webhook signing secrets, and raw webhook payloads.

Campaign offer details, including the current Reddit subscriber campaign terms, are covered in Promotion codes and campaign offers.