Keep agents, owners, providers, data context, access, lifecycle, risk, and evidence in one accountable inventory.
Let people use approved agents in chat and projects while identity, DLP, connector, memory, and file policies remain attached.
Review health, security events, usage, cost allocation, access decisions, audit history, and platform state from the same system.
Deploy Docker-based services inside the cloud, datacenter, region, network, and storage boundary selected by the customer.
Scope managed hosting, isolation, availability, backup, support, and offline requirements during solution design instead of assuming one topology.
Use platform health and deployment validation to inspect schemas, migrations, extensions, indexes, and other required runtime state.
Build from containerized services and apply the customer's own TLS, networking, storage, monitoring, backup, and recovery controls around them.
Export and restore supported platform configuration, providers, knowledge, policy, and operational settings with validation and clear dependency handling.
Pristan supplies application and deployment building blocks. Final high-availability, edge protection, data residency, and offline behavior depend on the agreed environment and connected providers.
Map where catalog records, conversations, files, secrets, telemetry, backups, and provider calls live. Then validate those controls against the selected deployment rather than relying on generic infrastructure claims.
Bring ownership, provider setup, access, capabilities, safety, health, cost, review, and retirement decisions into one repeatable administrative flow.
Create and review agent identity, provider operations, access mode, knowledge, artifacts, skills, memory, DLP, health, and cost metadata.
Bind agents to typed provider connection operations and validated invocation templates instead of hiding runtime behavior in unstructured endpoints.
Back up and restore supported configuration and platform data with encryption options, validation, and explicit handling for secrets and dependencies.
When Platform AI is configured, query catalog and operational metadata or run typed administrative actions without bypassing caller permissions or audit policy.
Centralize reusable configuration and secret references, then bind them into provider and integration settings without revealing values in normal administrative views.
Review administrative changes, access events, security signals, connector activity, and operational events with searchable and exportable context where exposed.
Connect identity providers, directories, groups, roles, feature policy, per-agent access, temporary elevation, and periodic review without flattening everything into one administrator role.
Organize users into groups, define granular permission roles, and keep administrative domains such as agents, identity, security, integrations, and observability explicit.
Configure password, OAuth/OIDC, SAML, MFA, SSO-only, session, and conditional-access behavior according to the providers and policies enabled for the deployment.
Grant access through users and groups, keep public/restricted/private modes explicit, and route requests or just-in-time access through review workflows.
Control access to My Files, Projects, memory, search, mobile clients, and related features for targeted users or groups.
Connect configured directories, issue SCIM provisioning tokens, and use bulk import jobs for controlled user and group lifecycle operations.
Review requests, active grants, exceptions, and recertification campaigns with accountable reviewers and recorded decisions.
Give teams productive chat, files, projects, knowledge, connectors, skills, artifacts, and memory without detaching those experiences from policy and evidence.
Stream responses, attach allowed files, inspect citations, rate answers, and manage conversation history while DLP, usage, audit, and optional memory run through configured policy.
Create project descriptions, shared files, project conversations, and collaborator permissions. Copy eligible personal chats into projects without carrying private resources across the boundary.
Manage personal files, project files, knowledge bases, embeddings, vector storage, and retrieval context with processing state, access, and citations where configured.
Install reviewed connector versions, assign approved operations to agents, expose effective sources in chat, and support encrypted per-user credentials where a connector declares them.
Assign validated portable skills, create Markdown artifacts, and enable managed audio dictation only for the agents, users, and providers approved for those capabilities.
When memory is enabled, let users review, edit, import, export, resolve, or forget global and agent-specific memories within administrator-defined retention and management policy.
Extend Pristan through supported channel integrations, webhooks, API keys, invocation contracts, and MCP connections while keeping scopes, approvals, and audit history explicit.
Configure workspace or tenant credentials, default agents, channel or user mappings, and access rules for supported collaboration-channel workflows.
Send selected platform events to signed webhook destinations or map events into configured ticketing connections with tests, delivery history, retries, and explicit activation.
Use scoped API keys, documented REST contracts, typed invocation templates, and approval-aware MCP service tokens for external clients and automation.
Pristan keeps connector installation governance separate from the account a person uses at runtime. Shared service credentials are an explicit choice; user-owned credentials remain scoped to that user when the connector supports them.
Use platform dashboards and exports to connect operational signals to agents, providers, users, groups, and projects. Exact coverage depends on the configured provider and telemetry paths.
Review platform metrics and usage trends, then create or import custom dashboards with supported widgets, data sources, and saved layouts.
Track provider usage and estimated cost by agent, user, group, and time range. Use cost-allocation views, budgets where configured, and exports for chargeback or showback work.
Review agent, provider, vector, schema, migration, extension, index, and enum health through dedicated operational surfaces.
Configure supported alert conditions, severity, cooldown, destination, and digest behavior for health, usage, cost, DLP, risk, and other monitored events.
Use OpenTelemetry, Prometheus, client telemetry, logs, traces, SLOs, incidents, synthetics, RUM, and release-correlation paths where they are configured for the deployment.
Review DLP and prompt-injection trends, alert activity, connector events, and the platform-wide event log with time and entity filters.
Register a representative set of agents, owners, provider connections, users, groups, and access decisions.
Test chat, projects, files, knowledge, connectors, DLP, and identity controls that match the capabilities you plan to enable.
Inspect health, security events, audit history, usage, cost allocation, and the operational gaps that still need design.