# uip admin

> Manage UiPath organization- and tenant-level admin resources with the `uip admin` tool — users, groups, robot accounts, external apps, SMTP settings, authorization, IP restriction, organizations, tenants, VPN gateways, resource catalog, and audit events.

`uip admin` manages UiPath's organization- and tenant-level administrative resources. The tool ships as the `@uipath/admin-tool` package, but is itself assembled from 7 separately-published sub-packages (`identity-commands`, `authz-commands`, `apms-tool`, `oms-commands`, `admin-vpngateway-commands`, `resourcecatalog-tool`, `audit-commands`) — each registers its own commands directly onto the shared `admin` top-level command, with no further nesting except where noted below. The real invocation is always `uip admin <verb>` (or `uip admin integrations vpn <verb>` for the VPN gateway group specifically).

## This resource spans eleven pages

- **This page** — concepts and the shared conventions across every admin resource.
- [`users`, `groups`](./uip-admin-users.md) — directory users and groups.
- [`robot-accounts`, `pat`, `scopes`](./uip-admin-robot-accounts.md) — non-human identities and personal access tokens.
- [`external-apps`](./uip-admin-external-apps.md) — OAuth external application registrations, including federated credentials.
- [`smtp`](./uip-admin-smtp.md) — organization SMTP relay settings.
- [`authorization`](./uip-admin-authorization.md) — custom roles, role assignments, the permission catalog, and effective-access checks.
- [`ip-restriction`](./uip-admin-ip-restriction.md) — IP-range allowlisting, enforcement, and bypass rules.
- [`organizations`, `tenants`](./uip-admin-organizations-tenants.md) — the caller's organization record and tenant lifecycle.
- [`integrations vpn`](./uip-admin-vpn.md) — VPN gateways and their connections.
- [`rcs`](./uip-admin-rcs.md) — Resource Catalog Service entity search and tenant tags.
- [`audit`](./uip-admin-audit.md) — organization- and tenant-scoped audit trail.

## Concepts

- **One tool, seven packages.** Each sub-package owns a distinct admin domain and is versioned/published independently, but they all attach their commands to the same `admin` Command object at CLI startup — from the command line there is no visible seam between them. If a verb behaves unexpectedly, the sibling page for that specific domain is the source of truth, not this overview.
- **Distinct from Orchestrator's own admin surfaces.** `uip admin audit` is a separate, org/tenant-scoped audit trail from Orchestrator's own [`uip or audit-logs`](./uip-or-audit-logs.md) (folder-scoped robot/process activity). `uip admin organizations`/`tenants` manage the organization and tenant records themselves, distinct from [`uip platform`](./uip-platform.md)'s license allocation against those same tenants.
- **`--organization` is deprecated on the identity-derived groups** (`users`, `groups`, `robot-accounts`, `external-apps`) — it's accepted for backward compatibility, warns, and has no effect; the organization is always resolved from your current login context. Check each sibling page for whether this applies to its own verbs.

## Global options and exit codes

All `uip admin` verbs honor the four [global options](./global-options.md) (`--output`, `--output-filter`, `--log-level`, `--log-file`). Exit codes follow the shared [contract](./exit-codes.md). Most verbs require an active login (`uip login`) with sufficient organization-admin privileges for the resource in question — see each sibling page for the specific role/permission a domain requires.

## See also

- [Concepts: how UiPath CLI is organized](./concepts-cli-architecture.md) — where tools fit in the host + tool model.
- [uip platform](./uip-platform.md) — organization/tenant license allocation, a related but distinct concern.
- [uip gov](./uip-gov.md) — governance policies and compliance packs, layered on top of the access model this tool manages.
- [Sessions](./concepts-sessions.md) — how the organization/tenant context is resolved.
