The administration surface
Where administration happens — one screen with a scope tree on the left and, for the scope you select, everything you can manage about it on the right.
Managing scopes and organizations
Create sub-scopes, and decide the one thing that matters most when you do — whether the new scope starts its own organization or joins its parent's.
Granting access
The access matrix — a grid of who holds which role at a scope, that tells you not just what access exists but why, and lets you grant and revoke with a click.
Managing users
See the people visible at a scope, bring in someone new by declaring them before their first sign-in, and keep their profile tidy.
Identity providers
Let a scope's people sign in through your own identity provider — register it, understand the three values that must match an incoming token, and change it safely later.
Credentials
Store the keys, tokens, and passwords iontos uses to reach protected external services on your behalf — entered once, referenced by many resources, and never shown back.
LLM configuration
Choose the language models a scope uses — define a model, bind it to a credential, and route each task to it — in three small layers that keep model choice, cost, and secrets cleanly apart.