CoreSkill
Language
Sign in
All sections

System administration

For whoever runs the server: the master switch, quotas, suspending a business, locking accounts, blocking domains.

This is a completely different role

A system administrator runs the whole CoreSkill server. Owner / Admin are roles inside one business. The owner of a business is not automatically a system administrator, and the other way round. If your company uses a CoreSkill that somebody else operates, this section isn't for you.

Open Admin at the bottom of the sidebar. Without the right role you are simply sent back to the home page with no message at all. That is the current behaviour, not a broken page.

The seven pages

PageWhat you do there
OverviewSystem-wide figures, a 14-day chart, the busiest server owners, recent actions
BusinessesEvery business: owner, size, server quota, suspension
UsersChange the system role, lock and unlock accounts
MCP logsEvery call across the whole system, filterable by business
Audit logEvery privileged write, with who did it and when
Blocked email domainsDomains that may never open an account
System settingsThe master switch and the system defaults

The master switch

System settingsMCP & logs tab → the Serve skills over MCP switch (on by default).

Turning it off makes every MCP endpoint refuse immediately, for everyone, across every business. The AI assistants of all your users stop reading skills. This is the emergency brake for a security incident, not an everyday maintenance button.

The same form holds two more values: Default server limit (5 by default, applied to every business with no limit of its own) and Keep usage logs for (days) (90 by default, from 7 up to 3650).

One value has no field in the interface: the number of businesses one person may own, 3 by default. It can only be changed in the database, but it is exactly the number in the error line You can own at most 3 businesses.

Managing businesses

The Businesses page lists every business with its owner, member count, server count and 7-day calls. Click Manage to open two forms:

Server quota
Set just for this business, from 1 to 500. Leave it empty to use the system default.
Suspend / Reinstate
Fill in Reason (optional) (up to 300 characters) and press Suspend. Every MCP endpoint of that business refuses immediately, and its staff's AI stops working until you reinstate it.

Click a business name to open its read-only detail page: departments, skill servers and up to 200 members. There is no button here to edit what's inside a business, which is the job of that business's own Owner and Admins.

Locking an account

Users page → Manage → the Account section → Lock account, with a Reason (optional) (up to 200 characters).

Locking an account means every key that person holds stops working. And if that person owns a business, the whole business stops working and everyone inside it loses access. Check the Businesses column before you click.

The Role section changes the system role: Administrator, Manager, Member. Only an Administrator can reach the admin area; the other two are labels now, since every business permission comes from the role inside the business.

You can't change your own role or lock your own account. This is the latch that stops you locking yourself out of the system when you are the only administrator.

Blocking email domains

The Blocked email domains page has three independent forms, split on purpose so that submitting one can't accidentally flip the switch in another.

  1. Under Add domain, paste one domain per line, then press Add domain.

    Subdomains are blocked too: blocking tempmail.com also blocks mail.tempmail.com. Up to 5000 domains.

  2. Under Policy, turn on the Block sign-ups from these domains switch (off by default).

    The list only takes effect while this switch is on.

  3. Write the Message shown to blocked sign-ups (up to 500 characters) and press Save.

    This is the only string in the app that doesn't go through the translation system. Visitors see it exactly as typed, so write it in your own users' language.

Domain blocking applies to email sign-ups and to Google/Facebook sign-ins alike. People who already have an account are exempt, so changing the policy never throws out someone already using the system.

The list draws at most 300 rows on screen; beyond that, use the Filter the list field to find one.

Pausing sign-ups

System settingsSite tab → Sign-ups card → the Pause new sign-ups switch (off by default). Turn it on and the sign-up page stops drawing its form. Existing accounts keep working, and invitations into a business still work.

This is the right setup for an internal system: pause public sign-ups, then let people in by invitation.

Branding

Same Site tab, Branding card → Site name (up to 60 characters). This name appears in the browser tab, in outgoing email and on the sign-in screen. Leave it empty to fall back to the default.

The audit log

It records every privileged write: admin actions, writes made by an AI through the management endpoint, and security changes. Filter by action (for example user.totp.enable, org.create) or by actor id.

This page is read-only: no row can be edited or deleted, not even by an administrator. That is exactly what makes it worth anything when an account of events is disputed.

Purging logs

The Log retention card in the right-hand column shows how many rows are stored, the oldest one, and the retention window. The system purges once a day on its own; the Purge now button runs it by hand, immediately.