Skip to main content
Telara

Platform / Governance administration

Set up governance

Connect your identity provider and AI platforms, decide how roles map into Telara, and choose what an agent may do without asking. Three screens, in that order.

Admin
Setup

Connect your AI stack

Starting screen: Governance → Connect. The order is deliberate — identity provider, then platforms, then the identity map — because each step gives the next one something to resolve against. The whole flow is re-runnable at any time; running it again does not undo what you connected before.

1
Connect the identity provider
Microsoft Entra ID or Google Workspace, with a SCIM endpoint. This is where your existing organisational structure comes from. Telara does not replace your IdP — it inherits from it, so the people and teams you already maintain become the starting point for policy rather than a second directory to keep in sync.
2
Connect the AI platforms
Each platform asks for a credential so Telara can read its usage. Filter by category to find the ones you run.
3
Build the identity map
Reconciles the people from your IdP against the accounts seen on each platform, so spend and activity attribute to a person rather than an anonymous key.
The class of key matters more than the key. Each platform names which class it needs — an organisation admin key, a service account, or a personal key — and they are not interchangeable. A personal key where an org admin key is required is the single most common failed setup: it authenticates fine and then returns nothing, or returns only that one person's usage, which looks like an empty estate rather than a wrong credential. OpenAI wants an sk-admin-… created by an organisation owner; Anthropic wants an sk-ant-admin… from a member holding the admin role; Cursor wants a team-admin key plus the team identifier; the compliance exports are a different key class again from the ordinary API keys. Each connector page states its own requirement — read it before generating anything.

Integration role mappings

Screen: Governance → Mappings. A role in one of your connected platforms maps to what the corresponding principal may do through Telara. A background worker applies these continuously rather than at setup time, which is what keeps them true as your IdP changes.

The freeze switch

Freezing stops the role-mapper worker writing anything at all until you unfreeze. Reach for it when a mapping is producing the wrong result and you need the current state to stop moving while you work out why — it holds the ground rather than reverting anything. Existing grants stay as they are; they simply stop being recalculated.

Default HITL policy

What a mapped role gets when nothing more specific applies: high sensitivity only (the default — a human approves the consequential actions and the rest run) or always require HITL (a human approves everything). This is a floor, not a ceiling: a specific policy can still demand approval for something the default would let through.

For how an individual action is gated once a role is mapped, see Autonomy & gates.

Governance settings

Screen: Governance → Settings. Four groups, and the first is the one to check when something looks empty rather than wrong.

GroupWhat it answers
Connector healthWhether each connected platform is still returning data. A dashboard that has gone quiet is usually a credential that expired or was rotated, not an estate that stopped using AI.
Identity provider & SCIMWhich IdP is connected and how people are being synced.
Roles & permissionsWhat each role may do, and the mappings that feed it.
Budgets & cost allocationHow spend is attributed and where limits sit. The methodology — usage, research, and committed floors — is explained in Governance data.

Where the rest of governance lives

Budgets, people, teams, platforms, cost attribution and audit are all tabs of the Spend hub rather than separate pages — the older URLs redirect there. Spend, spend-vs-output, the waste inbox and reports each carry their own methodology notes in Governance data, and discovery of unmanaged AI is covered in Shadow AI.