For admins
Where to look for each admin task, by surface.
Administration is spread across four surfaces. Pick the one that owns what you want to change.
| Want to… | Use… |
|---|---|
| Change app features, providers, file limits, branding | Admin panel → Configuration |
| Give a set of people different settings | Admin panel → Configuration profiles |
| Define roles and groups, assign members | Admin panel → Access |
| Choose which admin capabilities a role holds | Admin panel → Grants |
| See who changed what, and export it | Admin panel → Audit log |
| Register a model, set budgets and rate limits on keys | Gateway admin |
| Read one user's requests, find a bad reply, watch cost | Langfuse |
| Watch error rate, latency, guardrail decisions | Grafana |
| Set up an agent team, its roles and its budget | Agent roles and budgets |
Who is an admin
The first account registered on a fresh install gets the ADMIN role;
every later account is USER. What the admin panel actually checks at
sign-in is a capability, access:admin, which ADMIN holds and which you
can grant to a role of your own. Roles and groups
covers elevating people.
Each surface signs you in separately:
| Surface | Where | Sign in with |
|---|---|---|
| NuFi Admin Panel | admin.app.nufi.me on NuFi's hosting; port 3000 of its own container elsewhere | your NuFi account, if it holds access:admin |
| the gateway's admin UI | api.codechi.me/ui; localhost:4000/ui on the compose stack | the gateway master key |
| Langfuse | langfuse.codechi.me; localhost:3000 | the admin the stack seeded from .env (LANGFUSE_INIT_USER_EMAIL), then anyone invited |
| Grafana | grafana.codechi.me; localhost:3030 | GRAFANA_ADMIN_USER and its password from .env |
Four sign-ins on purpose: a compromise of one does not open the others. The app's account is the identity that matters; the other three are operating tools you open when you need them.