Administrator guide
SUPER_ADMIN owns platform policy, AI Providers, secrets and global Plugin state. ADMIN manages ordinary users only: it cannot create, inspect or modify another administrator and cannot change platform, Docker or Daemon authority.
Dynamic settings
Use Platform Settings for registration, SMTP/SMS/SSO enablement, AI Provider BaseURL and model policy, Plugin registries, signature trust and soft limits. Sensitive settings use versioned encrypted secret references and become active only after validation. Infrastructure roots remain deployment configuration.
AI work and approvals
Every conversation persists user-visible work items, tool calls, affected files, diffs, approvals and the final answer. The compact Worked for summary hides the process by default without deleting it.
Actions classified as ask pause before an Operation or Daemon command is created. Approval binds the exact redacted input, current actor and assignment revisions, Workspace generation, policy, Plugin/MCP identity and one operation. Approval cannot grant a permission the user does not already hold.
Plugin administration
Plugins are installed once for the Panel. Only SUPER_ADMIN with strong verification may install, upgrade, configure, disable or remove one. Workspaces do not own Plugin installations or secret values.