Observe and govern
Guide Available

Platform Administration and Oversight

Platform authority is intentionally separate from Organization Membership. Platform View exposes dedicated, allowlisted projections and administrative workflows without turning a Platform Administrator into a tenant user.

For
Platform administrators
On this page
  1. Platform cost reporting
  2. Platform access and Organization access
  3. Current administration surface
  4. Current oversight data
  5. Event Delivery monitoring
  6. Deferred platform work
  7. Data boundary
01

Platform cost reporting

Platform Administrators have separate cross-Organization cost reporting with unattributed spend, burn rate, available OpenRouter credit, and estimated runway. Continue with /guides/observe-and-govern/costs#platform-costs. This authority does not grant Organization Membership.

02

Platform access and Organization access

Platform Administrator access lets you use Platform View and manage the supported platform resources. It does not automatically grant access to an Organization’s private configuration, credentials, or Agent operations.

  1. 02.1

    To work inside an Organization, select one where you have membership. Your Organization and Agent permissions determine which actions are available there.

  2. 02.2

    Organization suspension and reactivation are not currently supported. Use /guides/observe-and-govern/platform-administration for the available administration workflows and current limitations.

03

Current administration surface

Platform Administrators can list users and Organizations, provision pending users with an initial Organization, resend invitations, and grant or revoke Platform Privilege with a reason. Privilege changes reject no-ops, self-revocation, and removal of the final Platform Administrator.

  1. 03.1

    Platform View also provides dedicated catalogues for global Platform Templates and Platform Skills. These are Platform-owned resources, not cross-tenant reads of Organization-owned content. Platform routes resolve no active Organization, require Platform Administrator authority, use dedicated Platform DTOs and API routes, and do not grant Membership in any Organization. The API remains authoritative even when the UI hides unavailable actions.

  2. 03.2

    Platform Templates use /dashboard/platform/templates and /api/v1/platform/templates. Platform Skills use /dashboard/platform/skills and /api/v1/platform/skills, including /dashboard/platform/skills/new for creation and /dashboard/platform/skills/{skillId} with /api/v1/platform/skills/{skillId} for detail. Organization and Agent-private Skills are not managed through these routes.

  3. 03.3

    Platform Skills are global resources visible to Organizations and Agents. Bundled aai-cli Skills are bootstrap-provided Platform lineages, while Platform Administrators may create custom global Skill lineages. Creation makes one mutable draft with no published version; the draft owns proposed SKILL.md, relative reference files, description, and provider metadata. Publishing copies its complete content into the next immutable Skill Version and clears the draft. Renaming changes lineage display metadata only; content and provider changes are draft-gated, and publishing never repins existing Agents, Templates, Overrides, Organizations, or forks.

  4. 03.4

    Each published Skill Version contains exactly one root SKILL.md, with other validated paths relative to the Skill root. Consumers pin exact immutable versions. Platform Skills are read-only in Organization and Agent scope; Organizations can fork visible Platform Skills, Agents can fork visible Platform or Organization Skills privately, and forks remain independent with exact direct-source provenance.

  5. 03.5

    Platform Administrators may delete an unreferenced historical Platform Skill Version or unused custom Platform Skill lineage through the shared branded confirmation flow. A version is blocked when it is final, Agent-pinned, Template or Override-required, draft-referenced, or a fork source. A custom lineage is blocked when any version has an Agent pin, Template/Override requirement, or draft/fork-source reference. Custom deletion removes draft, versions, and files; bundled aai_cli lineages cannot be deleted; soft-deleted Agent pins still protect versions; and blocked deletion explains its dependency.

  6. 03.6

    Checked-in bundled Skills seed only missing Platform Skill lineages. Once a lineage exists, database drafts and published versions are authoritative, so redeployment never overwrites Platform Administrator changes. Bundles use isolated api/domains/agents/aai_cli_skills/bundled/skills/aai-<integration>/SKILL.md roots, not Python modules or a shared mutable aai-cli root.

04

Current oversight data

Platform View includes allowlisted Organization and user identity detail, Membership drill-downs, current Agent counts, cross-Organization communication or Conversation volume, and Agent activity statistics. The Activity panel uses an explicit date range (today and the previous 29 local days by default, up to 366 days), Organization, app (Slack, Teams, Telegram, or Discord), and message direction. Agent and creator filters remain API-only. The URL preserves a fixed range and selected filters for another authorized Platform Administrator; direction changes message display, not Active agents. Sender identity and tenant content are excluded.

  1. 04.1

    Current Agent counts remain distinct from period-scoped activity statistics. Platform activity is bounded projection data, not tenant-level Conversation access; deferred Tool Call, model, and per-Agent drill-down work is not shipped behavior.

05

Event Delivery monitoring

A read-only global monitor shows Event Delivery counts, stale/unknown ages, and a filtered explorer. It reads PostgreSQL rather than raw Redis and exposes safe operational metadata, not the event envelope or full payload. Retry, replay, remapping, and deletion are intentionally absent.

  1. 05.1

    The Event Delivery Monitor displays Domain Event Handler deliveries only. It does not display Communication Deliveries or Connection operation-journal entries; those belong to /guides/observe-and-govern/communication-diagnostics.

06

Deferred platform work

The backlog proposes Organization suspension with immediate access denial and asynchronous runtime cleanup, a unified searchable Security Audit explorer, and deeper Agent, Tool Call, and model oversight. Suspension must commit before cleanup and reactivation must wait for cleanup completion; these are accepted design constraints for future implementation, not shipped controls.

07

Data boundary

Platform oversight projections must never expose tenant Conversation content, tool arguments or results, logs, prompts, Organization Templates, Organization or Agent-private Skills, Agent configuration, credentials, or raw Telemetry. New projection fields require explicit data-classification and authorization review.

  1. 07.1

    Dedicated Platform catalogue APIs may expose and manage global Platform Templates and Platform Skills. This does not permit Platform View to read or mutate tenant-owned definitions. Platform Privilege remains separate from Organization Membership and Agent Access: a Platform Administrator still needs a real Membership and applicable Agent Access for Organization-owned workflows.

  2. 07.2

    Platform-owned administration includes global Platform Templates, global Platform Skills, Platform Privilege management, and pending-user provisioning. Cross-tenant oversight is limited to allowlisted Organization and Agent statistics, user and Membership identity, read-only Event Delivery monitoring, and bounded activity projections.

  3. 07.3

    Platform View is not a deployment control plane. It administers the Agent Barn installation the user is signed into; it does not deploy another environment, promote images, create a public release, or aggregate data across clusters. Each installation has its own Platform Administrators and oversight data, and Platform authority never crosses cluster or database boundaries.

  4. 07.4

    The staging branch on AAI Labs k3s is branch testing with moving latest-staging images; main on the same k3s is the main-branch testing ground with moving latest images. Hosted public Agent Barn on Talos is public production and deploys only from an explicit vX.Y.Z release tag. .github/workflows/deploy-public.yml pins API and UI images from registry.agentbarn.dev; the main k3s deployment is not hosted public production. Public deployment and secret management remain infrastructure workflows outside Platform View, and public and k3s credentials are not interchangeable.

  5. 07.5

    Continue with /guides/observe-and-govern/platform-administration, /guides/templates-and-skills/skill-scopes, /guides/templates-and-skills/skills, /guides/templates-and-skills/skill-versions, /guides/templates-and-skills/forks-and-updates, /guides/local-development-and-operations, and /guides/self-hosting/upgrades for detailed procedures.

Documentation