System Admin
System Admin is for members with admin permissions. Use it to maintain organization members, system usage, cost limits, and sandbox resources, so that your team uses Agents with controlled permissions, usage, and runtime environments.
Intended for: Super Admins and Agent admins. This page covers organization-level administration. For member and shared capability settings within a workspace, see Create Space.
Search keywords: System settings, System Admin, Agent Members, admin permissions, System Usage, Cost Control, quotas, sandbox management, shared sandboxes.
What System Admin solves
When your team starts using Agents, you can decide here which members can use them, understand where usage comes from, set usage limits, and maintain the execution environments of personal or shared spaces.
- Enable and manage members: Add Agent members and adjust their enabled status, admin role, and user quota rules.
- Analyze usage: View model consumption and tool calls, and pinpoint the users, models, or products that need attention.
- Control usage: Set company quotas and user quota rules, and view the balance, usage progress, and users at limit.
- Keep the runtime environment healthy: Maintain sandbox availability, shared space resources, and sandbox tools.
How to get there: In the Platform Products area of the workbench sidebar, select System Admin. In Agent System Admin, select Agent Members, System Usage, Cost Control, or Sandboxes based on your goal. If you don't see the entry or get a no-permission message, contact a Super Admin or an Agent admin to check your account permissions.
Permission boundaries: Being a space Owner doesn't automatically grant System Admin permissions. Likewise, permission to manage shared space resources in System Admin doesn't automatically grant access to the content of that space. To enter a shared space, you still need to be a member, and the space must be available.
Model configuration is maintained centrally in Models, and messaging channel integration is maintained centrally in Channel Management.
Manage Agent members
Go to Agent Members to search for members and filter them by enabled or disabled status. The list shows each member's allowed models, quota and period, amount used in the period, and status.
Add members
- Click Add from AE and select the company members who need Agent access from the available members.
- Select Bind Limit Rule as needed. This step is optional. If you haven't created any rules yet, go to Cost Control to add one first.
- To set up a personal runtime environment at the same time, select Create sandbox for members. If the remaining quota is insufficient, you can't submit with this option selected.
- Click Batch add, check the operation results, and then confirm that the member status, limit rules, and sandboxes are as expected.
If you see a partial success message, the members may have been added, but the limit rule binding or sandbox setup may not be complete. Check what succeeded first, and then fix each failed item separately. Don't treat the whole operation as a complete failure and add the members again.
Maintain status, roles, and usage
Enable or disable: Use the member status toggle. Disabling requires confirmation, and once disabled, the member can't use the Agent system. When you need to pause a member's access, first assess whether disabling is enough to meet your goal.
Change the admin role: In the member's more actions, select Set as Admin or Revoke Admin. Super Admins can't be disabled, removed, or have their role changed on this page. After you revoke your own admin role, the page refreshes and checks your permissions again.
Modify Limit Rule: Click the member's Edit Quota Rule action and select a rule for the member. The quota, period, and allowed models of each rule are maintained centrally in Cost Control.
View member usage: Click Usage Details to view the tokens, conversations, Agent tool calls, trends, and recent conversation records in the selected date range. Agent tool calls include both MCP and CLI calls, so don't treat this number as the number of MCP calls.
Remove Member: In more actions, select Remove Member and confirm. Removing a member means they can no longer access the system; it doesn't remove the member from a particular workspace. If you only need to adjust space members, follow the space member and permission instructions in Create Space.
Query system usage
Usage queries help you understand how your team actually uses the system. Go to System Usage and choose a view based on the question you want to answer.
| View | Questions it answers | Key actions |
|---|---|---|
| Overview | How much is consumed overall? Is the trend changing? Which models are used most? | Select a date range and view metrics such as cost, tokens, requests, active users, and tool calls. Click a top model to go to the LLM usage view and locate that model. |
| LLM usage | Which users, models, or products does the consumption come from? | Group by user, model, product, or date; search, sort, and drill down. Export the current view, the current drilldown, or the full details as CSV as needed. |
| Agent tool calls | Who calls MCP or CLI, and how do the calls succeed or fail? | Select MCP or CLI, view trends, summaries, and individual call details by call source and optional summary dimensions, and export them as CSV. |
Align dates before comparing. Overview and LLM usage each keep their own date range. After you locate a model from Overview, also check the date of the current usage view. A custom date takes effect only after you confirm it, and the range limits are as shown on the page.
Distinguish load failures from zero usage. A —, unavailable cost, or failed tool call loading doesn't mean actual consumption is zero. If a refresh fails, the page may keep showing the last successfully loaded data, so check the update time and retry.
Follow up from the analysis. After you locate a user, you can go from the usage drilldown to that user's cost control rule. To adjust model configuration, see Models.
Set up cost control
System Usage shows what happened, while Cost Control sets the quotas and models that can be used. Go to Cost Control, review the account balance, company usage, rules, and users at limit first, and then choose the limits you need to adjust.
Company quota and user quota rules
Company Quota: Company members share one monthly quota pool. Click Add Company Quota or edit the existing company quota, choose an amount limit or a token limit, enter the monthly quota, and save.
User Rules: Define usage rules assigned to users. When adding or editing a rule, enter a rule name, choose daily, weekly, or monthly and the limit type, set the quota and allowed models, and assign users. Users bound to the rule are restricted by it.
When you use a token limit, you can set a total token quota and add limits for models as needed. Without model limits, usage is restricted only by the total token pool. A model limit must be a positive number and can't exceed the total quota. When entering an amount or tokens, pay attention to the currency and unit shown on the page.
Allowed models and quotas are different limits. Making a model unavailable may make Agents bound to that model unusable. After you turn on New models available by default, you no longer select model availability one by one. Before making changes, check the affected members and their Agents.
After saving, check that the rule is enabled and users are assigned correctly. When a user reaches a limit, check their rule period, used quota, and the company quota before deciding whether to adjust the rule, change the assignment, or wait for the next period. A user who hasn't reached their own quota isn't guaranteed that the company quota is still available. Also confirm the scope of impact before you disable or delete a rule.
Account balance and alerts
View the current account balance, and turn on Balance Alert and set a positive alert amount as needed. When the balance falls below that amount, the system shows an alert on the Cost Control page and in the user sidebar. Turning off the alert clears the alert amount you set.
The balance alert is a reminder about funds. It doesn't replace the company quota or user quota rules, and it doesn't top up your account automatically.
Manage sandboxes and shared space resources
A sandbox environment provides an isolated execution space for tasks such as running script files in Skills. Go to Sandboxes to view sandbox usage and switch between Personal Sandbox, Shared Sandbox, Sandbox Tools, and Distribution History. If the feature isn't enabled, the Sandboxes entry may not appear.
Personal sandboxes
In Personal Sandbox, search for the target user or sandbox, and check the bound user, availability, container status, and last access time. To create one, click Create Personal Sandbox, select a user, and enter a description if needed. You can also use Batch Create to create sandboxes for multiple users.
Check the remaining quota before creating or enabling sandboxes. Users who already have a personal sandbox don't need another one. After a batch operation, check the result for each target and handle any failures.
Distinguish availability from running status: The availability toggle controls whether the sandbox can be used, while start and stop control whether the sandbox is currently running. Being available doesn't mean it's running, and stopping isn't the same as deleting. When the status is switching, wait for the result and then refresh to confirm.
Admins can start, stop, edit, or delete personal sandboxes using the actions available on the page, or select multiple sandboxes to process them in batch. Before stopping a sandbox, make sure no important tasks are running. Before deleting one, confirm the impact and what needs to be kept. Don't use deletion as a regular restart.
Users who want to view their own resources, working directory, and terminal can go directly to My Sandbox.
Shared sandboxes
Shared Sandbox shows shared spaces and their dedicated sandboxes. When creating a shared space, select a space Owner and fill in the space information. After submitting, check the current stage and status, and wait for initialization and checks to complete. A successful submission doesn't mean the space is available yet. If creation fails, check the error message first, and don't keep resubmitting the same creation request.
Maintain availability: Disabling a shared sandbox also stops it and prevents space members from continuing to run tasks. Re-enabling restores only availability and doesn't mean the sandbox has started, so you still need to check its running status.
Transfer Owner: Select a new space Owner and confirm. The new Owner joins the space, and the original Owner remains a space member. Admins with resource management permissions can transfer the Owner within their permissions even if they aren't members of the space, but entering the space still requires membership, and the space must be available.
Delete a shared space: Deleting a shared space also deletes its shared sandbox. This can't be undone and affects all members' existing conversations. If you only need to pause it temporarily or change the owner, don't delete the space.
For space creation information, members, and shared capability settings, see Create Space. This page covers only organization-level resource maintenance.
Sandbox tools and distribution history
In Sandbox Tools, view preset and custom tools. As needed, refresh the tool list, maintain custom tools, or distribute, deactivate, or refresh the status of selected tools. Before distributing, confirm the target sandbox scope. All Running Sandboxes isn't limited by the search, filters, or pagination of the current list, and sandboxes that aren't running are skipped.
After you submit a distribution or deactivation, go to Distribution History to view the targets and the succeeded, failed, and skipped results. If some targets fail, retry only the ones that need it. If the status is uncertain, refresh the actual status first so that you don't treat an unknown result as not executed.
Deactivating a tool's managed entry doesn't uninstall every command with the same name, and other versions with the same name that already exist in the environment may still be used. To check which tools a user can actually use, ask the user to check in My Sandbox.
FAQ and next steps
| Problem | What to check first |
|---|---|
| Can't see Agent System Admin, or get a no-permission message | Confirm that the current account has Super Admin or Agent admin permissions. Being a space Owner or having admin permissions on another platform doesn't substitute for this. |
| Member added but still can't run tasks | Check whether the member is enabled, whether the add result had partial failures, whether the personal sandbox or current shared space is available, and the model and quota limits. |
| Personal usage below the limit but still restricted | Check the company quota, user rule period, and allowed models together, not just the personal usage progress. |
| Sandbox shows as available, but tasks can't start | Also check the running status, bindings, and creation stage. If the space and sandbox bindings don't match, find the cause first instead of deleting and recreating them. |
| Usage is empty, shows —, or fails to refresh | Check the date, filters, update time, and error messages. Missing data or data that failed to load can't be treated as zero usage. |
Continue reading based on your current goal, without going back to the main table of contents first:
- Manage only the members and shared capabilities of a space: Create Space.
- View personal sandbox status, working directory, and terminal: My Sandbox.
- Maintain model resources, default models, and availability: Models.
- Configure messaging platform integrations such as Feishu and Slack: Channel Management.
- Complete personal messaging account authorization and binding: Channel overview and binding.
Parent section: Platform and Settings. You can continue reading from the related pages above.

