Configure tenant AI and agent settings
Evaluate tenant AI and agent controls with documented provider ownership, data policy, least privilege, testing, and an explicit preview boundary.
Audience, roles, and scope
Admin AI and agent configuration surfaces; provider contracts, runtime guarantees, and production approval remain external governance responsibilities.
Who this is for
- Tenant AI administrators
- Security and privacy reviewers
Roles
- Tenant administrator
- AI administrator
- Security reviewer
Before you begin
- Approved AI use case and accountable owner
- Data classification and provider assessment
- Test plan, monitoring, and disable path
Article tags
- ai
- agents
- byoai
- provider
- governance
- preview
Procedures
Follow the sequence and stop when identity, authorization, target, or result differs from the article.
Evaluate an AI configuration
Use non-production values and harmless test data until capability and governance are confirmed.
- 1Complete governance review
Document purpose, users, provider, model, regions, data use and retention, subprocessors, risks, and accountable approvers.
- 2Inspect configuration boundaries
Confirm whether the screen is connected or preview-only; never paste a real credential into an unverified or mock interface.
- 3Test before enablement
Use non-sensitive test inputs, verify output and failure behavior, logging, access, cost controls, and an operational disable path.
The tenant can distinguish a preview from a connected service and does not enable AI without approved controls.
Security and data handling
- Use only the identity, tenant, role, and data scope approved for the task.
- Verify targets and expected effects before saving, sending, publishing, exporting, deleting, or approving.
- Keep secrets and regulated data out of screenshots, URLs, free-text diagnostics, and ordinary support messages.
- Store provider credentials only in an approved secret manager and rotate them if exposed.
- Do not assume a model provider may process tenant data merely because its name appears in the interface.
Known limitations
- The BYOAI configuration is explicitly a beta mock preview and does not establish a production provider connection or credential-storage guarantee.
- Agent behavior, models, costs, region, retention, logging, and tool access are deployment- and provider-specific.
Troubleshooting
You cannot open Vianordis Admin
Likely cause: The session expired, the account is not entitled, or the required tenant or role claim is missing.
- Open the service through the approved Vianordis entry point and sign in again.
- Confirm the intended organization, tenant, and account are in use.
- If access remains denied, record the time and request an entitlement check; do not attempt direct-URL bypasses.
A documented control or navigation item is not visible
Likely cause: The current role, subscription, tenant configuration, release status, or feature flag does not expose it.
- Confirm the audience, role, prerequisites, and limitations in this article.
- Refresh after a new sign-in and verify the correct tenant context.
- Ask the responsible administrator whether the capability is enabled before reporting a defect.
A saved change or background result is not visible
Likely cause: Validation failed, processing is incomplete, the view is stale, or the feature is locally simulated rather than persisted.
- Review inline validation, status indicators, filters, and the selected tenant or workspace.
- Refresh once and search by a stable identifier before repeating the action.
- Do not repeat irreversible or externally visible actions until the first operation's state is known.
Source verification
AI, agent, and BYOAI configuration code was reviewed; the BYOAI interaction is explicitly a mock preview in the pinned revision.
Reviewed paths at 8f3a86e
src/app/(base)/settings/ai/page.tsxsrc/components/ByoaiProvidersView.tsxsrc/components/TenantAgentSettings.tsxsrc/lib/byoai.ts
Contact support
Contact support when
- A repeatable Vianordis Admin error blocks an approved task
- Expected access, tenant scope, data, or status appears incorrect
- A security, privacy, financial, compliance, or data-loss concern is suspected
Include
- The page, action, expected result, and exact error text
- The time of occurrence with time zone and whether it is reproducible
- Your tenant, role, browser, and sanitized record or correlation identifier
- The troubleshooting steps already completed
Never include
- Passwords, access tokens, API keys, recovery codes, session cookies, or private keys
- Unredacted personal, financial, health, student, employee, or other regulated data
- Confidential documents or message bodies unless support provides an approved secure channel