Platform / Governance administration
Set up governance
Connect your identity provider and AI platforms, decide how roles map into Telara, and choose what an agent may do without asking. Three screens, in that order.
Connect your AI stack
Starting screen: Governance → Connect. The order is deliberate — identity provider, then platforms, then the identity map — because each step gives the next one something to resolve against. The whole flow is re-runnable at any time; running it again does not undo what you connected before.
sk-admin-… created by an organisation owner; Anthropic wants an sk-ant-admin… from a member holding the admin role; Cursor wants a team-admin key plus the team identifier; the compliance exports are a different key class again from the ordinary API keys. Each connector page states its own requirement — read it before generating anything.Integration role mappings
Screen: Governance → Mappings. A role in one of your connected platforms maps to what the corresponding principal may do through Telara. A background worker applies these continuously rather than at setup time, which is what keeps them true as your IdP changes.
Freezing stops the role-mapper worker writing anything at all until you unfreeze. Reach for it when a mapping is producing the wrong result and you need the current state to stop moving while you work out why — it holds the ground rather than reverting anything. Existing grants stay as they are; they simply stop being recalculated.
What a mapped role gets when nothing more specific applies: high sensitivity only (the default — a human approves the consequential actions and the rest run) or always require HITL (a human approves everything). This is a floor, not a ceiling: a specific policy can still demand approval for something the default would let through.
For how an individual action is gated once a role is mapped, see Autonomy & gates.
Governance settings
Screen: Governance → Settings. Four groups, and the first is the one to check when something looks empty rather than wrong.
| Group | What it answers |
|---|---|
| Connector health | Whether each connected platform is still returning data. A dashboard that has gone quiet is usually a credential that expired or was rotated, not an estate that stopped using AI. |
| Identity provider & SCIM | Which IdP is connected and how people are being synced. |
| Roles & permissions | What each role may do, and the mappings that feed it. |
| Budgets & cost allocation | How spend is attributed and where limits sit. The methodology — usage, research, and committed floors — is explained in Governance data. |
Where the rest of governance lives
Budgets, people, teams, platforms, cost attribution and audit are all tabs of the Spend hub rather than separate pages — the older URLs redirect there. Spend, spend-vs-output, the waste inbox and reports each carry their own methodology notes in Governance data, and discovery of unmanaged AI is covered in Shadow AI.



