> ## Documentation Index
> Fetch the complete documentation index at: https://docs.textql.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Admin & Governance

> A hands-on workshop for workspace administrators: identity and SSO, roles and permissions, connector governance, capability and model controls, monitoring, and the day-to-day op...

<p>A hands-on workshop for <b>workspace administrators</b>: identity and SSO, roles and permissions, connector governance, capability and model controls, monitoring, and the day-to-day operations of running TextQL safely at scale.</p>
<p>It runs as short, hands-on modules with exact click-paths, copy-paste prompts, what you'll see, and a checkpoint before moving on. Total time: <b>about 2.5 hours</b>.</p>

## What you'll be able to do

<CardGroup cols={2}>
  <Card title="Identity: SSO & SCIM">Login through your IdP; joiners and leavers handled automatically.</Card>
  <Card title="Roles & permissions">Least-privilege custom roles and the sharing model, demystified.</Card>
  <Card title="Connector governance">Who reaches which data, with which credentials, with what guardrails.</Card>
  <Card title="Capabilities & models">Org-wide tool toggles, model allowlists, limits, and spend.</Card>
  <Card title="Monitoring & audit">Audit log, thread-quality observability, and automated weekly review.</Card>
  <Card title="Governance operations">Patch review, access requests, on/offboarding, and the runbook.</Card>
</CardGroup>

## Before you start

<ol>
  <li>You need the <b>admin</b> role — ideally in a <b>staging org</b> for Modules 1–2.</li>
  <li>Work through modules <b>in order</b>: identity → authorization → data → monitoring → operations.</li>
  <li>Steps give exact <b>click-paths</b> (e.g., <i>Settings → Roles</i>) or <b>Prompts</b> to ask Ana. Adapt anything in <code>\[brackets]</code>.</li>
  <li>Don't skip <b>Checkpoints</b> — several settings have org-wide blast radius; checkpoints verify you haven't locked anyone out.</li>
</ol>

<Warning>
  Configuration details follow the current product docs at <a href="https://docs.textql.com/core/admin/settings" target="_blank">docs.textql.com</a>. VPC / self-hosted deployments: substitute your own host wherever you see <code>app.textql.com</code>.
</Warning>

<Accordion title="For facilitators — running this as a guided session">
  <p><b>T-minus-1-day pre-flight:</b> run the workshop's key prompts end-to-end in the session workspace — confirm logins, connectors, and the features this workshop touches are enabled for every attendee; have a fallback demo workspace ready in case a customer connector fails live. <b>Pacing:</b> when a long prompt is running (2–4 min), fire it first, then discuss the concept while Ana works — never watch a spinner in silence. If behind schedule, cut sections marked optional, never the checkpoints. <b>Group sessions:</b> attendees drive, you narrate; collect every miss or wrong answer in a shared doc — that list is the ontology backlog. With 10+ attendees on one warehouse, stagger the heavy prompts.</p>
</Accordion>
