Skip to main content

Governance

Governance is how X4RGE stays accountable — every sensitive change has a record of who did it, what changed, and when. It also controls who can change plans on the platform and how support may access your organization for debugging.

Organization admins care about the audit log in the dashboard (members, budgets, models). Platform operators use Governance in the Console for contracts, provisioning, and cross-customer oversight. Most customers never open Console — but this page explains what happens behind your org settings and what you can verify yourself.

What this page is for

You are…This page helps you…
Org adminFind your audit log and know what is tracked inside your org
Org adminUnderstand support access and plan changes you did not make
Security / complianceSee what events exist for reviews and tickets
Platform operatorRun monthly checks, support sessions, and incident follow-up
Dashboard vs Console

Your org audit log lives in the dashboard — membership, budgets, models, integrations. Console Governance is for X4RGE operators managing plans and clients across organizations. You will not see operator contract entries in your org log.

Why governance matters

Without governanceWith governance
Plan changes with no paper trailContract updates recorded with actor and reason
Unclear who can change capacityPlatform roles scoped to owner, admin, support
Support access is opaqueTime-bound support sessions, audited
"Who changed our budget?"Org audit log for customer admins

Governance is enforced on the server — permissions are checked before any change applies, not only in the UI.

How governance protects your org

Think of three guarantees:

GuaranteeWhat it means for you
Separation of dutiesCustomer admins run the org; platform operators set plan entitlement — roles do not mix by accident
Audit trailSensitive changes leave a record you or support can review
Bounded support accessWhen X4RGE helps debug your org, access is time-bound and logged — not open-ended

Your Usage ceiling comes from Contracts & capacity. Your admin choices (Members, Model control, budgets) stay inside that ceiling and appear in your audit log.

In practice

Pick the row that matches your role and goal.

You are…You want to…Do this
Org adminSee who changed members or budgetsDashboard audit log
Org adminProve compliance for security reviewExport or filter org audit events
OperatorReview contract changes this monthConsole Governance → audit
OperatorHelp a customer debug cloud runsOpen a support session (audited, time-bound)
OperatorOnboard a new platform teammateAssign the right platform role only
OperatorInvestigate wrong allowanceAudit + Contracts

Two layers of access

X4RGE separates platform access (X4RGE staff) from organization access (your team):

LayerWhoWhat they manage
Platform rolesX4RGE staff / internal platform teamClients, contracts, cross-customer audit, support sessions
Organization rolesCustomer admins and membersOne org — Members, Usage, Model control

Customer org admins never get Console access from org roles alone. Platform support may view client context but typically cannot change contract capacity without elevated operator access.

For customer admins

If Included allowance on Usage looks wrong, you cannot fix it in the dashboard — contact your operator or Help & support. Your org audit log will still show your team's policy changes.

What gets audited

Sensitive actions are recorded with who, what, and when. Not every click is logged — focus is on policy, access, contracts, and agent operations that affect spend or security.

CategoryExamples
Contracts & capacityPlan changes, allowance updates, limit adjustments
Platform accessPlatform user role changes
Org policyBudget, model catalog, membership (org audit in dashboard)
Agents & automationAutomation created, run cancelled, webhook processed
ProvisioningCustomer org created, people added

Cloud and automation activity also feeds operational views such as Sentinel for the last 24 hours — useful when correlating a customer report with recent agent events.

For organization admins

Your org audit log (dashboard, admin-only) is the main governance tool you use day to day. It covers changes inside your organization only:

  • Invites, role changes, and removals
  • Budget and model policy updates
  • Integration and settings changes
  • Ownership transfers
When something changed unexpectedly

Filter the audit log by date and actor before re-applying policy — often the answer is another admin's change, not a platform bug.

What you will not see in your org log: platform contract updates, provisioning, or other customers' activity. If entitlement (plan allowance) changed, operators record that separately — open a ticket with Help & support and your org name if Usage does not match your agreement.

Pair with Members, Usage, and Model control for the settings those audit entries refer to.

For platform operators

These workflows are for Console users managing the platform — not typical customer admins.

Monthly governance check

  1. Review recent audit events

    In Console Governance, scan the last 30 days — especially contract and capacity changes.

  2. Match changes to approvals

    Each capacity update should tie to a renewal, ticket, or approved change request.

  3. Refresh platform roster

    Remove platform roles from departed staff; align support access with on-call rotation.

  4. Spot-check enterprise orgs

    Sample active customers — confirm Contracts match signed agreements.

When something looks wrong

If allowance or access changed unexpectedly:

  1. Find the audit event

    Note who made the change, when, and the recorded reason.

  2. Correct if needed

    Apply a fix in Contracts & capacity with a clear revert reason.

  3. Notify the customer

    Tell their admin if Usage was affected; ask them to refresh Usage.

  4. Review access

    Confirm the actor still needs platform admin privileges.

Support sessions

When a customer needs live help (for example cloud runs failing setup), operators can open a support session tied to their organization.

For customer admins: you may be asked to approve or be notified when support investigates. Sessions are time-bound and audited — used for incidents, not routine configuration you handle in the dashboard.

After the incident, use cloud agent setup and dashboard settings for ongoing changes — not repeated support sessions.

Note

Org admins can further restrict models and spend within entitlement; they cannot exceed Contracts & capacity set in Console.

Questions about governance?

QuestionAnswer
Who changed our budget or models?Dashboard audit log (org admin)
Why did Included allowance change?Platform operator / contract — contact Help
Did support access our org?Support sessions are audited; ask support for timing if needed
Can we export audit events?Org admins: dashboard audit; operators: Console export (see hidden ops docs)
Where do agent runs appear?Org audit + Sentinel for recent activity