The Platform area is where Shokoofa's own staff run the service: customer tenants, people's accounts, platform roles, extensions and support sessions. It is shown only to people who hold a platform role.
Who sees what
Each platform page opens only with the matching permission, which comes from your platform role:
- Tenants (
tenants:read): list and open tenants. Provisioning, suspension, apps and deletion each need their own permission. - People (
accounts:read): search accounts and open one. Editing, sign-in emails and ending sessions needaccounts:manage; disabling an account needsaccounts:disable. - Platform roles (
platform-roles:assign): held by platform owners. - Extensions (
extensions:manage): the extension registry. - Support sessions (
support:session): the support sessions you asked for.
What each platform role allows is listed on Roles and what they allow.
Your second factor
Your organisation may require every platform page and action to use a sign-in confirmed with your second factor (a one-time code from an authenticator app); where it is optional, the note at the top of the platform pages says so, and a second factor is still recommended. If you have not set one up, do it first on . When a page asks you to confirm, a dialog explains why; you confirm on the Shokoofa sign-in page and return to the same page.
Your own account
Nobody changes their own account or their own platform role from the platform pages. Change your own details in My account; ask another platform owner to change your roles.
Extensions
Tenants install extensions only from the registry. Register the publisher first and verify it once you have checked who it is. Then register the extension with its first version's manifest: its surfaces, the permissions it needs (written as app/permission) and the data it keeps. An extension is installable once it is listed:
- a first-party extension is built by Shokoofa;
- an approved listing needs a passed security review and a signed data-processing agreement;
- a verified listing needs a verified publisher.
Each tenant's install policy decides which listings it accepts. When a new version needs more permissions, tenants that installed the extension are asked to consent again.
Support sessions
A support session gives you time-limited access to a tenant's apps, or to one person's own Peyk and Avand data, for a support ticket. Start one from the tenant's or the person's page with the ticket number, a reason and the hours you need. It starts only when the tenant (as its support-access setting says) or the person approves it, and write access is approved separately. End a session as soon as you are done; it also ends by itself.
Where changes go
Accounts, groups and roles live in the Shokoofa identity service; the platform pages read them live and write every change back there. Console keeps only its own records (tenant lifecycle, entitlements, settings, deletion requests, role expiry) and the audit log, where every change and every refused attempt is recorded with its reason.