Users
Users is the Admin's delegation map: every employee, the Agents acting on their behalf and the Connections those Agents access. Drill into any employee for their full delegation scope.
Users is the Admin's lens on Agent delegation across the org: who has Agents set up, what those Agents access and how active each employee is. Each row drills into a detail page.
📖 Key concepts
employee: A person in the organization, synced from your HRIS or IdP or invited manually.
Delegation: An employee allowing one or more Agents to act on their behalf via the MCP Gateway.
Delegation scope: The total footprint of one employee's Agent activity: Agent count, Connections accessed, tool calls.
Sync vs manual: When HRIS/IdP sync is on, the sync is authoritative and Users are read-only here. When sync is off, Admins manage Users by hand.
💡 Why this matters: Employee attributes (department, title, location) already drive Policy conditions. The delegation map adds the second half: what each employee's Agents are doing.
📊 The Users table
Navigation: Users.
What you see: one row per employee.
Name + email, Department, Role and other HRIS attributes.
Agents: count of Agents acting on behalf of this employee.
Connections: icon stack of Connections accessed.
Sessions (30d): Agent session count.
Last active.
Actions: inviting, editing and removing Users requires HRIS/IdP sync to be off. When sync is on, your identity provider is the source of truth and these records are read-only here.
Invite user: creates a User record and sends the invite.
Edit: name, department, role, job title, team. These feed Policy conditions.
Remove: deletes the employee record.
🛠 User detail
Navigation: Users → click any row. The detail page opens on the Overview tab.
Overview
What you see: identity and HRIS attributes (department, team, job title, tenure); an activity summary (sessions, Agent count, Connections count, last active); and a delegation scope summary, for example
This User has delegated to 3 Agents accessing 5 Connections with 284 tool calls in the last 30 days.Why it matters: one line tells you whether this employee is a heavy delegator or a light user.
Connections
What you see: every Connection this employee holds credentials for, with Connection status (Active / Error / Paused / Not Connected), the Agents that use it, sessions (30d) and last active.
Actions:
Add connection access: create a User-Connection association manually.
Revoke connection: pull the credential. The employee keeps their underlying app access.
Remove connection access: delete the User-Connection record (house-cleaning).
Sessions
What you see: every session this employee delegated, across all Agents and Connections. The same nested pattern used elsewhere: Level 1 sessions, Level 2 tool calls, and a side panel with payloads and the Policies that fired.
Why it matters: the investigation surface for one employee's activity.
📋 Users at a glance
Users table
Users
One row per employee: Agents, Connections, sessions, last active. Invite, edit and remove (sync off only).
The delegation map across the org.
Overview
Users → row
Identity, HRIS attributes and the delegation scope summary.
Heavy delegator or light user, in one line.
Connections
Users → row → Connections
Per-Connection status and activity for this employee. Revoke or remove access.
Per-credential view for one employee.
Sessions
Users → row → Sessions
Every delegated session, drillable to tool calls and the Policies that fired.
Investigate one employee's activity.
🔗 Related pages
Last updated
Was this helpful?