Skip to main content
MoleSignal separates three administration contexts.

Workspace administration

Use IAM for users and access:
  • pending user approvals, members, and invitations;
  • teams and service accounts;
  • built-in and custom roles;
  • role bindings, resource relationships, and cross-organization grants;
  • email-domain policy and SSO providers.
Use Settings for workspace and operational policy:
  • workspace name, stable identifiers, signup, sharing, and preference defaults;
  • billing where SaaS is available;
  • remote clusters and nodes;
  • cipher keys, regex patterns, domains, correlation, model pricing, and running queries;
  • audit events.

Platform administration

The permanent _sys organization is not a normal tenant. A system-scoped session can access only the routes granted by platform permissions. Typical platform permissions include:
  • sys.organizations.manage;
  • sys.licenses.read and sys.licenses.manage;
  • sys.telemetry.read, sys.telemetry.manage, and sys.trace_debug.manage;
  • sys.administrators.manage;
  • sys.settings.manage.
Tenant JWTs and ms_* API tokens cannot discover protected _sys metadata.

Where to continue

Identity & access

Roles, permissions, groups, service accounts, SSO, and cross-workspace access.

Settings

Workspace and platform settings by section.

Resource sharing

Share dashboards and reports safely.

Editions

Compare OpenSource Edition, Enterprise Edition, and the planned MoleSignal Cloud model.
Last modified on August 13, 2026