admin
The admin dashboard: users, projects, roles, config, credentials, and audit.
Maturity: stable (85 %)
Admin. One dashboard for owners and administrators to manage projects, members, roles, credentials, platform config, usage, audit and health, every action gated server-side.
- Admin adds no agent tools or slash commands; agents reach administration through its skills and the routes they wrap.
- Stored credential values are write-only; no screen or route reads a secret back.
- Credential-use limits apply platform-wide per credential; model provider keys are governed by spend limits instead.
- A vector reset is platform-wide and also deletes all brain:// content and its version history.
@neuralis/admin is the management layer of the platform — where the owner
and admins govern a workforce of humans and agents: who is in which
project, what each role may do (feature grants and role priority), what
everything costs, which secrets exist at which scope, and what happened,
recorded in an append-only audit log. It is a
builtin, first-party package with an embedded (in-process) runtime binding,
and it owns the Admin widget plus the administrative backend surface: system
health, dashboard statistics, user and project inventory, role and limit
metadata, platform configuration, encrypted credentials, audit and log views,
vector-store maintenance, and an organization canvas.
This section documents the package itself — its features, routes, UI, skills, and security posture. For the operational story (how to run a deployment as an administrator), see Administration.
Responsibilities
- System overview — health checks (vector store, disk, memory, configured LLM providers), per-package status, active streams, and dashboard KPIs.
- Usage analytics — time-bucketed token/cost series, grouped by model, agent, user, or project, aggregated server-side.
- Users and projects — read inventory of your projects' users (the whole
platform with
platform.users) and projects, with member, role, and limit detail per project. - Platform configuration — file-backed runtime settings editable through the Config tab; environment-derived settings shown as read-only rows.
- Roles — the role catalog (feature grants and role priority), edited per project or platform-wide.
- Credentials — the scope-aware encrypted credential store (platform /
project / user / agent), surfaced in the Credentials tab and through the
manage-credentialsskill. See Credentials. - Audit and logs — audit event reader and per-source log views.
- Vector store — status probe of the vector database and embedding host, the active and target embedding models with the rebuild that moves between them, your own embedding endpoints, plus an explicitly-confirmed destructive reset.
- Organization canvas — an interactive graph of users, agents, and their ownership/assignment relationships.
What the manifest declares
The package manifest provides two feature tiers. A project.* feature acts
inside the caller's current project; a platform.* feature crosses the project
boundary.
| Project-tier feature | Purpose |
|---|---|
project.dashboard | System overview: stats, health, usage charts, package and stream lists |
project.members | This project's member/role inventory |
project.audit | Project-scoped log views — project-installed package logs and per-agent run logs |
project.roles | READ this project's role map (rewriting it additionally needs the role-management flag) |
project.sources | This project's source-connector configurations |
project.credentials | Credential catalog at the caller's own scope (read tier) |
project.credentials.write | Credential mutation at the caller's own scope (stricter write tier) |
project.canvas | Organization canvas |
packages.manage | Cache-clear and package-rescan operations (already namespace-free, so it keeps its bare id) |
| Platform-tier feature | Purpose |
|---|---|
platform.projects | See and read projects you are not a member of |
platform.users | Platform-wide user records and cross-user spend |
platform.scope | Act on a scope outside your session — another project, member, agent, or the platform-wide credential scope |
platform.audit | Every platform-global log: the audit log, the route log, and the first-party packages' own file logs |
platform.config | Platform-global settings, the custom-endpoint registry, the host CLI import |
platform.vector | Vector store status and collections |
platform.vector.reset | The destructive, platform-global vector reset |
Default role grants give every role project.dashboard, so all members see
the system overview. The admin role receives every project-tier feature above;
the owner role holds the '*' wildcard. No platform.* feature is granted
to any role by default — an owner grants them explicitly. The full gating
model is described in
Features and access.
The manifest also declares:
- A singleton widget surface (
type: "admin", Shield icon) rendered frameless and transparent over the workspace background, plus a matching dock entry on the bottom rail. Both requireproject.dashboard. - A
uriPoliciesbaseline for its own data zone:data://<self>/**is read-write by default, while thedata://<self>/audit/**subtree is read-only (writes disabled for all roles). Read access to audit content is gated at the route layer byproject.audit(andplatform.auditfor the organization-wide log), not by the path policy. See URI policies. - Two platform config settings (
configSettings[]) the package owns and reads live on every call:qdrantProbeTimeoutMs(default 3000 ms, range 250–30000) for the vector-database probes, andadminLogsReadMaxLines(default 500, range 100–10000), the per-request line cap on log reads — there is no paging, so it is the maximum forensics depth reachable in one request. Both are edited from the Config tab like any other declared key; see Configuration. - One declared source instance (
sources[]) — the platform App Zone on brain-core'slocalkind, rooted at the platform app directory, user-scoped and write-protected (read: true, write: false, exec: false). Seeing and attaching it requiresdrive.mount.privileged, a feature with no grant below theadmintier. See Manifest. - Trust tier
first-party, embedded runtime binding, and no hosted MCP surfaces.
The package ships no tools and no commands — its model-facing surface is the five management skills plus the feature-gated routes those skills wrap.
Folder map
admin has no tools/ folder; its real package folders map to these pages:
| Package folder | Doc page | Cross-reference |
|---|---|---|
src/ routes (no tools/) | Features and routes | package-system routes |
app/admin | UI | package-system App surfaces |
skills/ (5 bundles) | Skills | package-system skills |
workflows/ (System maintenance) | Workflows | agent-core workflows |
| (cross-cutting) | Security | security model |
In this section
API and usage
Why admin ships routes instead of tools, the route surface grouped by capability, and the one typed agent-core adapter.
Features and routes
The two-tier project.* / platform.* feature namespace and what an administrator can query and mutate.
UI
The dashboard widget: PROJECT/PLATFORM sidebar, panels, and deep-link state.
Skills
Five management skill bundles that let an agent operate the platform.
Workflows
The System maintenance template: a daily platform-health pass that reports everything and remediates within a narrow closed list.
Security
Server-side gates, credential tiers, audit recording, and destructive-action guards.