Managing AIPSO
Once your Platform & Security Officer has been set up, day-to-day management happens in the Platform & Security Officer section of the admin console, not the setup wizard. This article covers the Overview and Settings pages.
Overview Page
Navigate to Governance > AIPSO in the admin nav to reach /governance/aipso. The Overview page shows:
- Status -
active,paused,terminated, orconfigured - Autonomy Dial - the current autonomy level and a short description of what it permits (read-only here; change it from Settings)
- Next Review - the next scheduled wake-up time, and when AIPSO last ran
- Managers - the active IT admin managers, with the primary manager flagged
If your tenant has the AIPSO entitlement but hasn't run the setup wizard yet, this page shows a Set up AIPSO prompt instead.
Lifecycle Actions
Managers (users with the aipso:manage permission) see an Actions panel with:
- Pause / Resume - pausing stops AIPSO from waking up on its schedule until you resume it; in-flight work is not interrupted. A confirmation dialog explains this before pausing.
- Run Review Now - triggers an immediate review run outside the normal schedule.
- Terminate - permanently stops AIPSO. This cannot be undone from the console, and requires confirmation.
These actions are hidden once AIPSO is terminated (aside from viewing status).
Settings Page
From the Overview page, click Settings (or navigate to /governance/aipso/settings) to reach the management controls.
Autonomy Dial
Select one of the five autonomy levels:
| Level | Behavior |
|---|---|
| Investigate Only | AIPSO can look into issues and report findings, but has no ability to make changes |
| Approve Every Change | Every change, regardless of risk, waits for a manager to approve it |
| Auto-Approve Low Risk | Low-risk changes execute automatically; medium and high-risk changes wait for approval |
| Auto-Approve Low & Medium Risk | Only high-risk changes wait for manager approval |
| Full Autonomy | AIPSO acts independently across all risk levels |
Changing the dial shows a confirmation dialog stating exactly what the new level permits before it is saved. Every change is audit-logged.
Managers
The Managers panel lists all active managers and lets you:
- Add a manager - select any eligible
platform-adminfrom the dropdown and click Add manager - Set primary - promote a non-primary manager to primary
- Remove a manager - remove an active manager (audit-logged)
AIPSO must always have at least one active manager. The Remove control is disabled when only one manager remains, and the server enforces the same rule even if bypassed on the client.
Monitored Mailbox
The Monitored Mailbox card manages AIPSO's own email inbox - the shared mailbox your managers use to reach AIPSO by email (see the Overview). It shows the currently bound mailbox and its email subscription health, and lets you:
- Assign or change the mailbox - pick an existing monitored mailbox, or link/create one through the shared mailbox modal. If the mailbox is already assigned to another active agent, you must confirm the reassignment first.
- Unassign the mailbox - AIPSO stops receiving email until you assign a mailbox again.
Managers can email AIPSO's mailbox once one is bound; mail from anyone who is not a manager is ignored. AIPSO reads inbound email today but does not yet reply conversationally.
Tools
The Tools card manages the catalog tools AIPSO has been granted (for example, web search, HTTP, or SQL tools). Use it to grant or revoke tools from your general tool catalog at any time. AIPSO's built-in capabilities are always available and are not listed here.
Both the Monitored Mailbox card and the Tools card are hidden once AIPSO is terminated.
Lifecycle
The same Pause / Resume / Terminate controls available on the Overview page are also available here.
Permissions
aipso:view- lets a user see the Overview and Settings pages in read-only mode.aipso:manage- required to change the autonomy dial, manage the manager roster, or use lifecycle actions. Users withoutaipso:managesee a notice explaining that settings changes require this permission.
Related Topics
- AIPSO Overview - Introduction to the Platform & Security Officer
- AIPSO Setup Wizard - Step-by-step guide to initial configuration