System administration
For whoever runs the server: the master switch, quotas, suspending a business, locking accounts, blocking domains.
This is a completely different role
A system administrator runs the whole CoreSkill server. Owner / Admin are roles inside one business. The owner of a business is not automatically a system administrator, and the other way round. If your company uses a CoreSkill that somebody else operates, this section isn't for you.
Open Admin at the bottom of the sidebar. Without the right role you are simply sent back to the home page with no message at all. That is the current behaviour, not a broken page.
The seven pages
| Page | What you do there |
|---|---|
| Overview | System-wide figures, a 14-day chart, the busiest server owners, recent actions |
| Businesses | Every business: owner, size, server quota, suspension |
| Users | Change the system role, lock and unlock accounts |
| MCP logs | Every call across the whole system, filterable by business |
| Audit log | Every privileged write, with who did it and when |
| Blocked email domains | Domains that may never open an account |
| System settings | The master switch and the system defaults |
The master switch
System settings → MCP & logs tab → the Serve skills over MCP switch (on by default).
Turning it off makes every MCP endpoint refuse immediately, for everyone, across every business. The AI assistants of all your users stop reading skills. This is the emergency brake for a security incident, not an everyday maintenance button.
The same form holds two more values: Default server limit (5 by default, applied to every business with no limit of its own) and Keep usage logs for (days) (90 by default, from 7 up to 3650).
One value has no field in the interface: the number of businesses one person may own, 3 by default. It can only be changed in the database, but it is exactly the number in the error line You can own at most 3 businesses.
Managing businesses
The Businesses page lists every business with its owner, member count, server count and 7-day calls. Click Manage to open two forms:
- Server quota
- Set just for this business, from 1 to 500. Leave it empty to use the system default.
- Suspend / Reinstate
- Fill in Reason (optional) (up to 300 characters) and press Suspend. Every MCP endpoint of that business refuses immediately, and its staff's AI stops working until you reinstate it.
Click a business name to open its read-only detail page: departments, skill servers and up to 200 members. There is no button here to edit what's inside a business, which is the job of that business's own Owner and Admins.
Locking an account
Users page → Manage → the Account section → Lock account, with a Reason (optional) (up to 200 characters).
Locking an account means every key that person holds stops working. And if that person owns a business, the whole business stops working and everyone inside it loses access. Check the Businesses column before you click.
The Role section changes the system role: Administrator, Manager, Member. Only an Administrator can reach the admin area; the other two are labels now, since every business permission comes from the role inside the business.
You can't change your own role or lock your own account. This is the latch that stops you locking yourself out of the system when you are the only administrator.
Blocking email domains
The Blocked email domains page has three independent forms, split on purpose so that submitting one can't accidentally flip the switch in another.
Under Add domain, paste one domain per line, then press Add domain.
Subdomains are blocked too: blocking
tempmail.comalso blocksmail.tempmail.com. Up to 5000 domains.Under Policy, turn on the Block sign-ups from these domains switch (off by default).
The list only takes effect while this switch is on.
Write the Message shown to blocked sign-ups (up to 500 characters) and press Save.
This is the only string in the app that doesn't go through the translation system. Visitors see it exactly as typed, so write it in your own users' language.
Domain blocking applies to email sign-ups and to Google/Facebook sign-ins alike. People who already have an account are exempt, so changing the policy never throws out someone already using the system.
The list draws at most 300 rows on screen; beyond that, use the Filter the list field to find one.
Pausing sign-ups
System settings → Site tab → Sign-ups card → the Pause new sign-ups switch (off by default). Turn it on and the sign-up page stops drawing its form. Existing accounts keep working, and invitations into a business still work.
This is the right setup for an internal system: pause public sign-ups, then let people in by invitation.
Branding
Same Site tab, Branding card → Site name (up to 60 characters). This name appears in the browser tab, in outgoing email and on the sign-in screen. Leave it empty to fall back to the default.
The audit log
It records every privileged write: admin actions, writes made by an AI through the management endpoint, and security changes. Filter by action (for example user.totp.enable, org.create) or by actor id.
This page is read-only: no row can be edited or deleted, not even by an administrator. That is exactly what makes it worth anything when an account of events is disputed.
Purging logs
The Log retention card in the right-hand column shows how many rows are stored, the oldest one, and the retention window. The system purges once a day on its own; the Purge now button runs it by hand, immediately.
