Everything in the console
Directory, actions, logs, posture, evidence, browser.
One tenant. Customer-owned credentials. Technicians, engineers, and security see different surfaces.
Directory
One people list from Okta, Workspace, Entra, and Slack. Groups, aliases, OU, typeahead.
Actions
Suspend, reset password, sign out, group add/remove, tokens, MDM, SaaS admin — catalogued, ticketed, audited.
Workflows
Offboard and other multi-app runs. SpaceXAI picks catalog steps. High blast-radius stays gated.
Integrations
Customer OAuth or API JSON per app. API tests ping live endpoints. AI can add a new app to this tenant’s catalog.
Configuration health
Org score over time. Google Admin and Okta HealthInsight-style checks. Sections collapse. Apps isolate.
Security logs
Pull on connect and hourly. 429s back off. Investigate by person. Dump files for apps without a live pull.
Compliance
Framework packs: SOX ITGC, ISO Annex A, SOC 2 CC6–CC8, or a named custom set. Only that framework’s evidence.
Hosted browser
Isolated Chromium or the tenant’s Browserbase. Paste from the password manager. Recording and event log. No vault.
ITSM execute
Deep-link a ticket into Actions, or POST a signed execute so Adminzero runs the command. Tokens stay here.
No privileged seats in the tools
Technicians never collect Super Admin, Global Admin, or Org Owner. They work here, under tenant RBAC, on the customer’s own OAuth and API credentials.
Security cannot change a thing
The security role sees directory, events, and logs. It cannot launch actions, approve blast-radius, or touch integrations. Review is not a second admin.
Ticket-linked execution
Launch from ServiceNow, Freshservice, or Jira with the user and ticket already filled. The ITSM does not hold SaaS tokens. Adminzero does the write and the audit.
Hosted browser when there is no API
Isolated Chromium or the tenant’s Browserbase. Paste from the password manager. We never store passwords. The session is recorded.
Posture and logs without extra admin
Pull configuration health and security logs from connected apps. Investigate by person. Export framework-specific evidence. No live firehose, no extra Super Admin for the SOC.