Administration is for authorized platform operators. Regular members manage their own Threads and the Projects they can access; they do not need these controls for everyday work.
Choose the administrative area
| Goal | Administrative area |
|---|---|
| Add, suspend, or investigate a person | Users and organization access |
| Connect a provider or approve a model | Gateways and models |
| Qualify profiles or review deployment lifecycle | Managed model deployments |
| Verify transactional messages | Email configuration and test delivery |
| Diagnose platform behavior | Logs, statistics, runtime tools, and health |
| Configure provider reasoning or inspect opted-in retained content | Environment settings and Environment activity |
| Manage shared Apps, custom MCP Apps, and maximum capability policy | Environment Apps |
| Manage enabled commercial controls | Organization billing |
| Inspect or reconcile governed spend | Budgets and allocation ledger |
| Approve and inspect application/worker releases | Releases and rollouts |
| Inspect pending schema changes and data health | Migrations and database health |
Kestrel One checks for an administrator session before returning administrative data. Secrets may be entered through trusted settings but are never returned in readable form.
Provider reasoning display and retention are separate Environment controls. Display is labeled by provider format and is live-only by default. Full provider-visible retention is an explicit encrypted opt-in with a 1–30 day window; only organization administrators can inspect it, and policy changes, views, and deletions are audited. Encrypted or opaque continuation state is never available in the inspector.
Read Environments before changing execution or shared capability policy, and continue with Production operations before changing a live deployment.
Organizations and access
Manage people and roles without using organization administration as a substitute for Project, Environment, model, App, or external-effect authority.
Environments, Apps, and MCP
Own execution images, Workspaces, shared connections, capability ceilings, network modes, OCI egress, and retained activity through Environment administration.
Models, gateways, and deployments
Register provider/model identities, qualify capabilities, manage trusted credentials and leases, and operate immutable managed-model profiles.
Budgets and allocations
Inspect reservation, commit, release, reconciliation, exhaustion, and provider/model evidence through the durable organization ledger.
Releases, workers, and image rollouts
Approve exact application and image candidates, verify all required roles, inspect immutable digests, run canaries, and preserve rollback identities.
Migrations and data health
Inspect the actual target and pending migrations, take an owned backup, apply repository-owned migrations once, and verify application/worker compatibility.
Audit and incident evidence
Record actor, organization, resource, version/revision, operation, decision, result, correlation, and timestamps without returning secrets.