Admin is the console behind the org: 2,485 licensed seats against 1,677 assigned, 396 sitting idle, and $14K a month of waste broken down by idle, over-tier and ghost — per pack, with reclaim evidence one click away.
The sharpest alert on the Overview is structural, not technical: an org-owner still signing in with a password only. The console notices, because that is what it is for.
admin.cedxsystems.com — live build
Runs on demo data. Northline Production in the captures is the software's demo workspace, not a customer.
1,677 of 2,485 seats assigned67% utilisation, on the header
$14K a month of seat wasteidle, over-tier and ghost, itemised per pack
27 principals with high driftprivilege scored against role, top score 95
What it is
Three jobs an org console has to do with numbers.
Seat waste, priced per pack
The Seats screen is a waste radar: 396 idle seats, $14K a month in waste, and the packs ranked by a waste score — the platform suite leads at 82 with 14 idle, 6 over-tier and 3 ghost seats at $1.1K a month. Even the AI packs are counted: $718 of waste across 91 AI seats.
Idle, over-tier and ghost broken out per pack
Reclaim simulator and scoring model are tabs on the screen
8 packs cross the high-waste line (score ≥55)
admin — screen-3
36 roles, sensitivity labelled
The role table separates system from tenant-defined: 36 templates, 21 custom, each with permission count, member count and a sensitivity label. The two orphan roles — zero members, one of them a legacy admin with 40 permissions marked Critical — are exactly what a role audit goes looking for.
System and custom roles filterable in one click
Perms, members and sensitivity on every row
Org owner: 48 permissions, 3 members, Critical
admin — screen-4
Users, with seat and MFA in one row
The Users table joins the two facts admins usually chase across two tools: what seat someone holds and whether MFA is on. 130 privileged accounts at 87% MFA coverage means 17 are not covered — and the idle-30d card counts 255 accounts with 19 of those without MFA either.
Role, seat tier, MFA flag and last active per row
Active · Invited · Suspended · Deprovisioned chips
Roles from Help desk to Org owner, seats Member to Enterprise
admin — screen-2
Product tour
Four screens, captured from the running build.
Not a mockup and not a concept deck. This is what opens at /app/admin.
admin.cedxsystems.com
01 — Overview
Estate health with the alerts root-caused
Seat utilisation reads 67%, and the alert list says what to do about it: 14 idle Enterprise seats older than 45 days at $1.1K a month and rising; a service account holding Enterprise write with no traffic in 90 days; a partner sandbox at 18 of 25 seats with invites still open.
Directory, seats, drift, waste and MFA on one header row
Privilege drift leaderboard, service accounts first
24 workspaces, 4 flagged near seat cap
02 — Users
Who holds what, and whether it is safe
320 identities with department, status, role, seat, MFA and last active on the row. The gap between 87% MFA on privileged accounts and 100% is not a report request — it is a filter away.
130 privileged accounts, MFA coverage on the card
Idle 30d+ counted at 255 with MFA status attached
Search by user or email, CSV on the view
03 — Seats
Where the licence money goes
2,485 licensed, 1,677 assigned, and the waste radar beneath priced pack by pack — viewer pool with 28 idle, project packs with 16 idle and 5 ghost. Waste $ is a column, not a quarterly estimate.
396 idle seats of the 2,485 licensed
Ghost seats counted separately from idle
AI packs have their own tab — 14 of them
04 — Roles
Templates, customs and the orphans
Thirty-six roles with permission and member counts, sensitivity from Low to Critical. Orphan roles — the ones nobody holds — are counted on the header, because a Critical role with zero members is still a key under the mat.
36 templates, 13 privileged (high + critical)
21 tenant-defined custom roles
New role is a button, not a ticket
Who runs it
Three roles run the org from here.
Roles, not references. We have no named customers yet, so nobody in these photographs is quoted, credited or claimed as one.
IT administration
Owns the seat ledger. The 396 idle seats and the reclaim simulator are their monthly number, argued from the same table finance sees.
idle seats · 396
Security
Owns the drift board: 27 high-drift principals, the org-owner on password-only sign-in, and the service accounts holding write access with no traffic.
high drift · 27
Workspace owners
Own the 24 workspaces and the seat caps — 4 of them near the limit with invites still open, which the Overview flags before the invite fails.
workspaces · 24
The shape of it
What the demo workspace actually looks like.
Every figure below is legible in the captures above. Nothing here is a projection of your estate — it is the state of the demo data, dollars included.
2,485licensed seats1,677 assigned · 67% util
$14Kseat waste per monthidle + over-tier + ghost
36role templates13 privileged · 2 orphan
87%MFA on privileged accounts130 accounts in scope
Waste per pack, priced on screenidle · over-tier · ghost — monthly
Finding this out on the third call is worse for you than reading it here, and worse for us.
Admin is not generally available. What opens today is the live build running on demo data — Northline Production in the captures is the software's demo workspace, not a customer.
We have no named customers to show you, so this page shows none. The people named inside the demo captures are fictional rows in demo data.
The dollar figures — $14K a month of seat waste, $1.1K on the platform pack — are computed from the demo tenant's licence file. They are not prices, yours or ours; nothing on this page is a price list.
The waste radar scores packs against a visible model. We are not claiming the reclaim simulator's projections survive contact with your procurement process.
No audit or compliance certification has been issued for Admin. What we can evidence about hosting, encryption and access is on the security page.
Yes. Every screenshot is a capture of the running build and you can open the same build at /app/admin. It runs on demo data, which the page says next to the figures rather than in a footnote.
How is seat waste calculated?
Three buckets, visible on the Seats screen: idle (no activity), over-tier (a bigger seat than the role needs) and ghost (invites never accepted). Each pack shows all three counts with a dollar figure and a waste score — the scoring model is a tab on the same screen.
What is privilege drift?
The distance between what a principal can do and what their role says they should. The Overview leaderboards it — service accounts with elevated write and no traffic score highest, 95 and 84 in the demo data — so the fix is scoped to a role, not a suspicion.
Can we create our own roles?
Yes — 21 of the 36 roles in the demo tenant are custom, and New role is a button on the table. Every role carries a permission count, member count and sensitivity label so a custom Critical role is visible as such.
Does this replace our identity admin console?
Admin is the org console for the CEDX estate — seats, roles, workspaces. Identity is where sign-in policy and MFA live. How the two map onto your existing stack is the estate map conversation.
Is Admin audited or certified?
No certification has been issued. What we can evidence about hosting, encryption, tenant isolation and production access is written up on the security page.
The console is running. Go and look at it.
Live build, demo data, no card. Then count the idle Enterprise seats in your own org — if you can.