The admin dashboard
Beyond talking to one agent, someone has to operate the fleet — see what's running, who's waiting on an approval, what each agent is configured to do, and what it did. That's the admin dashboard: a web console served by the platform, gated by the same authorization graph as everything else.
What it shows
The console groups its views by what you're doing:
- Live — agent sessions in flight, live tool calls as they happen, pending approvals, and active work.
- Config — the agents, tools, skills, sources, channels, and identity wiring, plus users, access, and tiered settings. It's where you review what an agent is allowed to be.
- Audit — the logs, past sessions, budget and spend, artifacts, and the memory and knowledge stores. This is the read side of the tamper-evident record.
Each section in depth
- Live activity — sessions in flight, live tool calls, and the approvals queue.
- Agents, tools & skills — the reviewed building blocks of an agent.
- Channels & directory — where agents are reached, and the directory syncs.
- Identity, users & access — who acts, whose credentials, and who administers.
- Memory, knowledge & artifacts — the stores agents write to and produce.
- Audit log & budget — what happened, and what it cost.
Config also includes the tiered Settings, shown in the console per setting.
Reached like any other surface
The dashboard is a loopback-only tab on Desktop and a signed-in, authorized surface on a cluster — the same sign-in and per-request SpiceDB checks as the browser chat. Being an admin is itself a permission in the graph, not a static role file, so who can see and change what is answered the same way as who can call a tool.