The platform admin area
Who can reach it, how the privilege is granted, and what each of the nine pages is for.
The admin area is for the people who run Madebook itself, not the people who use it. It sits at /admin behind its own chrome.
Who can reach it
One flag on a user account, and nothing else. There is no organization role that grants it.
It is granted at Bookbag, not in Madebook. An account's product role is read from Bookbag on every sign-in and on every request, so an administrator made or unmade there becomes one — or stops being one — without anything happening here. An account arriving through sign-in for the first time never lands as a platform administrator.
The nine platform capabilities:
| Capability | What it reaches |
|---|---|
platform.manage_users |
The user list across the deployment |
platform.view_overview |
The counts on the admin front page |
platform.manage_billing |
Plans and revenue |
platform.manage_ai_providers |
Reaching the two AI links. The pages themselves are at the account service and gate on its own platform admins |
platform.manage_email |
Email settings |
platform.manage_integrations |
The Madebook GitHub App registration |
platform.view_jobs |
The background job queue |
platform.view_audit_log |
The audit log across organizations |
skill.publish_platform |
Publishing a skill above every organization |
There is deliberately no platform.manage_organizations:
An organization belongs to Bookbag and is administered there, for every product at once. Madebook holds no power over one, so it must not advertise a capability to manage one.
Two of those capabilities — managing users and managing email — have no pages in Madebook. Members and email both live at Bookbag.
Reaching everything
A platform administrator reaches every organization, and every write they make outside their own memberships is written to the audit log with the capability used. Reads are not.
One thing still binds them: an API token is a ceiling that applies first. A platform admin acting through a token scoped to one organization and one workspace is still confined to it, and a read-only token still cannot write.
The browser-side gate is a convenience, not the boundary. Every admin endpoint checks the capability on the server.
The nine pages
| Page | What it is for |
|---|---|
| Overview | Counts at a glance, and the newest workspaces. |
| Models & providers ↗ | A link out to the account service. The keys and models the platform runs on. Madebook holds none. |
| Model catalog ↗ | A link out to the account service. The models customers may approve, and be managed by. |
| Integrations | The Madebook GitHub App, and every source-control connection. |
| Skills | The shared shelf, and every customer skill. |
| Background jobs | The queue. |
| Audit log | Across organizations. |
| Readiness | What /ready answers and why — every check with its reason, migrations behind, stuck jobs, failing audit streams, undelivered messages to linked products, drifted repositories. See Operational readiness. |
| Revenue | What the platform earns. |
| Stripe & plans | Free mode, the Stripe key, and the prices. |
Plus one external row, Organizations ↗, which leaves for Bookbag — organizations are made, named, peopled, suspended and deleted there, so Madebook has nothing left to administer.
Overview
Eight tiles, and a panel of the five newest workspaces.
| Tile | What it counts |
|---|---|
| Organizations | Organizations this deployment holds work for. Links out to Bookbag, which is where one is administered. |
| Workspaces | Every workspace, across every organization. |
| Repositories | Every connected repository. |
| Missions | Every mission contract. |
| Agent sessions | Every session an agent has registered. |
| Paying | Organizations on a live subscription. |
| On trial | Organizations inside a trial. |
| MRR | The estimate from the Revenue page. |
Each value falls back to an em dash, never to 0, because "none" and "not loaded yet" are different facts and should not look the same. Each tile reads its own figure, so a revenue call that fails does not blank the counts beside it.
There are no member figures here, deliberately. Accounts and the sign-ins that make a signup date belong to Bookbag and are counted there. Madebook could count the people who happen to have signed into Madebook, but that is a different number wearing the same label — so the page counts the work it holds and links out for the rest. The Organizations ↗ row in the sidebar is the way there.
Related
- Platform AI and the model catalog
- Integrations
- Background jobs
- Plans, Stripe and revenue
- Skills — the platform shelf and promotion
- The audit log