Admin Roles & Login
Two Roles
| Role | Determination | Scope |
|---|---|---|
| System admin | Lansenger scan + developer org + app operator | Global: providers, marketplace, all orgs, global audit |
| Org admin | Lansenger scan + installer org + app operator | Own org: users, policies, keys, private skills, org audit |
Non-operators cannot access the admin console.
Login Flow
- Admin console shows Lansenger authorization QR code
- Scan and confirm with Lansenger app
- Server retrieves userToken and determines role via Lansenger API
- Issues admin session (30 min, HMAC-signed)
Role is determined at login time; operator changes take effect immediately.
System Admin Functions
- Global overview (orgs, users, active users, content, usage trends)
- Organization list (read + enable/disable)
- Official provider CRUD (with key hosting and rotation)
- Skill/plugin/expert marketplace management
- Global usage stats and audit
Org Admin Functions
- Org overview with usage trends
- User management (search/disable/revoke tokens)
- Three-tier policy configuration
- Custom providers and API key hosting
- Private skill upload and management
- Org usage stats and audit