Understand administrator access
Distinguish tenant and application administration, verify active scope, and avoid assuming that interface visibility grants authority.
Audience, roles, and scope
Administrator access context in Admin; organization policy remains the authority for who may perform each action.
Who this is for
- New or existing Vianordis administrators
- Security reviewers
Roles
- Tenant administrator
- Application administrator
- Authorized reviewer
Before you begin
- A formally approved administrator role
- A named accountable owner and tenant scope
Article tags
- administrator
- roles
- tenant
- access-control
Procedures
Follow the sequence and stop when identity, authorization, target, or result differs from the article.
Verify administrator context
Confirm identity, tenant, role, and intended change before using privileged controls.
- 1Open Admin through the approved entry point
Authenticate normally and stop if the identity or organization shown is unexpected.
- 2Confirm role and scope
Identify whether the task is tenant-wide or application-specific and compare it with the approved request.
- 3Use least privilege
Perform only the approved change, verify its result, and retain the appropriate change or ticket reference.
Administrative work occurs under the correct identity, tenant, role, and documented purpose.
Security and data handling
- Use only the identity, tenant, role, and data scope approved for the task.
- Verify targets and expected effects before saving, sending, publishing, exporting, deleting, or approving.
- Keep secrets and regulated data out of screenshots, URLs, free-text diagnostics, and ordinary support messages.
- Use a separate administrative identity where organization policy requires it.
- Do not share administrator sessions or approve a change solely because a control is visible.
Known limitations
- Displayed controls can depend on claims, subscription, configuration, or feature flags and do not define organization authority.
- Role names and approval requirements can vary by tenant policy.
Troubleshooting
You cannot open Vianordis Admin
Likely cause: The session expired, the account is not entitled, or the required tenant or role claim is missing.
- Open the service through the approved Vianordis entry point and sign in again.
- Confirm the intended organization, tenant, and account are in use.
- If access remains denied, record the time and request an entitlement check; do not attempt direct-URL bypasses.
A documented control or navigation item is not visible
Likely cause: The current role, subscription, tenant configuration, release status, or feature flag does not expose it.
- Confirm the audience, role, prerequisites, and limitations in this article.
- Refresh after a new sign-in and verify the correct tenant context.
- Ask the responsible administrator whether the capability is enabled before reporting a defect.
A saved change or background result is not visible
Likely cause: Validation failed, processing is incomplete, the view is stale, or the feature is locally simulated rather than persisted.
- Review inline validation, status indicators, filters, and the selected tenant or workspace.
- Refresh once and search by a stable identifier before repeating the action.
- Do not repeat irreversible or externally visible actions until the first operation's state is known.
Source verification
Admin navigation, route access context, and administrator-facing areas were reviewed in the pinned source.
Reviewed paths at 8f3a86e
src/app/page.tsxsrc/components/AdminShell.tsxsrc/lib/authz.tssrc/lib/effective-roles.ts
Contact support
Contact support when
- A repeatable Vianordis Admin error blocks an approved task
- Expected access, tenant scope, data, or status appears incorrect
- A security, privacy, financial, compliance, or data-loss concern is suspected
Include
- The page, action, expected result, and exact error text
- The time of occurrence with time zone and whether it is reproducible
- Your tenant, role, browser, and sanitized record or correlation identifier
- The troubleshooting steps already completed
Never include
- Passwords, access tokens, API keys, recovery codes, session cookies, or private keys
- Unredacted personal, financial, health, student, employee, or other regulated data
- Confidential documents or message bodies unless support provides an approved secure channel