Skip to main content

Platform Overview

The Platform admin area is a separate console used by Ascent operators to run the Ascent service itself — managing the MSP organizations on the platform, the people with platform-level access, subscriptions, and platform-wide settings. It is not part of the MSP-facing org app: it lives under /platform/*, has its own login, and org admins and technicians cannot see it.

Overview

From the Platform admin console, Ascent operators can:

  • Review platform-wide stats — total organizations, total users, active subscriptions, and monthly recurring revenue.
  • Manage every MSP organization on the platform (status, plans, and settings).
  • Manage users who hold platform-level roles.
  • Track subscriptions and billing across all organizations.
  • Audit platform-level activity across organizations.
  • Monitor system status (background jobs and worker health).
  • Configure the platform-managed email service, SSO for platform admins, and SCIM provisioning.

Who can access the Platform admin

The Platform admin console requires a platform role. There are three:

RoleScope
Platform Admin (PLATFORM_ADMIN)Full access to all platform pages
Platform Support (PLATFORM_SUPPORT)Dashboard, Organizations, Users, and the Audit Log. Some destructive organization actions (deleting and purging organizations) are reserved for Platform Admin.
Platform Billing (PLATFORM_BILLING)Dashboard and Billing (viewing and managing organization subscriptions)

Users without a platform role see an Access Denied screen. The navigation only shows the pages your role can reach, and several pages are further restricted to the Platform Admin role (noted below).

Platform operators sign in at the dedicated platform login and land on the Platform Admin dashboard at /platform. The dashboard shows stat cards (Total Organizations, Total Users, Active Subscriptions, Monthly Revenue), a Quick Actions grid, and a Recent Platform Activity feed drawn from the platform audit log.

Navigation across the top of the console exposes the following pages.

Platform pages

Dashboard

/platform — Platform-wide overview with key metrics, quick-action cards, and the latest events across all organizations.

Organizations

/platform/organizations — "View and manage all organizations on the Ascent platform." This is the master list of every MSP tenant. Each organization opens a detail page where operators can review and adjust its settings.

Users

/platform/users — "Manage users with platform-level access." Lists the people who hold platform roles, lets you manage their accounts and sessions, and links out to Configure SSO for platform sign-in.

Billing

/platform/billing — "Manage organization subscriptions and billing." Tracks monthly recurring revenue, active subscriptions, trials, and past-due accounts across all organizations. Visible to Platform Admin and Platform Billing roles.

Audit Log

/platform/audit — "View platform-level activity and changes." A searchable record of administrative actions and security-relevant events across the platform.

System Status

/platform/system-status — "Monitor background jobs and worker health across the platform." Shows scheduled job runs, recent job executions, queue statistics, and worker health, with maintenance actions for clearing stuck or pending jobs. Restricted to the Platform Admin role.

Email Settings

/platform/email-settings — "Configure the platform-managed email service used to send transactional email on behalf of organizations." Restricted to the Platform Admin role.

SSO

/platform/sso — "Configure single sign-on for platform administrators." Platform SSO is separate from organization-level SSO; these providers authenticate users who hold platform roles. Supported provider types are Microsoft Entra ID, Google Workspace, Authentik, and generic OIDC. The page also has a Password Authentication toggle; once you have added and enabled an SSO provider, you can turn password authentication off so platform admins can only sign in via SSO. This page is not in the main navigation bar — it is reached from the Users page via the Configure SSO link. Restricted to the Platform Admin role.

SCIM

/platform/scim — "Provision platform users from your identity provider (Okta, Entra, JumpCloud)." Manages SCIM clients and tokens for automated provisioning of platform users. Restricted to the Platform Admin role.

Terms of Service

/platform/tos — "Manage ToS versions and view user acceptance records." Edit the platform Terms of Service content, publish new versions, and review who has accepted the current version. Editing the content and publishing new versions are restricted to the Platform Admin role.

Tips

  • The Platform admin console is intentionally isolated from the MSP org app. If you are an MSP technician or org admin looking for client, ticket, or billing management, use the main app instead — see the Dashboard overview.
  • Platform SSO and organization SSO are configured in different places and serve different audiences. Configure platform SSO here only for users who administer the Ascent service itself.