Platform cost reporting
Platform Administrators have separate cross-Organization cost reporting with unattributed spend, burn rate, available OpenRouter credit, and estimated runway. Continue with /guides/observe-and-govern/costs#platform-costs. This authority does not grant Organization Membership.
Platform access and Organization access
Platform Administrator access lets you use Platform View and manage the supported platform resources. It does not automatically grant access to an Organization’s private configuration, credentials, or Agent operations.
- 02.1
To work inside an Organization, select one where you have membership. Your Organization and Agent permissions determine which actions are available there.
- 02.2
Organization suspension and reactivation are not currently supported. Use
/guides/observe-and-govern/platform-administrationfor the available administration workflows and current limitations.
Current administration surface
Platform Administrators can list users and Organizations, provision pending users with an initial Organization, resend invitations, and grant or revoke Platform Privilege with a reason. Privilege changes reject no-ops, self-revocation, and removal of the final Platform Administrator.
- 03.1
Platform View also provides dedicated catalogues for global Platform Templates and Platform Skills. These are Platform-owned resources, not cross-tenant reads of Organization-owned content. Platform routes resolve no active Organization, require Platform Administrator authority, use dedicated Platform DTOs and API routes, and do not grant Membership in any Organization. The API remains authoritative even when the UI hides unavailable actions.
- 03.2
Platform Templates use
/dashboard/platform/templatesand/api/v1/platform/templates. Platform Skills use/dashboard/platform/skillsand/api/v1/platform/skills, including/dashboard/platform/skills/newfor creation and/dashboard/platform/skills/{skillId}with/api/v1/platform/skills/{skillId}for detail. Organization and Agent-private Skills are not managed through these routes. - 03.3
Platform Skills are global resources visible to Organizations and Agents. Bundled
aai-cliSkills are bootstrap-provided Platform lineages, while Platform Administrators may create custom global Skill lineages. Creation makes one mutable draft with no published version; the draft owns proposedSKILL.md, relative reference files, description, and provider metadata. Publishing copies its complete content into the next immutable Skill Version and clears the draft. Renaming changes lineage display metadata only; content and provider changes are draft-gated, and publishing never repins existing Agents, Templates, Overrides, Organizations, or forks. - 03.4
Each published Skill Version contains exactly one root
SKILL.md, with other validated paths relative to the Skill root. Consumers pin exact immutable versions. Platform Skills are read-only in Organization and Agent scope; Organizations can fork visible Platform Skills, Agents can fork visible Platform or Organization Skills privately, and forks remain independent with exact direct-source provenance. - 03.5
Platform Administrators may delete an unreferenced historical Platform Skill Version or unused custom Platform Skill lineage through the shared branded confirmation flow. A version is blocked when it is final, Agent-pinned, Template or Override-required, draft-referenced, or a fork source. A custom lineage is blocked when any version has an Agent pin, Template/Override requirement, or draft/fork-source reference. Custom deletion removes draft, versions, and files; bundled
aai_clilineages cannot be deleted; soft-deleted Agent pins still protect versions; and blocked deletion explains its dependency. - 03.6
Checked-in bundled Skills seed only missing Platform Skill lineages. Once a lineage exists, database drafts and published versions are authoritative, so redeployment never overwrites Platform Administrator changes. Bundles use isolated
api/domains/agents/aai_cli_skills/bundled/skills/aai-<integration>/SKILL.mdroots, not Python modules or a shared mutableaai-cliroot.
Current oversight data
Platform View includes allowlisted Organization and user identity detail, Membership drill-downs, current Agent counts, cross-Organization communication or Conversation volume, and Agent activity statistics. The Activity panel uses an explicit date range (today and the previous 29 local days by default, up to 366 days), Organization, app (Slack, Teams, Telegram, or Discord), and message direction. Agent and creator filters remain API-only. The URL preserves a fixed range and selected filters for another authorized Platform Administrator; direction changes message display, not Active agents. Sender identity and tenant content are excluded.
- 04.1
Current Agent counts remain distinct from period-scoped activity statistics. Platform activity is bounded projection data, not tenant-level Conversation access; deferred Tool Call, model, and per-Agent drill-down work is not shipped behavior.
Event Delivery monitoring
A read-only global monitor shows Event Delivery counts, stale/unknown ages, and a filtered explorer. It reads PostgreSQL rather than raw Redis and exposes safe operational metadata, not the event envelope or full payload. Retry, replay, remapping, and deletion are intentionally absent.
- 05.1
The Event Delivery Monitor displays Domain Event Handler deliveries only. It does not display Communication Deliveries or Connection operation-journal entries; those belong to
/guides/observe-and-govern/communication-diagnostics.
Deferred platform work
The backlog proposes Organization suspension with immediate access denial and asynchronous runtime cleanup, a unified searchable Security Audit explorer, and deeper Agent, Tool Call, and model oversight. Suspension must commit before cleanup and reactivation must wait for cleanup completion; these are accepted design constraints for future implementation, not shipped controls.
Data boundary
Platform oversight projections must never expose tenant Conversation content, tool arguments or results, logs, prompts, Organization Templates, Organization or Agent-private Skills, Agent configuration, credentials, or raw Telemetry. New projection fields require explicit data-classification and authorization review.
- 07.1
Dedicated Platform catalogue APIs may expose and manage global Platform Templates and Platform Skills. This does not permit Platform View to read or mutate tenant-owned definitions. Platform Privilege remains separate from Organization Membership and Agent Access: a Platform Administrator still needs a real Membership and applicable Agent Access for Organization-owned workflows.
- 07.2
Platform-owned administration includes global Platform Templates, global Platform Skills, Platform Privilege management, and pending-user provisioning. Cross-tenant oversight is limited to allowlisted Organization and Agent statistics, user and Membership identity, read-only Event Delivery monitoring, and bounded activity projections.
- 07.3
Platform View is not a deployment control plane. It administers the Agent Barn installation the user is signed into; it does not deploy another environment, promote images, create a public release, or aggregate data across clusters. Each installation has its own Platform Administrators and oversight data, and Platform authority never crosses cluster or database boundaries.
- 07.4
The
stagingbranch on AAI Labs k3s is branch testing with movinglatest-stagingimages;mainon the same k3s is the main-branch testing ground with movinglatestimages. Hosted public Agent Barn on Talos is public production and deploys only from an explicitvX.Y.Zrelease tag..github/workflows/deploy-public.ymlpins API and UI images fromregistry.agentbarn.dev; the main k3s deployment is not hosted public production. Public deployment and secret management remain infrastructure workflows outside Platform View, and public and k3s credentials are not interchangeable. - 07.5
Continue with
/guides/observe-and-govern/platform-administration,/guides/templates-and-skills/skill-scopes,/guides/templates-and-skills/skills,/guides/templates-and-skills/skill-versions,/guides/templates-and-skills/forks-and-updates,/guides/local-development-and-operations, and/guides/self-hosting/upgradesfor detailed procedures.