Platform roles are held by Shokoofa's own staff: owner, operator, support, security and billing. What each allows is on Roles and what they allow. Platform owners manage them on Platform → Platform roles.
Who holds a role
The page reads the current holders of each role live from the identity service and joins them with Console's records: who assigned the role, when, when it expires and when it was last recertified.
Assigning a role
Choose Assign role, find the person by name or email and choose the role:
- platform.owner never expires;
- every other platform role is held for at most 90 days (you choose 1 to 90) and must then be recertified.
Platform staff hold no role inside customer tenants, so a person who is a member of a tenant must leave it first. Nobody assigns a role to themselves, and every platform owner is notified of each assignment. Your organisation may require two-step sign-in for every platform role; where it is optional, these pages say so, and two-step sign-in is still recommended.
Recertification
Recertifying confirms that the person still needs the role and starts a new period of up to 90 days. Assignments that expire within 14 days are marked Recertification due; turn on Only roles due for recertification to see just those. A role that is not recertified in time is removed automatically. Nobody recertifies their own role.
Removing a role
Removing takes the role away in every app at once and needs a reason. Some roles must keep a minimum number of holders (for example at least one owner); such a removal is refused until someone else holds the role. Nobody removes their own role.
Holders not recorded by Console
A holder marked Not recorded got the role outside Console, for example directly in the identity service. Such a role has no expiry and is never recertified. Choose Record to bring it under the rules: Console starts tracking it with an expiry like any role assigned here. To take it away instead, choose Remove: you give a reason, and the role is removed in the identity service and audited like any other removal. A role that must keep a minimum number of holders (the last platform owner) is never removed; assign it to someone else first.