Operating the admin console
Kill switches, threat blocklist, abuse queue, account powers, audit exports, and margin guardrails.
Last updated · September 2026
On this page
The admin console (/admin) is the incident-response surface: pause the platform, cut off threats, review abuse, act on accounts, and hand evidence over — every action audited with the acting admin attached.
Kill switches
- Maintenance mode (Platform tab) pauses all inference with a 503; sign-in and billing stay up. The Command center raises a critical alert while it is on, so it cannot be forgotten.
- Signup gate freezes new accounts during an abuse wave. Both take effect within 30 seconds on every instance.
Threat blocklist
Security tab → Threat blocklist: add a hostile host and it is refused across the prompt guard, tool layer, and recon within a minute — no code change, no redeploy. Entries are bare domains; wildcards and fragments are rejected.
Abuse queue
Refused prompts, blocked targets, and stacked high-misuse scores file review cases automatically (one per account per day, not a flood). Each case is one decision: dismiss it, or suspend the account and revoke every session it holds.
Account powers
- Users tab: suspend/reactivate, grant/revoke admin, adjust token balances with a reason, revoke one or all sessions, reset two-factor authentication (with a written reason).
- Prompt audit tab: every AI run with its target, cost, and misuse score; open a record to read the encrypted prompt and output (each opening is itself audited); export filtered records as a JSON evidence bundle for lawful disclosure.
- Economics tab: collected revenue, provider cost, net margin, per-user and per-package unit economics with break-even rates, plus Command-center alerts when a package sells below target or at a loss.

