Restricted administration
Digital Brain Admin
Sign in with an authorized platform administrator account.
Platform administrator access is verified after authentication.
Restricted administration
Sign in with an authorized platform administrator account.
Platform administrator access is verified after authentication.
Overview & control center
Blueprint-aligned V1 operations overview. Later-version modules remain visibly Planned.
Live Core API, database, schema and service state.
Current normalized V1 provider route.
Registry-driven routing policies and provider/model priorities are operational.
Open Blueprint-prescribed Admin modules.
Live counts for the selected project.
Latest selected-project events.
Latest coordinated backup generation.
Exact 12-module Blueprint order.
AI foundation
Live provider registry, active model controls and capability routing configuration.
Provider Registry and model lifecycle controls are operational.
Routing policies, priority/fallback controls and STT/TTS-ready capability slots are operational; quota telemetry remains unavailable.
Legacy route alias
This legacy path resolves to the canonical Project operational center.
Brain operational center
A Brain is the lifetime root. Internal Projects / Work Contexts are optional child records; existing files, memory, connectors, Vault and operations remain Brain-wide compatibility resources.
Live Brain-root counts and assignment context.
Optional Brain children only. They do not move existing Brain-wide data or create a separate user mode.
Assignments are managed by Platform Admin. Stored legacy role values are not permission levels.
Brain-wide compatibility storage remains unchanged in Phase 2.
Vault remains Brain-wide and isolated; Work Contexts cannot expose it.
Upload an original file only in the selected Brain compatibility root.
Review pending or conflicted Brain memory with the existing audited workflow.
Connector ownership and Action/Job execution are unchanged. Future optional Work Context restriction is deferred.
Existing Brain-root behavior remains unchanged; no scheduler or worker redesign is introduced.
Vault infrastructure is local-only. Admin never receives decrypted records, passwords, Secure Notes, tokens, or Assistant prompts/responses.
Brain-owned connector catalogue and lifecycle
Connector instances belong to a Brain. They are Brain-wide unless an optional Internal Project / Work Context restriction is configured; credentials stay encrypted and redacted.
Admin remains the current connector-management authority. A Work Context can restrict use, never becomes the connector owner, and never exposes credentials. CMS external capability awaits an approved API specification; WooCommerce and Custom API live connectivity remain unverified without approved external configuration.
Admin-owned account lifecycle
Create accounts and manage the single User ↔ Project assignment boundary.
Assign or remove existing users using the canonical Admin assignment lifecycle.
Protected boundaries
Current V1 identity, Core boundary, isolation and recovery protection.
External assurance and later hardening are not claimed complete.
Recovery architecture
Coordinated database, file and local-model backup state.
Database, original files and Ollama are scheduled and checksum verified.
Disposable restore validation is available. Destructive production restore is not exposed here.
Accountability
Recent V1 mutation and orchestration events for the selected project.
Connector, automation, approval and advanced recovery audit domains are not implemented.
Configuration
V1 owner-controlled, versioned project settings.
AI and Voice V2 capabilities are operational; Connector and Automation settings remain V3 planned and not started.
Consolidated platform administration
Security, Vault infrastructure, Backup & Recovery, Audit, Settings and Service Health in one operational destination.
Live Core API readiness, database and schema; Worker and Scheduler are separately reported.
Destructive restore is not exposed in Admin.
Project audit and Timeline/Event inspection remain scoped to their Project context. No secret payload is rendered.
AI & Voice configuration is in AI & Voice; Project configuration remains Admin-mediated and Project-scoped. No normal-user Settings controls are embedded here.