> For the complete documentation index, see [llms.txt](https://docs.uptiq.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.uptiq.ai/control-center/admin/admin-faqs-and-troubleshooting.md).

# Admin: FAQs & Troubleshooting

Answers to common Admin questions, and fixes for sign-in, team, and API key issues.

This page answers common questions about users, sign-in, teams, roles, and API keys. Use the troubleshooting entries when someone can't sign in or a dialog doesn't behave as expected.

## FAQs

### Users and sign-in

<details>

<summary>Can people sign up for Qore themselves?</summary>

No. Access is invite-only, whichever sign-in method someone uses. An administrator creates the account by inviting the person from **Admin → Users**. The sign-in page mentions creating an account, but it can't create one. See [Users](/control-center/admin/users.md#create-or-edit-a-user).

</details>

<details>

<summary>Which sign-in methods can people use?</summary>

**Continue with Email** is always available, using the password from the invitation. **Continue with Google** and **Continue with Microsoft** are turned on per Qore deployment, so a sign-in page can show both, one, or neither. Which methods are on isn't set from Control Center. See [Single Sign-On](/control-center/admin/single-sign-on.md#which-buttons-appear).

</details>

<details>

<summary>Does Qore support multi-factor authentication?</summary>

Yes. When someone signs in with their organization's Microsoft Entra ID account, the organization's own Microsoft sign-in rules apply, including multi-factor authentication. Qore doesn't store their Microsoft password. See [Sign in with Microsoft](/control-center/admin/single-sign-on.md#sign-in-with-microsoft).

</details>

<details>

<summary>Does single sign-on give different access from a password?</summary>

No. What someone can do comes from their [roles](/control-center/admin/roles.md), however they sign in. Single sign-on proves who they are; the invitation decides whether they get in.

</details>

### Roles

<details>

<summary>Can one person hold more than one role?</summary>

Yes. A person can hold several roles in one account, and their capabilities add up. Select one or more roles when you [create or edit a user](/control-center/admin/users.md#create-or-edit-a-user).

</details>

<details>

<summary>Does a role in one account apply in another?</summary>

No. Roles are held per account membership, so a role in one account doesn't carry into another. **Organisation Admin**'s three tenant-level capabilities are the exception: they reach every account in the tenant. See [Roles](/control-center/admin/roles.md).

</details>

<details>

<summary>Who can manage users, teams, and API keys?</summary>

Only **Account Admin** and **Organisation Admin**. They carry **Create user**, **Manage user**, **Remove a user**, **Manage teams**, and **Manage API keys**. **Developer**, **Governance Manager**, and **Auditor** can view users, and **Governance Manager** can view teams. See [Capabilities by role](/control-center/admin/roles.md#capabilities-by-role).

</details>

<details>

<summary>Can I create a custom role or change what a role grants?</summary>

Your organization's policies manage roles at the tenant level, and only **Organisation Admin** carries **Manage organization roles**. Roles your organization creates appear under **Custom Roles** in **Admin → Roles**. To request a change, contact your Organisation Admin.

</details>

### Teams

<details>

<summary>What's the difference between a team role and an account role?</summary>

A **team role** (**Admin** or **Member**) applies only within one team. **Account roles** (Developer, Account Admin, and so on) are account-wide and govern everything else. You set both when you invite someone new from **Create Team**. See [Teams](/control-center/admin/teams.md#members).

</details>

<details>

<summary>What does a team give its members access to?</summary>

The agents and apps in the team's **Data Permissions**. You grant them in step 2 of **Create Team**, or later from the team's **Data Permissions** table. What each person can do with them still comes from their account-wide [roles](/control-center/admin/roles.md). See [Teams](/control-center/admin/teams.md).

</details>

<details>

<summary>What are a team's spaces?</summary>

The products the team can operate in: **Console**, **Control Center**, or both. Spaces are separate from the agent and app permissions you grant the team. See [Create a team](/control-center/admin/teams.md#create-a-team).

</details>

### API keys

<details>

<summary>Which permissions can an API key carry?</summary>

Any of the account's capabilities, the same set that roles carry. Grant the key only the ones it needs. See [Create an API key](/control-center/admin/api-keys.md#create-an-api-key).

</details>

<details>

<summary>Can I call an agent with the key from Admin → API Keys?</summary>

No. The platform key from **Admin → API Keys** is sent as `x-platform-key` and isn't accepted by agent runtime routes. To call an agent, use its **agent key** or **widget key** from the agent's Deploy tab. See [Integrate Agent](/console/agent-builder/deploy/agent-integration.md).

</details>

<details>

<summary>Do API keys expire?</summary>

No. None of the key types expire or support rotation today. To stop a platform key from being used, select **Revoke** in its **Actions** menu. See [Manage a key](/control-center/admin/api-keys.md#manage-a-key).

</details>

## Troubleshooting

### Sign-in

<details>

<summary>Someone gets a validation error when they try to sign in</summary>

Their email address hasn't been invited. Invite that exact address from **Admin → Users**, then ask them to try again. See [Access is invite-only](/control-center/admin/single-sign-on.md#access-is-invite-only).

</details>

<details>

<summary>Someone can't sign in with Google or Microsoft, even though they were invited</summary>

The address on their Google or Microsoft account must match the invited email exactly. A person invited as `jane.doe@example.com` can't sign in with Microsoft as `jdoe@example.com`, even if both reach the same mailbox. Invite the address their Google or Microsoft account actually uses.

</details>

<details>

<summary>The Continue with Google or Continue with Microsoft button is missing</summary>

Each single sign-on button is turned on per Qore deployment, and it isn't set from Control Center. When none is on, the sign-in page shows only **Continue with Email**. Ask your Qore administrator for the method you need.

</details>

<details>

<summary>The temporary password email hasn't arrived</summary>

Wait a few minutes, then check the spam or junk folder. A temporary password goes only to the invited email address shown on the confirmation. See [Reset a forgotten password](/control-center/admin/password-sign-in.md#reset-a-forgotten-password).

</details>

<details>

<summary>Someone who signs in with Google wants to reset their password</summary>

People who only ever sign in with Google don't have a Qore password to reset. They should use **Continue with Google**.

</details>

<details>

<summary>Update Password stays unavailable</summary>

Fill all three fields: **Current Password** (the temporary password), **New Password**, and **Confirm Password**. The button becomes available once all three are filled. See [Set your own password](/control-center/admin/password-sign-in.md#set-your-own-password).

</details>

### Teams

<details>

<summary>A new team's agent or app selections weren't saved</summary>

The selections are saved only when you finish both steps of **Create Team** and select **Create Team** in step 2. Open the team and add them from **Data Permissions**. See [Manage an existing team](/control-center/admin/teams.md#manage-an-existing-team).

</details>

<details>

<summary>Changes to a team's members or permissions didn't apply</summary>

Changes in a team's dialog apply only when you select **Save & close**. Open the team, make the changes again, and select **Save & close**.

</details>

### API keys

<details>

<summary>Create Key stays unavailable</summary>

Enter a **Key name** and select at least one permission. The button becomes available once both are set.

</details>

<details>

<summary>I didn't copy a new key before closing the dialog</summary>

A key is shown only once, when it's created, and can't be retrieved later. Create a new key and copy it before you select **Done**. You can revoke the key you lost from its **Actions** menu.

</details>

<details>

<summary>An agent runtime route rejects the key</summary>

Agent runtime routes don't accept the platform key (`x-platform-key`). Use the agent's **agent key** (`x-api-key` plus its secret) or **widget key** (`x-widget-key` plus a whitelisted domain) from its Deploy tab. See [Integrate Agent](/console/agent-builder/deploy/agent-integration.md).

</details>

### Roles

<details>

<summary>Someone can't stop or resume an agent</summary>

Only **Account Admin** and **Organisation Admin** can stop or resume agents. **Governance Manager** and **Auditor** can view agent controls but can't change them. See [Roles](/control-center/admin/roles.md).

</details>

<details>

<summary>Someone needs a capability their roles don't include</summary>

Capabilities add up across roles, so give them a role that includes it, as well as the roles they already hold. For example, **Approver** approves publishing but doesn't build, so an Approver who also needs to build agents needs the **Developer** role too. Check which roles carry a capability in [Capabilities by role](/control-center/admin/roles.md#capabilities-by-role). To change what a role grants, contact your Organisation Admin.

</details>

### Related

<table data-view="cards"><thead><tr><th>Title</th><th>Description</th><th data-card-target data-type="content-ref">Target</th></tr></thead><tbody><tr><td><strong>Users</strong></td><td>Invite people and assign their roles.</td><td><a href="/control-center/admin/users.md">Users</a></td></tr><tr><td><strong>Teams</strong></td><td>Group members and grant them agent and app access.</td><td><a href="/control-center/admin/teams.md">Teams</a></td></tr><tr><td><strong>Roles</strong></td><td>What each role can do.</td><td><a href="/control-center/admin/roles.md">Roles</a></td></tr><tr><td><strong>API Keys</strong></td><td>Create, copy, and revoke platform keys.</td><td><a href="/control-center/admin/api-keys.md">API Keys</a></td></tr></tbody></table>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.uptiq.ai/control-center/admin/admin-faqs-and-troubleshooting.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
