Appearance
Administration and DevOps overview
The Administration branch of the Studio Explorer groups the screens that operate a tenant: health and audit views, backups, background jobs, approvals, tenant-wide settings, data loading, and moving a tenant or its customizations between regions and environments. The DevOps branch holds the extension (plugin) manager. This section is the reference for every screen in both branches. It goes deeper than the short overviews in Monitoring and troubleshooting, Job and Scheduler Designer, Testing, Deployment, Versioning and release management and Code extensions.
Where to find it
Studio Explorer: Workspace > Administration and Workspace > DevOps. The definition of both branches is administrationBranch() and devOpsBranch() in frontend/packages/studio-core/src/metadataTree.ts. Each Explorer node opens one screen identified by a page key (the Studio view kind). Every screen also appears in the command palette under Go to.
Screen map
| Explorer path | Page key | Reference |
|---|---|---|
| Administration > Monitoring | monitoring | Monitoring |
| Administration > Logging | audit-log | Logging |
| Administration > Backup | backups | Backup |
| Administration > System Settings | system-settings | System Settings |
| Administration > Jobs | jobs | Jobs |
| Administration > My tasks | task-inbox | My tasks |
| Administration > Notification templates | notification-templates | Notification templates |
| Administration > Data import | data-import | Data import |
| Administration > Branding | branding | Branding |
| Administration > Platform dictionary | platform-dictionary | Platform dictionary |
| Administration > API rate limits | rate-limit-settings | API rate limits |
| Administration > Read replica routing | read-replica-settings | Read replica routing |
| Administration > Tenant migration | tenant-migration | Tenant migration |
| Administration > Environment promotion | environment-promotion | Environment promotion |
| Administration > Test / QA cases | test-cases | Test / QA cases |
| Administration > Chat flows | chat-flows | Chat flows |
| DevOps > Extensions | marketplace | Extensions |
The other DevOps nodes (Source Control, Build, Deployment, Packages) are shown as "coming soon" in the Explorer and are not available in this release.
Key concepts
| Term | Meaning |
|---|---|
| Tenant | One customer organization. Every request carries the tenant in the X-Tenant-Id header and the acting user in X-Actor. All Administration screens operate on the tenant of the current Studio session. |
| Tenant scope | The screen reads or writes only the current tenant's data (audit events, jobs, backups, notification overrides, branding, rate-limit override, test cases, chat flows). |
| Platform scope | The screen shows or changes something shared by all tenants. In this branch only the Operational Config block of Read replica routing is platform-wide. Environment promotion and Tenant migration span tenants or regions but are invoked from a tenant session. |
| Artifact | A versioned, tenant-owned definition with the lifecycle draft, published, deprecated, archived. Test / QA cases and Chat flows are artifacts. See Versioning and release management. |
| Privileged action | An action that is denied unless the actor holds one of the roles STUDIO_STAFF, TENANT_OWNER or TENANT_ADMIN, or has been granted the permission explicitly. Backup and Monitoring (platform numbers) use this gate. |
Permissions at a glance
The screens do not apply a client-side gate except Extensions; the server decides. A denied call surfaces as an error banner on the screen.
| Screen | Resource and action checked by the server | Check type |
|---|---|---|
| Monitoring | admin.monitoring / view (Platform panel); integration.flow / view; communication / view; integration.webhook / view. Jobs numbers: no permission check. | Panels degrade independently: a denied panel reads "Not available to you". |
| Logging | None checked by the audit endpoints. | Open to any caller routed to the tenant. |
| Backup | admin.backup / view (list), admin.backup / manage (back up now, verify) | Privileged action gate |
| System Settings, Branding | branding:tenant-settings / update (write). Read is open. | Permission resolver |
| Jobs | None checked by the job endpoints. | Open to any caller routed to the tenant. |
| My tasks | Candidate approver of the task; workflow:<name> / approve, reject or return | Permission resolver |
| Notification templates | AUTHOR on artifact type notification-template (write). Read is open. | Authoring policy |
| Data import | None checked by the import controller; each row is created through the Entity Engine, which applies the entity's own rules. | Entity rules |
| Platform dictionary | EDIT_TRANSLATIONS on translation (write). Browse is open. | Authoring policy |
| API rate limits | rate-limit:tenant-policy / update (write). Read is open. | Permission resolver |
| Read replica routing | read-replica:tenant-policy / update (write). Operational config endpoints: none checked. | Permission resolver |
| Tenant migration | region:tenant-migration / execute | Permission resolver |
| Environment promotion | AUTHOR on the source tenant, PUBLISH on the target tenant, both for the owner type | Authoring policy |
| Test / QA cases | AUTHOR (create, edit, run), PUBLISH (publish, deprecate, archive, delete) on test_case | Authoring policy |
| Chat flows | AUTHOR / PUBLISH on chat_flow for authoring; starting and replying to a session is not permission-checked | Authoring policy |
| Extensions | INSTALL_PLUGINS on plugin; PUBLISH_PACKAGES on package | Authoring policy; Studio disables the buttons with the reason "Managing plugins is not permitted for your role" |
See Permissions model for how roles map to resources and actions.
Conventions shared by all screens
- Errors from the backend are shown in a banner at the top of the screen. On Logging, Jobs, Environment promotion, Test / QA cases, Chat flows and Data import the banner reads
code: message, where the code is the error code returned by the API; the other screens show the message only. - List endpoints that return grids are paginated:
pageIndex(default 0) andpageSize(default 25, maximum 500). - Before any controller runs, every request that carries
X-Tenant-Idpasses the tenant's API access rules, which can answer 403api-access-denied, 403api-ip-not-allowedor 429api-rate-limit-exceeded. Requests to/api/v1/**also count against the tenant request ceiling described in API rate limits. - All timestamps returned by the API are ISO-8601 instants. The screens render them in the browser locale.
- Audited actions are written to the audit log (see Logging): backups write category
configurationwith actionsbackup.startedandbackup.verified; job operations write categoryjob. - The CLI reaches any endpoint in this section through
erp api get|post|put|delete <path>using the logged-in session; see CLI operations reference. Screen pages list the specific commands.
