Use Topline
Use Topline: Tenant administration
Manage Profile, Resources, members, capabilities, credentials, billing visibility, usage metering reviews by user and customer, Brand, and audit investigations safely.
Tenant Administration Guide
Tenant administrators manage member access, credentials, billing visibility, capacity requests, brand, and audit history. Use these controls to grant the least access needed and preserve a reviewable operational record.
Access
Open the relevant account page:
- Profile at
/account/profileis visible to every signed-in member; - Usage at
/account/usagelets active members review their own usage and personal coding limits; organization views require billing visibility; - Team Members at
/account/membersrequires member-management visibility; - Credentials at
/account/credentialsrequires secret-management access; - Billing at
/account/billingrequires billing visibility; and - Resources at
/account/resourcesrequires customer-resource management; - Brand at
/account/brandrequires organization-management access; and - Audit Log at
/account/audit-logrequires audit visibility.
Unavailable pages or controls indicate the active account lacks the required tenant capability. Access is enforced by the API as well as the interface.
Profile and session
Profile lets the current user change their display name, inspect their account identity and access summary, or sign out. Tenant-owned role, capability, and resource access remain administrator controls even when personal details are editable.
Manage a member
- Open Team Members and confirm the active tenant.
- Invite or select the member.
- Select the correct access type, including Chat-only only when the person should use enabled Slack or Google Chat without the web workspace or builder.
- Grant only the product roles, capabilities, workspace access, and app access required for their work.
- Set Read organizational memory and Contribute to organizational memory independently. Turning contribution off keeps otherwise authorized chat available and does not delete previously accepted memory.
- Verify the member can reach one intended resource and cannot reach an out-of-scope resource.
- Resend an invitation only when the existing invitation is still the intended identity and tenant.
- During offboarding, archive the member, remove resource memberships, and revoke credentials, MCP grants, or other access owned by that person.
Manage credentials safely
Create a named secret reference with a clear owner and purpose. Topline displays metadata, versions, consumers, and health, not the stored value after creation. Rotate by adding the replacement, testing every consumer, promoting the new version, and then revoking the old value. Delete only after the consumer review shows the reference is no longer required. Never paste a credential into chat, documentation, artifact source, or audit notes.
Review billing
Use Billing to review the selected period, plan, invoice or reconciliation state, customer charges, pricing, and line items made visible to the tenant. The cost breakdown groups model usage under AI usage and coding-tool usage under Coding agent. It does not list the specific models or providers behind those charges. Topline operators retain that detail in the access-gated Admin usage view for reconciliation. Keep provider cost, customer charge, markup, credits, tax, and invoice reconciliation distinct. Treat unavailable, delayed, or unresolved provider data as unknown rather than zero. Export or share billing details only with authorized recipients.
Customer administrators can also manage Coding usage from Billing. Topline sets the included allowance and versioned customer price; one coding credit is one cent of customer charge, and the configured charge is never below the underlying provider cost. Administrators can:
- stop all new coding tasks immediately;
- allow or block paid usage after the included allowance;
- pause new paid usage immediately without changing the next-month plan;
- set a finite organization paid-usage limit and concurrency limit;
- leave new people blocked by default or give them a default monthly allowance;
- set a tighter allowance, paid-usage toggle, paid limit, and concurrency limit for an individual; and
- return an individual to the organization defaults; and
- select active tenant administrators who should receive organization budget email alerts.
Usage includes both settled and pending reserved credits so simultaneous tasks cannot spend past a cap. The page shows an in-product alert at 80% of the included allowance, when paid usage begins, and when the hard limit is reached. Each organization threshold is recorded once per month. Selected active administrators receive the matching organization alert by email; individual alerts remain in-product. Billing also shows a current-pace forecast, recent task charges and reservations, pending reconciliation age, and durable alert history. A forecast is directional, not an invoice or a guarantee.
The same thresholds appear on an affected person's card. Changes to the organization's included allowance, paid allowance, or price apply to the next monthly period after a period has been opened; access, concurrency, and per-person limits apply immediately. Pause new paid usage now also applies immediately after save: existing included credits remain usable, but a new reservation cannot cross into paid usage. Topline-absorbed provider overrun is shown separately and does not consume the customer's allowance. All customer changes are written to the tenant audit log.
Usage metering by user and customer
Usage metering helps administrators and finance understand which features consume resources, who initiated work, and which customer the work relates to. It can support usage reviews and billing reconciliation alongside the existing Billing page. Open Usage from the account menu or Billing. My usage shows only the signed-in member's attributed activity. Members with billing visibility can choose Organization to see totals and filter by person. Managing organization limits separately requires billing-management permission. Availability depends on the release installed for your organization; an unavailable report is not zero usage.
What can be measured
| Feature | Measurement | How to interpret it |
|---|---|---|
| Chat | Model tokens | Token usage from recorded chat invocations; provider counters and costs remain separate. |
| Customer Profiles operations | Profile operations | Work associated with a customer, including background work that may have no initiating user. |
| Customer Profiles monthly usage | Active customer-month quantity | Quantity from the monthly commercial statement; this is a tenant-level measure and cannot always be broken down by person or individual customer. |
| SMS | Message segments | Actual provider evidence is required for settled usage; estimated segments remain provisional. |
| Build | Coding credits | Usage linked to coding reservations; raw model tokens and provider costs are separate measures. |
These measurements cover their supported source records. They do not imply that every connector, feature, historical period, or background action is metered. Your organization is the account boundary; a customer grouping refers to a customer identifier recorded by a source within that organization. A user or customer breakdown is available only when the source has the required identity evidence. Unknown attribution stays unattributed. Renaming or deactivating a member does not move their past usage to someone else.
Review your usage
- Open Usage, choose My usage or the authorized Organization view, and select a UTC calendar month and feature. Organization viewers can narrow the results by person. Personal reports show allowances and quantities without dollar amounts. Select the current month to view or update today's daily coding allowance and personal controls.
- Confirm which sources and dates are covered. An empty result is not proof of zero consumption; a partial first month or missing historical evidence may remain incomplete.
- Review feature quantities and allowance credits separately. Detailed dollar spending remains in authorized billing and administration views. Different units cannot be added into one usage total. Internal provider costs, shared cost allocations, pricing internals and source references are excluded from this page. Missing charges are unknown, not free usage.
- Review recent activity and any truncation notice. Totals include the complete filter, even when only the latest 100 events are displayed. Ask your Topline contact for unresolved items and late corrections to be reconciled to their source evidence before using the results for a billing decision. A corrected record retains revision history, and retrying the same source event does not create another charge.
For example, a chat token total describes measured consumption. It does not on its own establish the amount owed. A missing SMS actual remains pending even if an operational segment estimate is available.
Tiers, daily allowances and recovery
Daily coding limits reset at 00:00 UTC. Usage shows the next reset in your local time. Settled coding charges count on the UTC day they reconcile; reserved or pending work continues to count until it settles or is released, even across midnight. A reset can therefore leave less than the full daily allowance available.
- Administrators with billing-management permission define named usage tiers, each with a daily coding allowance. They choose a default tier and assign a different tier to selected people. Choosing the default for a person restores inheritance. Editing a tier changes the allowance for its members; lowering it below usage already committed can block new work until reset.
- An administrator can grant an Unlimited user allowance override. It removes that person's tier daily allowance and administrator per-person monthly allowance restrictions. Organization access, monthly spending caps, paid-usage pause and concurrency limits still apply. It never authorizes unlimited organization spending or bypasses a member's own pause or tighter daily limit.
- Every member can set a tighter personal daily limit or pause their own new coding work. Clearing a personal limit restores the administrator's allowance; it does not raise that allowance or change organization settings. Personal pause remains in place until the member deliberately resumes.
- The organization's monthly spending cap, existing administrator limits and access controls still apply. A daily reset does not refill a depleted monthly organization budget. Billing remains the place for authorized administrators to manage the monthly organization budget and paid-usage policy.
Members see their effective tier, daily allowance, usage and next reset. Tier names and allowances are organization-defined; these controls do not create a subscription price, charge a card or change the organization's commercial plan. If no tier is assigned, existing organization controls remain authoritative.
When blocked, read the reason before retrying. For a personal daily limit, wait for the displayed reset or adjust your own restriction within the administrator's limits. For an administrator limit or a paused organization, contact your admin. For pending work, let the task settle or investigate its status. A missing coding plan requires administrator setup; saving a personal limit never creates a price or enables billing. Existing tasks still consume their authorized reservations. Starting a task requires enough remaining credits for its initial reservation. If the full tier allowance is smaller than that reservation, a daily reset will not help: an administrator must raise the tier allowance or change the assignment.
Daily spending controls currently apply to coding. The other meters provide visibility; a displayed quantity does not imply a configurable daily spending cap for chat, profiles or SMS.
Availability and billing decisions
To use metering for your organization, Topline must confirm that the required release and database changes are installed, source capture is healthy, and the requested period has sufficient coverage. A member without a stable attribution identity receives an explicit unavailable-attribution state rather than other people's activity. Organization totals can include unattributed background work. Viewing a report does not enable a feature, choose a price, or activate usage-based billing. Any billable feature still needs its existing enablement process and an approved commercial policy. Ask your Topline contact to review those options and the applicable price and effective date before activation; metering has no universal billing-on control.
A closed metering month freezes the reviewed measurement evidence. Invoice approval remains a separate process. Late usage or corrections stay visible for review and do not silently rewrite a closed invoice. Existing billing statements remain authoritative; metered copies must not be charged a second time.
Request capacity
Use Resources to review current database and application-cache capacity and submit a justified request. A request records desired capacity, reason, status, and history; it is not an immediate infrastructure mutation. Do not create a second request while an active request already represents the same change.
Manage brand
Use Brand to set the accessible workspace name and select or upload the logo and favicon. The existing or fallback brand remains authoritative until the new value saves. Brand images may come from Assets, but changing a shared setting does not prove a separately deployed customer runtime has received it.
Investigate activity
Search the Audit Log by actor, action, resource, outcome, and time range. Start narrow, open a bounded event, preserve relevant resource IDs, correlation IDs, and timestamps, and expand only as needed. Audit metadata is evidence of recorded Topline activity; it is not external-provider, deployment, billing-invoice, or customer-rollout proof and is not a place to copy secret payloads.
Security and tenant boundary
All administration is tenant-bound. A role does not automatically grant access to every resource, and a resource link does not bypass authorization. Use least privilege, short-lived integration grants, named credential ownership, and prompt offboarding.
Automation and MCP
External clients receive only their granted OAuth scopes and current tenant capabilities. Developer tokens and MCP grants are managed separately from member roles and should be revoked when no longer required. Automated changes must preserve the same review and audit boundaries as UI changes.
Errors and recovery
- Invite or grant fails: confirm the identity, tenant, capability, and resource scope.
- Credential consumer fails after rotation: restore the previous active version if safe, inspect the consumer reference, and repeat the smoke test.
- Billing unavailable: retry after the provider window and escalate without inferring usage.
- Coding task blocked by a limit: review settled and pending usage, then raise the applicable finite limit or wait for the next UTC billing month. Turning on paid usage without a positive paid limit does not create unlimited spend.
- Coding plan changed while saving: refresh Billing before changing limits again so the form uses Topline's current included allowance and price.
- Budget email does not arrive: confirm the recipient is still an active tenant administrator and selected in Billing. The on-page alert history is authoritative for whether the threshold was recorded; contact Topline if a recorded alert remains undelivered.
- Capacity request fails: keep the requested values and reason, refresh the current active request, and retry only if no equivalent request was accepted.
- Brand save fails: keep the existing brand and retry after asset, authorization, or storage health is corrected.
- Audit result missing: verify the time range, tenant, action spelling, and retention window.
- Unexpected access: remove the narrowest implicated grant first, preserve IDs and timestamps, and begin an authorized audit review.
Enablement, smoke check, and rollback
For access changes, test one intended and one prohibited action. For credential changes, test every named consumer before revocation. For brand changes, verify the account shell and public-brand endpoints without claiming customer-runtime rollout. For capacity, verify only the saved request and later authoritative status. Roll back by restoring the previous role, capability, scope, credential version, or brand value; do not weaken unrelated controls.
Limitations
Available billing fields, resource controls, retention, roles, and product capabilities depend on tenant configuration. Removing access does not delete historical audit records or outputs the member previously created. A capacity request, billing row, audit event, or saved brand value does not by itself prove an external or deployed-system change.