Administration
This section is for platform administrators: the people who decide which workspace requests become workspaces and who monitor the platform's protected signer and signing keys. If you administer your own organisation's workspace, see the Console guide instead.
Platform screens
Platform screens are separate from the tenant console. They are marked PLATFORM-RESTRICTED and share a two-tab navigation:
| Screen | Address | Purpose |
|---|---|---|
| Workspace reviews | /console/platform/onboarding | Approve or reject verified workspace requests. |
| Signer & keys | /console/platform/signer | Read-only health of the protected signer and every signing key set. |
Tenant console in the top right of either screen returns you to the normal console.
Access and sign-in
- Both screens require a platform administrator account with workspace-review permission. Without it, the screens do not load.
- Recording a review decision also requires MFA completed within the last ten minutes. A Re-authenticate button appears when you need to sign in again. See The ten-minute rule.
Authority boundaries
Neither screen grants PKI authority:
- Approving a workspace creates the workspace and activates its first administrator, but does not connect a CA or grant any signing permission.
- The signer screen is read-only and never displays private keys.
In this section
Workspace reviews
Reviewing verified workspace requests, approving them with a reserved tenant ID or rejecting them with a decision code, the ten-minute fresh sign-in rule, and how to resolve review errors.
Signer & keys
Reading the read-only Signer & keys screen: protected signer health, what each warning means and what to do, and the key sets table with status pills, pair checks and release publication.