> ## Documentation Index
> Fetch the complete documentation index at: https://docs.textql.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Admin & Governance

> A hands-on workshop for workspace administrators: identity and SSO, roles and permissions, connector governance, capability and model controls, monitoring, and the day-to-day op…

A hands-on workshop for **workspace administrators**: identity and SSO, roles and permissions, connector governance, capability and model controls, monitoring, and the day-to-day operations of running TextQL safely at scale.

It runs as short, hands-on modules with exact click-paths, copy-paste prompts, what you'll see, and a checkpoint before moving on. Total time: **about 2.5 hours**.

## What you'll be able to do

<CardGroup cols={2}>
  <Card title="Identity: SSO & SCIM">Login through your IdP; joiners and leavers handled automatically.</Card>
  <Card title="Roles & permissions">Least-privilege custom roles and the sharing model, demystified.</Card>
  <Card title="Connector governance">Who reaches which data, with which credentials, with what guardrails.</Card>
  <Card title="Capabilities & models">Org-wide tool toggles, model allowlists, limits, and spend.</Card>
  <Card title="Monitoring & audit">Audit log, thread-quality observability, and automated weekly review.</Card>
  <Card title="Governance operations">Patch review, access requests, on/offboarding, and the runbook.</Card>
</CardGroup>

## Before you start

* You need the **admin** role — ideally in a **staging org** for Modules 1–2.
* Work through modules **in order**: identity → authorization → data → monitoring → operations.
* Steps give exact **click-paths** (e.g., *Settings → Roles*) or **Prompts** to ask Ana. Adapt anything in `[brackets]`.
* Don't skip **Checkpoints** — several settings have org-wide blast radius; checkpoints verify you haven't locked anyone out.

<Warning>
  Configuration details follow the current product docs at [docs.textql.com](https://docs.textql.com/core/admin/settings). VPC / self-hosted deployments: substitute your own host wherever you see `app.textql.com`.
</Warning>

<Accordion title="For facilitators — running this as a guided session">
  **T-minus-1-day pre-flight:** run the workshop's key prompts end-to-end in the session workspace — confirm logins, connectors, and the features this workshop touches are enabled for every attendee; have a fallback demo workspace ready in case a customer connector fails live. **Pacing:** when a long prompt is running (2–4 min), fire it first, then discuss the concept while Ana works — never watch a spinner in silence. If behind schedule, cut sections marked optional, never the checkpoints. **Group sessions:** attendees drive, you narrate; collect every miss or wrong answer in a shared doc — that list is the ontology backlog. With 10+ attendees on one warehouse, stagger the heavy prompts.
</Accordion>

<Note>
  **🤖 Prefer to have Ana run this workshop?** Open a thread with your data connected and paste the prompt below — Ana walks you through it on your own data, one step at a time. You run each prompt; she coaches. *(Air-gapped / VPC tenants where Ana can't reach the web: download [`ana-runner.md`](https://github.com/TextQLLabs/workshops/blob/main/admin-governance/ana-runner.md) and paste its module list instead.)*
</Note>

```text Run with Ana theme={null}
Hey Ana — facilitate the "Admin & Governance" workshop with me on this workspace. It has steps I do in the console/CLI, so: first inspect the current state (connectors / roles / context / git, as relevant) and tell me where we're starting. Then go ONE step at a time — for analysis steps hand me the prompt to run; for console/setup steps tell me exactly what to do, then WAIT until I say "done" and re-check before moving on. If I leave and come back, re-inspect and resume. Start by telling me what you see.
```

[**▶ Open in Ana — prompt loaded**](https://app.textql.com/chat/new?prefill=Hey%20Ana%20%E2%80%94%20facilitate%20the%20%22Admin%20%26%20Governance%22%20workshop%20with%20me%20on%20this%20workspace.%20It%20has%20steps%20I%20do%20in%20the%20console/CLI%2C%20so%3A%20first%20inspect%20the%20current%20state%20%28connectors%20/%20roles%20/%20context%20/%20git%2C%20as%20relevant%29%20and%20tell%20me%20where%20we%27re%20starting.%20Then%20go%20ONE%20step%20at%20a%20time%20%E2%80%94%20for%20analysis%20steps%20hand%20me%20the%20prompt%20to%20run%3B%20for%20console/setup%20steps%20tell%20me%20exactly%20what%20to%20do%2C%20then%20WAIT%20until%20I%20say%20%22done%22%20and%20re-check%20before%20moving%20on.%20If%20I%20leave%20and%20come%20back%2C%20re-inspect%20and%20resume.%20Start%20by%20telling%20me%20what%20you%20see.)

Ana gates on the setup steps and resumes if you step away. (Air-gapped / VPC tenants: download [ana-runner.md](https://github.com/TextQLLabs/workshops/blob/main/admin-governance/ana-runner.md) and follow the steps.)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.