Enterprise Administration

Manage your organization with the Enterprise Admin console — members, roles, tenants, governance, and integration policies

Enterprise Administration

Enterprise plan subscribers get a dedicated administration console for managing members, roles, tenants, teams, integration policies, governance settings, and audit logs across the organization.


Accessing Enterprise Admin

If you have enterprise administration privileges, an Enterprise section appears in the dashboard sidebar with an Enterprise Admin link. Click it to open the Enterprise console.

The console uses a horizontal tab bar to navigate between sections. Which tabs you see depends on your capabilities — users with full enterprise:manage access see all sections, while users with narrower roles (e.g., auditor or tenant admin) see only the sections they have permission to view.

If your organization is not on the Enterprise plan, the console shows an upgrade prompt.

Overview Dashboard

The Overview tab is the landing page of the Enterprise console. It displays summary counts and quick links:

  • Members — total count with seat usage
  • Tenants — number of tenants in the organization
  • Teams — number of teams
  • Roles — configured roles
  • Hosts — enrolled DAP hosts
  • Integration policies — active integration access policies
  • Recent audit activity — latest actions across the organization

Shortcut buttons let you jump directly to Invite members, Manage roles, or Governance settings.

Members

The Members tab provides a full organization directory with three sub-tabs: Members, Invitations, and Removed.

  • Search and filter — find members by name or email
  • Invite — send email invitations to new members
  • Bulk actions — suspend, reactivate, or remove multiple members at once
  • Export — download the member list
  • Detail drawer — click a member to view their teams, role bindings, and account details

Roles

The Roles tab lets you create and manage roles that control what members can do across the organization.

  • Create role — define a new role with a name, description, scope (organization, tenant, team, or host), and capabilities
  • Presets — start from a built-in preset (Enterprise Admin, Tenant Admin, Member, Auditor) and customize
  • Edit — modify capabilities on existing custom roles
  • Delete — remove custom roles (built-in default roles cannot be deleted)

Each role bundles capabilities like enterprise:manage, tenant:manage, team:manage, billing:view, integration:configure, audit:view, and more. Assign roles to members from the Members tab.

Tenants

The Tenants tab manages logical subdivisions within your organization. Each tenant can have its own teams, integrations, and DAP configuration.

  • Create tenant — add a new tenant with a name and slug
  • Rename — update a tenant's display name or slug
  • Assign teams — control which teams belong to each tenant
  • Delete — remove tenants that are no longer needed

Teams

The Teams tab provides team-level management within the organization.

  • Create team — add a new team and assign it to a tenant
  • Rename — update team names
  • Manage members — add or remove members from teams
  • Delete — remove teams

Integration Allowlist

The Integrations tab lets you control which integration templates are available across your organization.

  • All integrations mode — all integration types are available to members (default)
  • Restricted mode — only explicitly allowed integration types can be configured by members

In restricted mode, the page shows the full integration catalog with per-row Allowed or Blocked status. Each row displays the integration name, category, authentication type (API key, MCP OAuth, OAuth), and tool count. Use the search and filter controls to find specific integrations.

Smithery marketplace integrations support a wildcard (smithery:*) to allow all Smithery tools at once, or you can allow individual Smithery integration templates by name.

You need integration:configure or enterprise:manage capabilities to edit the allowlist. Users without these capabilities see a read-only view.

Governance

The Governance tab manages organization-wide policies:

  • SSO required — enforce single sign-on for all members
  • JIT elevation — configure just-in-time privilege elevation preferences
  • Audit trail required — require audit logging for all actions
  • Invite domain allowlist — restrict invitations to specific email domains
  • Owner review note — a note visible only to enterprise admins for internal documentation

Audit Log

The Audit tab shows a filterable activity log of actions taken across the organization. You can filter by date range, action type, and user. A CSV export button downloads the filtered log for offline analysis or compliance reporting.

Settings

The Settings tab lets you rename your organization and tenant display names.

Host Lifecycle

The Host lifecycle tab lets enterprise and platform administrators decommission worker bootstrap enrollments per product plane.

Navigate to EnterpriseHost lifecycle in the dashboard sidebar. The page lists active worker bootstrap enrollments for the selected product (currently Splunk Enterprise). Each row shows hostname, host ID, enrollment status, and last-seen time.

Decommissioning a Host

  1. Select the worker product plane from the dropdown (for example, Splunk Enterprise).
  2. Click Decommission on the host row, or open the page with a hostId query parameter from a node detail link.
  3. Optionally enable Purge observed inventory to delete the Observer host row and cascaded configs, compliance findings, and operational state. Leave this off to clear enrollment only while keeping inventory history.
  4. Type the host hostname to confirm and click Decommission.

After decommission, the host can enroll again with a new worker token once the bootstrap package is removed from the server. Use the Uninstall worker action on the node detail page for on-host cleanup snippets.

You need dap:product:splunk-enterprise:manage, dap:platform:manage, or enterprise administration capabilities to decommission hosts.

If you have administrative capabilities, a Workspace administration card appears on the General dashboard page (your personal account settings). This card shows capability-gated shortcuts to the most common Enterprise Admin surfaces:

  • Tenants — create and rename tenants
  • Teams — manage team membership
  • Members — invite and manage organization members
  • Roles — edit role assignments
  • Settings — organization-level configuration

Each link respects your current role — you only see shortcuts to sections you have permission to manage. If you have no administrative capabilities, the card does not appear.

Enterprise Administration | Deslicer AI Docs