Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 15 additions & 0 deletions Knowledge-OpsCenter/Docusaurus-OpsCenter.md
Original file line number Diff line number Diff line change
Expand Up @@ -336,6 +336,21 @@ The organization-details view shows details about an org and lets you perform se

### Authentication logs

> **These are NOT audit or activity logs, and this section is what a question about "audit
> logs" wrongly retrieves.** Authentication logs cover **sign-in activity only**. They will
> not tell you who licensed a product, who changed a setting, or who did anything else
> operational. Ops Center has **no** activity/audit logs today; they are planned but not
> shipped. Audit/activity data lives in **Audit Center**, which is **OneTyler-staff-only**,
> so for everyone else the route is to file a request. There is no Tyler-wide audit/activity
> tool. See
> `FAQ-OpsCenter.md` -> *How do I access audit logs in Ops Center?* for the route.
>
> This warning is repeated here on purpose. Retrievers chunk independently of headings, so an
> agent answering "how do I see audit logs" retrieves *this* table rather than the FAQ entry
> that governs it — stating the rule only in the FAQ was measured as insufficient. Do not
> tidy it away as duplication. (Authored addition, not from Blueprint: re-add it if this file
> is re-derived.)

Available behavior differs sharply by tier:

| Aspect | Workforce Managed | Workforce Direct |
Expand Down
118 changes: 103 additions & 15 deletions Knowledge-OpsCenter/FAQ-OpsCenter.md
Original file line number Diff line number Diff line change
Expand Up @@ -100,9 +100,10 @@ Do not offer a workaround that implies a consolidated list exists.

### Q: I need to be an Org Admin / I need access to a customer's Admin Center — how do I get it?

**A:** **There are two different paths, and the right one depends on how often you need
access.** Present both; do not send someone down the manager's-guide route when a single
ticket would do.
**A:** **There are three paths, and the right one depends on how often you need access and on
whether you already hold the self-promotion permission.** Present the one that fits; do not
send someone down the manager's-guide route when a single ticket would do, and do not send
someone who *already* has self-promotion rights to raise anything at all.

**Occasional access to one customer's Admin Center** — use the **Client Admin Center access
request** ticket. **Give the user the Confluence page, not the raw form URL** — it carries the
Expand All @@ -117,27 +118,50 @@ it makes you an Org Admin for that one organization. Requirements: the org must
in Ops Center in that environment, and you must not already have access. Allow up to five
minutes after approval.

**Frequent access across many customers' Admin Centers** — follow the **Manager's Guide**:
*Tyler Cloud Platform (TCP) | Org Admin promotions (Admin Center access) - a Manager's guide*
(`/wiki/spaces/TTI/pages/386629479/`)
**Frequent access, and you ALREADY have self-promotion permission** — just do it yourself, in
product. No ticket. Ops Center -> **Organization Details -> Admins**, then
**+ Promote me as admin**. OneTyler grants this elevated *Promote / Remove yourself as Org
Admin* right to select Ops users whose roles require routine customer access, so a good number
of people asking this question can already self-serve and do not know it. **Check whether the
user has the permission before routing them anywhere** — if the menu action is there, that is
the whole answer.

Please also **remove your own Org Admin rights when you no longer need them**. Tyler-staff Org
Admins can self-remove from the same screen, and cleaning up is expected rather than optional.
Permission changes take a little time to propagate.

**Frequent access, and you do NOT yet have that permission** — this is the only case that
needs the **Manager's Guide**: *Tyler Cloud Platform (TCP) | Org Admin promotions (Admin Center
access) - a Manager's guide* (`/wiki/spaces/TTI/pages/386629479/`)

This exists so a team that routinely needs Admin Center access does not have to raise a
separate ticket per organization. It is a manager-driven workflow — the team's manager
delegates special permissions — and there is no single ticket URL for it.
It is a manager-driven workflow — the team's manager delegates the self-promotion permission —
and there is **no single ticket URL** for it. Prerequisites: the user already has Ops Center
access, and does not already have self-promotion rights. Once granted, they are in the case
above permanently and never need this route again.

Neither path uses the generic "Ops Center additional permissions" form (`4133`).
None of the three paths uses the generic "Ops Center additional permissions" form (`4133`).

**Why this entry exists:** asked as "need to add myself as an org admin for product add", the
team agent returned only the Manager's Guide. That answer is not wrong, but for a one-off
request it sends the user into a manager-approval process when ticket `4165` would have
settled it. The two routes are catalogued separately in
settled it. The routes are catalogued separately in
`Knowledge-Shared/Conf-OneTylerTickets.md`; what was missing everywhere was the rule for
choosing between them.

- **Source:** Vijay Venkataraman, reviewing transcript `team/2026-08-24--53d51e27`. Ticket
numbers and prerequisites cross-checked against `Knowledge-Shared/Conf-OneTylerTickets.md`
(*Client Admin Center access request*, and *Add an Org Admin, or self-promote as Org
Admin*).
**Why it says three paths and not two:** asked again as plain "how to add myself as an admin",
the agent described the ticket route and the Manager's Guide but presented the manager's guide
as the way to get access, when for someone who already holds the self-promotion permission the
answer is a single in-product action and no request at all. Collapsing "use the permission you
have" and "obtain the permission" into one branch is what made the answer incomplete. Treat
them as separate outcomes.

- **Source:** Vijay Venkataraman, reviewing transcript `team/2026-08-24--53d51e27`, and again
on `team/2026-09-08--4125fbd2` for the three-path split. Ticket numbers and prerequisites
cross-checked against `Knowledge-Shared/Conf-OneTylerTickets.md` (*Client Admin Center access
request*, and *Add an Org Admin, or self-promote as Org Admin*), and the in-product
self-promote screen against `Docusaurus-OpsCenter.md` -> *Organization Details - Admins*.
- **Added:** 2026-08-24, three-path split added 2026-09-09, by vijay-tylertech
- **Confidence:** confirmed by owner
- **Added:** 2026-08-25 by vijay-tylertech
- **Confidence:** confirmed by owner
- **Promote when:** the Confluence ticket page or the Manager's Guide itself states the
Expand Down Expand Up @@ -233,6 +257,70 @@ OneTyler, but quote system names exactly as they appear in that system.
- **Promote when:** also recorded in `Docusaurus-Terminology.md` under *OneTyler (formerly
CorpDev)*. Keep here only while the rename is still in flight.

### Q: How do I access audit logs in Ops Center? / Where do I see who licensed a product for a workspace?

**A:** **Ops Center does not have audit logs today. It has *authentication* logs, and they are
a different thing.** This is the trap in the question: searching for "audit logs" lands on the
**Authentication logs** section, which looks like an answer and is not one. Say the distinction
out loud before describing either.

| | **Authentication logs** | **Activity / audit logs** |
|---|---|---|
| In Ops Center today? | **Yes** | **No** |
| What they cover | User **sign-in** activity | Operational **actions** — who licensed a product, who changed a setting |
| How to get them | Ops Center -> **Organizations** -> select the org -> **Organization Details** -> *Authentication logs*. Behaviour differs sharply by Identity Workforce tier — see the comparison table in `Docusaurus-OpsCenter.md` -> *Authentication logs*. | **Not in Ops Center at all.** Held in **Audit Center**, which is OneTyler-staff-only. Everyone else files a request: use the Confluence ticket page -> *Other non-product assistance with Organizations and Workspaces*: <https://tylertech.atlassian.net/wiki/spaces/TTI/pages/386600308/Tyler+Cloud+Platform+TCP+Ops+Center+Related+Tickets+and+Permissions> — state the activity you need. |

**Authentication logs will not answer "who licensed this product".** They track logins, not
operational changes. Do not offer them as a substitute; that is the specific way this question
gets answered wrongly.

**There is no Tyler-wide audit/activity tool at all.** Authentication logs in Ops Center are
the **only** log surface available across Tyler. Audit and activity data does exist, in
**Audit Center** — but Audit Center is a **OneTyler-staff-only** tool, so it is not an answer
you can hand to a general Tyler audience. That restriction is precisely *why* the route for
everyone else is to file a request: the request is how you reach data held in a tool you
cannot open yourself. Never tell a user to "check the audit logs" without establishing that
they are OneTyler staff.

**Activity logs in Ops Center are planned, not shipped.** Ops Center is expected to gain
Activity logs against a **product in the Product Registry** and against an **organization**.
Describe this as coming, never as available, and do not promise a date.

**What to do about "who licensed a product for a workspace" in the meantime:**

1. **File the request** above — that is the supported route for anyone who is not OneTyler
staff, and it is the right first answer in almost every case.
2. **Ops telemetry (AWS QuickSight)** gives you licensing *counts and current state*, not
attribution. It will tell you a product **is** licensed, never **who** licensed it. Path:
<https://sso.tylertech.com/app/UserHome> -> **Tyler Cloud Insights Center** -> **TCP Prod
Stats** dashboard. See `Docusaurus-OpsCenter.md` -> *Ops telemetry (AWS QuickSight)*.
3. **Ask the OneTyler team** for a specific attribution question that cannot wait.
4. **If the user is OneTyler staff**, the answer is in **Audit Center**, which records the
acting user against product-licensing events. Do not offer this branch otherwise.

Also worth separating: **licensing is org-level, availability is workspace-level** (see
`Docusaurus-OpsCenter.md` -> *Product licensing (organization) and availability (workspace)*).
A question phrased "licensed a product **for a workspace**" is usually really about
availability/activation on that workspace, so check which one the user means before answering.

- **Source:** Vijay Venkataraman, reviewing transcript `team/2026-09-04--f4fc1c8a` — the team
agent answered "how do i access audit logs in ops center" with the authentication-logs
material, which is the wrong log type, and did not mention that activity data requires a
ticket today. The Audit Center scoping is his correction on 2026-09-09: "TCP Audit log
currently only exists in Audit Center that is only for OneTyler staff. There is no Tyler
wide tool that gives Audit/Activity logs excepting Authentication logs which is available
in Ops Center."
- **Note:** `Knowledge-BP-General/Docusaurus-OpsApps.md` owns Audit Center and its upstream
Blueprint page is a **stub**, so that file cannot currently say who Audit Center is for.
This entry is the only place that restriction is written down.
- **Added:** 2026-09-09 by vijay-tylertech
- **Confidence:** confirmed by owner
- **Promote when:** Activity logs ship in Ops Center and Blueprint documents them — at which
point this entry needs rewriting, not just re-confirming, and the "planned" wording must go.
**Vijay Venkataraman will flag when that lands** (confirmed 2026-09-09: expected soon, no
date available). Until he does, do not go looking for a ship date and do not soften the
"not shipped" wording — the absence of a date is the known state, not missing research.

---

## Notes for the chatbot
Expand Down
16 changes: 10 additions & 6 deletions Knowledge-OpsCenter/_START_HERE.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ Domain: Ops Center (Tyler Cloud Platform — operational tooling, organization/w

| File | One-liner — what's in it |
|---|---|
| `FAQ-OpsCenter.md` | **Authored answers with no upstream source** — verbal SME guidance, observed behaviour, corrections upstream owners have not yet made. Currently: how to disambiguate the word "client"; that there is **no** consolidated list of Admin Center instances you can access; choosing between the two Admin Center access paths (ticket `4165` for occasional, Manager's Guide for frequent); and the OneTyler / CorpDev rename. Check here when no `Conf-`/`Docusaurus-` file answers the question. |
| `FAQ-OpsCenter.md` | **Authored answers with no upstream source** — verbal SME guidance, observed behaviour, corrections upstream owners have not yet made. Currently: how to disambiguate the word "client"; that there is **no** consolidated list of Admin Center instances you can access; choosing between the **three** Admin Center access paths (ticket `4165` for occasional, in-product **+ Promote me as admin** if you already hold self-promotion rights, Manager's Guide to obtain those rights); that Ops Center has **authentication** logs but **no audit/activity logs**, and how to get activity data and product-licensing attribution; how to add an org email domain; renaming/deleting a workspace; and the OneTyler / CorpDev rename. Check here when no `Conf-`/`Docusaurus-` file answers the question. |
| `Conf-CRMCustomerIdentifiers.md` | The deep technical/operational reference for the **CRM Customer Identifier** (= the Ops Center Org Key). Generation algorithm, portability across CRM merges, usage across TCP / Tyler Deploy / TID-W / SaaS / Twilio, troubleshooting tree, exact ticket subjects. |
| `Conf-GatewayOperationalTesting.md` | How to validate a **Gateway-ready product** against the real-world test org `tylertownwa`. Test account emails (**password NOT in this corpus** — points to the source Confluence page), 4 Gateway integration components, Core vs Full compliance, Tyler Deploy addendum, net-new-customer routing rules. |
| `Conf-AddingExternalUsersToEntraId.md` | The **Workforce Direct-only** workaround for adding non-employee users (temps, contractors) to a customer's Entra ID **without consuming an Office 365 license**. Tyler-staff coaching material — NOT to share with customers directly. |
Expand Down Expand Up @@ -51,19 +51,23 @@ The Ops Center Foundry agent surfaces four starting prompts to new users. The ca
1. **"How do I get access to Ops Center?"** — *Starting prompts → How do I get access to Ops Center?*; deeper: `Docusaurus-OpsCenter.md` → *Access — environment URLs*, *Access — request a ticket*, *Access — promote teammates*; `Knowledge-Shared/Conf-OneTylerTickets.md` → *Basic Access* for the exact Notes-field wording on shared form 4133.
2. **"How can I get access to a client's Admin Center?"** / **"I need to add myself as an org
admin"** — start with `FAQ-OpsCenter.md` → *I need to be an Org Admin / I need access to a
customer's Admin Center*, which gives the rule for choosing between the two paths and is
the thing most often got wrong. Then *Starting prompts → How can I get access…*; deeper:
customer's Admin Center*, which gives the rule for choosing between the **three** paths and
is the thing most often got wrong. Then *Starting prompts → How can I get access…*; deeper:
`Knowledge-Shared/Conf-OneTylerTickets.md` → *Client Admin Center access request* (form
4165) for the standard path, and `Docusaurus-OpsCenter.md` → *Organization Details —
4165) for the occasional path, and `Docusaurus-OpsCenter.md` → *Organization Details —
Admins* + the *Org Admin promotions — a Manager's guide* Confluence page for the
elevated-permission self-promote alternative. **Always present both**, sized to how often
the user needs access.
elevated-permission self-promote route. **Size the answer to how often the user needs
access, and check first whether they already hold self-promotion rights** — if they do, the
answer is one in-product action (**+ Promote me as admin**) and no request at all. Sending
someone who already has the permission to the Manager's Guide, or sending a one-off request
there instead of to form 4165, are the two observed failures.
3. **"Where can I see the Identity Configuration details for a customer?"** — *Starting prompts → Where can I see the Identity Configuration…*; deeper: `Docusaurus-OpsCenter.md` → *Organization Details* (Basic details for Identity Tier; Manage workspaces for per-workspace OnPrem Target), *Identity Workforce (org details)* for tier-specific federation/AD-Agent setup, and *Authentication logs* for sign-in history. Always flag that Identity Tier cannot be changed after org creation (the narrow UNINITIATED WD→WM conversion ticket is the only exception).
4. **"Where can I see Ops Center training and other useful guides?"** — *Starting prompts → Where can I see Ops Center training…*. **Primary URL — must be surfaced verbatim, never paraphrased:** https://tylertech.atlassian.net/wiki/spaces/TTI/pages/386599613/Tyler+Cloud+Platform+TCP+Deployment — the Tyler Cloud Platform Deployment / Operational Training Hub on Confluence, which hosts the 6-part video series, the slide deck, and the handout PDF. Deeper: `Misc-Links.md` → *TCP / TID Operational Training* for the same URL plus the individual demo/setup Confluence pages; `Training-OpsCenterOperations.md` → *Resources* table also carries the URL; `Training-OpsCenterOperations.md` and `Training-WorkforceManagedToDirectMigration.md` for the GPT-distilled training narratives.

### "How do I file a ticket / what's the right ticket for X?"
- `Knowledge-Shared/Conf-OneTylerTickets.md` (start here always)
- **Critical disambiguation:** "Add an Org Admin / Promote me as admin" does NOT use the generic form 4133 — see *Org Admins* section in that file.
- **Critical disambiguation:** **"audit logs" vs "authentication logs".** Ops Center has only the latter, and they cover sign-ins — never operational actions like who licensed a product. **Authentication logs are the only Tyler-wide log surface**; audit/activity data lives in **Audit Center**, which is **OneTyler-staff-only**, so for everyone else the answer is to file a request. A question about audit/activity logs goes to `FAQ-OpsCenter.md` → *How do I access audit logs in Ops Center?*, which carries the ticket route, the Audit Center scoping and the QuickSight caveat. Answering it from `Docusaurus-OpsCenter.md` → *Authentication logs* is the known wrong answer.

### "What does this Tyler term mean?"
- `Docusaurus-Terminology.md` (authoritative glossary)
Expand Down
Loading
Loading