get started

Companies, users and roles

Every customer is a company. Machines belong to the company whose install link enrolled them; users belong to one or more companies; every request is filtered by company on the hub, and anything out of scope answers as if it did not exist.

Roles

rolewhocan
superadminthe platform ownercreate, rename and disable companies; set plan limits (BE AI on or off, auto-run, runs per day); rotate enrollment tokens; move machines between companies; create other superadmins; see everything
company admina customer's own IT-minded person, or youmanage that company's users (operators and other company admins), issue temporary passwords, rotate keys and the install link, edit the notes BE AI reads, set the nightly schedule, see usage; never sees another company
operatortechnicianswork the machines of the companies they are assigned to: investigate, approve, push checks and releases

Creating a company

Superadmin only. Companies → new company. It gets an enrollment token and an install link on the spot. Give the link to whoever installs the agents. Then create at least one user for it.

Creating users

From the company page or from Users. Pick a username (email addresses are a good choice, since usernames are unique across the platform), a role, and the companies. A temporary password is shown once; the person must change it at first sign-in. An API key is issued at the same time for scripts.

Moving a machine to another company

Superadmin: on the company page, choose the machine and the destination. The hub re-homes the machine and closes its connection. The machine then has the wrong enrollment token, so run the new company's install line on it with the apply option; it reconnects under the new company with its history intact. Until then it shows offline. A machine cannot be claimed by another company's token on its own; that refusal is the stolen-identity protection working.

Rotating the install link and the token

Rotate install link (company admin or superadmin): the old link stops working immediately; enrolled machines are unaffected. Rotate enrollment token (superadmin): every machine of that company must be re-pointed with the new link before its next reconnect, or it drops. The new token is shown once.

Disabling a company

Its people cannot sign in and every request of theirs is refused; BE AI stops for it; its agents keep reporting so re-enabling is seamless.

Company scope

Superadmins and users with several companies see a company switcher in the top strip. It scopes every view: fleet, alerts, approvals, runs, events, audit and updates.

Try it on one machine first.

The install line takes a minute. Uninstall the agent and you are out.