A systems administrator at dual monitors covered in sticky notes, a server rack through the doorway and coffee rings on the desk.

CEDX Admin · Platform

Seats, roles, drift —
accounted for, in dollars.

Admin is the console behind the org: 2,485 licensed seats against 1,677 assigned, 396 sitting idle, and $14K a month of waste broken down by idle, over-tier and ghost — per pack, with reclaim evidence one click away.

The sharpest alert on the Overview is structural, not technical: an org-owner still signing in with a password only. The console notices, because that is what it is for.

admin.cedxsystems.com — live build
CEDX Admin overview: directory, paid seats, seat waste in dollars, privilege drift, estate health and root-caused alerts.

Runs on demo data. Northline Production in the captures is the software's demo workspace, not a customer.

1,677 of 2,485 seats assigned67% utilisation, on the header
$14K a month of seat wasteidle, over-tier and ghost, itemised per pack
27 principals with high driftprivilege scored against role, top score 95

What it is

Three jobs an org console has to do with numbers.

Seat waste, priced per pack

The Seats screen is a waste radar: 396 idle seats, $14K a month in waste, and the packs ranked by a waste score — the platform suite leads at 82 with 14 idle, 6 over-tier and 3 ghost seats at $1.1K a month. Even the AI packs are counted: $718 of waste across 91 AI seats.

  • Idle, over-tier and ghost broken out per pack
  • Reclaim simulator and scoring model are tabs on the screen
  • 8 packs cross the high-waste line (score ≥55)
admin — screen-3
Seat waste, priced per pack

36 roles, sensitivity labelled

The role table separates system from tenant-defined: 36 templates, 21 custom, each with permission count, member count and a sensitivity label. The two orphan roles — zero members, one of them a legacy admin with 40 permissions marked Critical — are exactly what a role audit goes looking for.

  • System and custom roles filterable in one click
  • Perms, members and sensitivity on every row
  • Org owner: 48 permissions, 3 members, Critical
admin — screen-4
36 roles, sensitivity labelled

Users, with seat and MFA in one row

The Users table joins the two facts admins usually chase across two tools: what seat someone holds and whether MFA is on. 130 privileged accounts at 87% MFA coverage means 17 are not covered — and the idle-30d card counts 255 accounts with 19 of those without MFA either.

  • Role, seat tier, MFA flag and last active per row
  • Active · Invited · Suspended · Deprovisioned chips
  • Roles from Help desk to Org owner, seats Member to Enterprise
admin — screen-2
Users, with seat and MFA in one row

Product tour

Four screens, captured from the running build.

Not a mockup and not a concept deck. This is what opens at /app/admin.

admin.cedxsystems.com
CEDX Admin Overview screen.CEDX Admin Users screen.CEDX Admin Seats screen.CEDX Admin Roles screen.

01 — Overview

Estate health with the alerts root-caused

Seat utilisation reads 67%, and the alert list says what to do about it: 14 idle Enterprise seats older than 45 days at $1.1K a month and rising; a service account holding Enterprise write with no traffic in 90 days; a partner sandbox at 18 of 25 seats with invites still open.

  • Directory, seats, drift, waste and MFA on one header row
  • Privilege drift leaderboard, service accounts first
  • 24 workspaces, 4 flagged near seat cap

02 — Users

Who holds what, and whether it is safe

320 identities with department, status, role, seat, MFA and last active on the row. The gap between 87% MFA on privileged accounts and 100% is not a report request — it is a filter away.

  • 130 privileged accounts, MFA coverage on the card
  • Idle 30d+ counted at 255 with MFA status attached
  • Search by user or email, CSV on the view

03 — Seats

Where the licence money goes

2,485 licensed, 1,677 assigned, and the waste radar beneath priced pack by pack — viewer pool with 28 idle, project packs with 16 idle and 5 ghost. Waste $ is a column, not a quarterly estimate.

  • 396 idle seats of the 2,485 licensed
  • Ghost seats counted separately from idle
  • AI packs have their own tab — 14 of them

04 — Roles

Templates, customs and the orphans

Thirty-six roles with permission and member counts, sensitivity from Low to Critical. Orphan roles — the ones nobody holds — are counted on the header, because a Critical role with zero members is still a key under the mat.

  • 36 templates, 13 privileged (high + critical)
  • 21 tenant-defined custom roles
  • New role is a button, not a ticket

Who runs it

Three roles run the org from here.

Roles, not references. We have no named customers yet, so nobody in these photographs is quoted, credited or claimed as one.

IT administration

Owns the seat ledger. The 396 idle seats and the reclaim simulator are their monthly number, argued from the same table finance sees.

idle seats · 396

Security

Owns the drift board: 27 high-drift principals, the org-owner on password-only sign-in, and the service accounts holding write access with no traffic.

high drift · 27

Workspace owners

Own the 24 workspaces and the seat caps — 4 of them near the limit with invites still open, which the Overview flags before the invite fails.

workspaces · 24

The shape of it

What the demo workspace actually looks like.

Every figure below is legible in the captures above. Nothing here is a projection of your estate — it is the state of the demo data, dollars included.

2,485licensed seats1,677 assigned · 67% util
$14Kseat waste per monthidle + over-tier + ghost
36role templates13 privileged · 2 orphan
87%MFA on privileged accounts130 accounts in scope
Waste per pack, priced on screenidle · over-tier · ghost — monthly
  • Platform suite · Enterprise — 14 idle, 6 over-tier, 3 ghost$1.1K
  • Projects · Enterprise — 16 idle, 1 over-tier, 5 ghost$984
  • Projects · Enterprise — 9 idle, 3 over-tier, 6 ghost$734
  • CRM · Pro — 9 idle, 4 over-tier, 2 ghost$480
  • Desk · Member — 11 idle, 2 over-tier, 1 ghost$380
Seat utilisation1,677 assigned of 2,485 licensed
  • Assigned · 1,677 seats
  • Unassigned or idle — 396 idle on the radar
AI seat waste$718 of 91 AI seats, idle + over-tier + ghost
$718
  • Wasted AI seats · $718 a month
  • AI packs tracked separately · 14 packs

How it runs

An org's admin loop, in the order it actually happens.

01

Assign

A seat is granted with a role and a workspace — one of the 1,677 assigned, with the pack and tier recorded from day one.

02

Measure

Utilisation and drift are computed continuously: 67% seat util, 27 high-drift principals, MFA coverage on the privileged set.

03

Alert

Anomalies arrive root-caused — idle Enterprise seats at 45+ days, an org-owner without MFA, a sandbox near its cap.

04

Reclaim

The reclaim simulator turns the waste radar into an action list, pack by pack, before the next true-up.

One record

The org settings every
other product inherits.

Admin is where the org itself is configured — the seats, roles and workspaces the rest of the estate bills against and enforces.

All 132 applications

Limits

What Admin does not do yet.

Finding this out on the third call is worse for you than reading it here, and worse for us.

Start

Open it before you talk to anyone.

Try

Open it right now

  • The live build
  • Demo data
  • No card, no call
Open live Admin

Pilot

Your seats, your roles

  • Everything in Try
  • Licence-import plan
  • Role-cleanup workshop
  • Estate map
Talk to sales

Estate

Admin with the rest of it

  • Admin with Identity, Directory and Audit
  • One org, one bill
  • CEDX delivery
Book an estate map

Questions

Before you pilot Admin.

Is the software on this page real?

Yes. Every screenshot is a capture of the running build and you can open the same build at /app/admin. It runs on demo data, which the page says next to the figures rather than in a footnote.

How is seat waste calculated?

Three buckets, visible on the Seats screen: idle (no activity), over-tier (a bigger seat than the role needs) and ghost (invites never accepted). Each pack shows all three counts with a dollar figure and a waste score — the scoring model is a tab on the same screen.

What is privilege drift?

The distance between what a principal can do and what their role says they should. The Overview leaderboards it — service accounts with elevated write and no traffic score highest, 95 and 84 in the demo data — so the fix is scoped to a role, not a suspicion.

Can we create our own roles?

Yes — 21 of the 36 roles in the demo tenant are custom, and New role is a button on the table. Every role carries a permission count, member count and sensitivity label so a custom Critical role is visible as such.

Does this replace our identity admin console?

Admin is the org console for the CEDX estate — seats, roles, workspaces. Identity is where sign-in policy and MFA live. How the two map onto your existing stack is the estate map conversation.

Is Admin audited or certified?

No certification has been issued. What we can evidence about hosting, encryption, tenant isolation and production access is written up on the security page.

The console is running. Go and look at it.

Live build, demo data, no card. Then count the idle Enterprise seats in your own org — if you can.