NuFiDocs

Admin panel basics

Sign in, find your way around, and the capability model behind every action.

NuFi Admin Panel is the web app where you manage the NuFi app for your organisation: configuration, roles, groups, members, capability grants, and the audit log of who changed what. NuFi's own copy is at admin.app.nufi.me; a self-hosted one runs from its own image (Installing the admin panel).

The admin panel dashboard with quick links

Sign in

The admin panel sign-in screen

Open the admin panel. It keeps its own session and does not pick up the app's sign-in, so you sign in here even if the app is open in another tab.
Enter the email and password of a NuFi account, then Sign in. The account must hold the access:admin capability, which the ADMIN role has. If single sign-on is configured, Sign in with SSO instead.
If the account has two-factor authentication, enter the 6-digit code from your authenticator app when asked.

With SSO-only mode on, the panel goes straight to the identity provider. If that redirect fails, the password form comes back with a note saying so.

Find your way around

The left sidebar has seven destinations:

SectionWhat it is for
Dashboardquick links to Configuration, Access, Grants and Help
Configurationevery setting the app reads: providers, custom endpoints, model specs, MCP, features, files, system. Configuration
Accessroles, groups and their members. Roles and groups
Grantswhich admin capabilities each role holds. Capabilities
Audit logevery admin action, with a CSV export. Audit log
Securitya page that has had no data source since July 2026; see below
Helplinks to documentation

The Security page used to show the app's own guardrail decisions. Those controls moved to the gateway on 2026-07-29 and the page says so at the top; an empty table there means the page has nothing to read from, not that nothing was blocked. The gateway's decisions are on the Grafana dashboard and in the gateway's audit events: Operating the guardrails.

Your account sits at the bottom left of the sidebar. ⌘K (Ctrl+K) opens a command menu that jumps to any page, configuration tab or section.

Some of the panel's own text still says "LibreChat", the project the app grew from, and the Help page links to that project's documentation rather than this manual. The panel is NuFi's; the strings have not caught up.

The capability model

Every admin action is gated by a capability. You do not hand out individual permissions; you grant a role a set of capabilities on the Grants page, then put people into that role on Access.

Two System roles ship built in:

  • ADMIN holds every capability.
  • USER holds none: ordinary use of the app, nothing here.

A constrained sub-admin is a new role with only the capabilities it needs.

A typical workflow

A teammate needs limited admin powers. On Access → Roles, click Create role and name it, say SUPPORT.
On Grants, open that role and tick only the capabilities it should have. Include access:admin, or the teammate cannot sign in here.
Back on Access, open the role's Members tab and add the teammate.
A set of people needs a different model or a higher limit? Create a Group under Access, add the members, then give the group a configuration profile: Configuration profiles.