Documentation
Administrator Guide
How operators run Tiresias-ZT day to day: deploying the proxy, managing tenants and agents, authoring policy, and responding to SoulWatch detections — all from the admin portal.
The complete guides for the current release are published at admin.tiresias.network, user.tiresias.network, and quickstart.tiresias.network. Administer your deployment from the admin portal.
Covered in the full guide
The rewritten guide for the current release covers:
- Deploying the self-hosted proxy in front of your backend
- RBAC hierarchy: Platform → MSSP → Tenant → Agent
- OIDC single sign-on configuration
- Authoring deny-by-default policies (monitor-first rollout supported)
- SoulWatch anomaly review and quarantine actions
- Enabling and operating server-side encrypted transcript retention (crypto-shred erasure)
- Usage metering, budgets, and the cost governor
- Exporting and verifying the tamper-evident audit trail
Admin portal
Administration happens in the hosted portal at cp.tiresias.network (Google OIDC sign-in). Design partners receive onboarding and the current admin runbook directly from the team.