@admin

Workflows

The System maintenance workflow template admin ships: a daily platform-health pass for owners and admins that reports everything and remediates only within a narrow closed list.

admin's workflows/ folder ships one default workflow template, System maintenance — a parallel typed JSON contribution (workflows/*.json), not a markdown contribution. Installing it instantiates a draft workflow on the calendar under the installing caller's identity; the workflow engine in agent-core owns the scheduling and run execution.

System maintenance

FieldValue
Groupessentials
Default triggercron 0 7 * * * (07:00 UTC — edit after install)
State modefresh (each run starts a clean context)
InputsDEPTH — a choice of quick (default: audit, membership, credentials and package scan) or deep (adds the usage breakdown and the data-growth checks)
Deliverynone — the run writes its report to the workflow's state folder; it sends nothing to a channel
Requiresproject.audit, project.members

A daily platform-health pass for owners/admins. Each run reviews:

  • Audit-log anomalies — unusual or failed privileged operations.
  • Membership drift — users, roles, and project membership changes.
  • Credential catalog health — which secrets exist at which scope (values are never printed).
  • Package trust posture — installed packages and their trust tiers.
  • Usage and spend — token/cost trends and top consumers.
  • Data growth (deep runs only) — disk usage across the project data roots, flagging directories growing unusually fast (runaway logs, runaway run histories).

It writes a dated report with critical findings first. Since template revision 2 the pass may also remediate on the spot, but only within a closed list: trigger a sync or reindex for a source it found stale; re-time, pause or resume a workflow whose own run history shows repeatedly missed or skipped occurrences (after reading the other entries' current schedules, so it never moves one onto an occupied slot); or set or lower a per-credential or rate limit — never raise or remove one. Everything outside the list stays a proposal, every remediation is re-verified with a fresh read rather than trusted from the write acknowledgement, and a denied call is recorded with the feature it needed instead of worked around. The run's real authority is unchanged either way — it executes as its creator's current re-resolved rights, and platform policy enforcement applies exactly as in interactive chat. Because it requires project.audit and project.members — neither of which is granted below the admin tier — non-admin users never see the template.

Why admin ships no tools

admin's model-facing surface is its five management skills plus the feature-gated routes those skills wrap — the package declares no tools and no commands. The System maintenance template is the one scheduled contribution; everything else an agent does in the admin domain goes through a skill that wraps a feature-gated route.

On this page