This console is scoped to your tenant only. You cannot see or affect other tenants. Everything you do here writes to your tenant's audit ledger, which ProjexCloud platform staff (and your own auditors) can verify.
Why: Show your finance team what the tenant is spending in near real-time, plus a historical invoice archive.
sdk-meter.WARN header is being
stamped on responses. Talk to your ProjexCloud rep about raising the cap or moving to a higher plan.Why: Add and manage humans (and service accounts) inside your tenant. A persona is the assignable identity; a role maps the persona to a set of permissions; a BU (business unit) lets you group personas for billing and approvals.
human — invite by email; they'll receive a sign-in link.service — generates a service-account persona; pair with an API key.cost-center, region).Why: Long-lived credentials for machine-to-machine integrations (your CI pipeline, a custom integration, an analytics ETL).
service persona).tenant.admin scope.Why: ProjexCloud pushes events (invoice finalized, persona created, ticket status changed, etc.) to URLs you control.
If your endpoint goes down, failed deliveries land in your DLQ.
Why: Some actions in your tenant (export-all, BYOK rotation, deleting an audit-relevant record) need a second pair of eyes. The Approvals page is your queue + history.
Why: Wire your tenant into Slack, Salesforce, Microsoft 365, Google Workspace, Jira, Linear, Zendesk, Zoom, HubSpot, GitHub, Snowflake — whichever ones are part of your plan.
Why: GDPR/CCPA-style receipts. Every data-processing purpose for which ProjexCloud holds personal data on a subject must have an explicit, dated consent receipt; subjects (your end users) can revoke at any time.
Why: ProjexCloud's AI gateway routes LLM calls through approved providers. This page is where you register your tenant's MCP (Model Context Protocol) servers — typically your own data sources you want the AI to be able to read.
sdk-vault).localhost from your laptop won't work — agents run in ProjexCloud's network and need a reachable URL.Why: Customers with strict crypto controls insist on holding their own KMS keys; ProjexCloud encrypts your tenant's data with envelope keys wrapped by your KMS, so we can never read it without you.
Encrypt + Decrypt + GenerateDataKey permissions on that key (provider-specific console steps shown inline).When your tenant is freshly provisioned, do these in order:
The gateway can't reach your tenant's pool, or your JWT's tenant_id doesn't match what the URL expects. Check the URL has your tenant_id. If you've been issued the wrong tenant_id, contact your ProjexCloud rep.
Token expired or was revoked upstream. Click Reconnect.