13 Commits
Author SHA1 Message Date
arc53-machine 4b08e94be7 Name every person on agent pages by one rule
people_named_to decides whom the edit page and the share dialog name:
the reader, the holder's owner, anyone sharing a team with the reader and,
for the owner, whoever sponsored something on the holder. A resource's
owner, named as whom to ask or whose credentials a tool uses, also needs
the reader to see that resource. Sponsors, runs_as, contact and account
in resource_states and sponsors in sponsor_details all follow it; anyone
else is left unnamed and the pages say someone else.

A tool's run details (note, credential_mode, account, writes) come from
one function and only for a tool that runs. The share dialog keys each
person's own account on the per_user_account note, as the notice does,
and the unused noteKey helper and its string are gone.
2026-09-29 18:12:54 +01:00
arc53-machine d04f76e97a Say which resources are left out of runs and which can't run until fixed 2026-09-29 17:52:12 +01:00
arc53-machine db9eb2b1c3 Correct what the agent sharing docs say about accounts, sponsors and switches
The table adds tools with saved credentials, says API and widget users
get the owner's account on a tool each person connects, that a sponsored
item runs as the owner again once the owner can use it, and that a
teammate's name shows only to people who share a team with them. The
editor switches are named per resource type, public-link users are said
to be asked only for writes that need approval, the allowlist is said to
cover sponsored and workflow node tools, and the badge names and the new
resource_states fields match the app.
2026-09-29 17:50:42 +01:00
arc53-machine da75845fcf Document sharing agents and whose access what they use runs with
A new "Sharing agents and what they use" section covers viewers and
editors, whose access each tool, source and prompt runs with as the share
dialog labels it, sponsors, stopped resources, what API, widget and
public-link users can't do without the write allowlist, the wiki switch
and research steps. The sharing rules now mention the editor switches and
member-mode tools, the guardrails page no longer says editors can't
change guardrails, the connector guide uses the new tool share labels,
and related pages link to the section.
2026-09-29 17:35:17 +01:00
arc53-machine 9775dd1af9 Document what happens when an agent's resource stops working 2026-09-29 17:17:13 +01:00
arc53-machine 90b385e9ea Document taking over stopped resources and how the agent's audience can grow 2026-09-29 16:55:00 +01:00
arc53-machine ff10fcca0f Say the wiki switch covers API keys and widgets, not public links
Public-link visitors edit only wikis they can edit themselves and approve
each edit. The docs also note that with authentication off every caller
is the owner's local user, so the switch has no effect there.
2026-09-29 16:37:58 +01:00
arc53-machine c66afd6b30 Document who may sponsor a resource in someone else's agent 2026-09-29 16:34:53 +01:00
arc53-machine d4b30f4838 Document who can edit a wiki from the API, widget and public links 2026-09-29 16:12:42 +01:00
arc53-machine 25c82003d7 fix(admin): second review pass
Correctness
- /api/remote never recorded source.created, so URL, GitHub and connector
  sources had a source.deleted with no matching creation. All three creation
  paths now go through one _audit_source_created helper.
- The prompt-cache rate divided cached tokens by a whole bucket's prompt
  tokens. A bucket is a day and mixes calls whose provider reports a cache
  breakdown with calls whose provider does not, so filtering buckets in the
  client could not separate them and the rate was understated by however much
  traffic ran on a non-reporting provider. The denominator is now computed in
  SQL over the reporting rows.
- The outcome pill matched values nothing writes. Guardrails emit triggered /
  not_evaluated and the device feed emits dispatched; the map had blocked /
  denied / allowed, so a guardrail that fired rendered neutral grey -- the one
  signal the merged feed exists to surface. Fixtures were seeding the
  fictional values, so the tests passed on it too.
- Stream duration_ms timed the consumer. stream_token_usage is a generator,
  so start-to-exhaustion includes the agent loop's tool handling and the SSE
  client's pace; a slow browser recorded ~30s for a sub-second call. It now
  accumulates only the time spent inside next().

Safety
- Activity filters failed open: an unknown facet or unparseable timestamp was
  dropped, and no filter means every row, so a typo widened an audit view and
  on the export streamed the full history. Both are now a 400.
- The search term was interpolated into an ILIKE pattern, so "100%" matched
  everything and "q1_report" matched more than it should. Escaped.
- 0034 set actor_id NOT NULL with no default. A previous-release process
  inserting mid-rollout would raise, and in admin/routes.py that insert shares
  the request transaction, so a role grant beside it would roll back too.

Noise and dead code
- The per-user panel is a security panel: data-plane events file under the
  actor, so an active account's routine deletes pushed a denied login out of
  the 20-row window. It now excludes them; the Activity tab shows everything.
- device_audit_log had no created_at-leading index, so the merged feed
  sequentially scanned that branch every page (migration 0036).
- conversation.deleted_all no longer records when nothing was deleted, and
  agent.updated no longer records an empty field list.
- Dropped by_model from /admin/usage (no consumer; an extra aggregate per page
  load), the duplicate filter surface on AuthEventsRepository that nothing
  called, and the unreachable FLOW_LABELS.schedule entry.
- Type hints on record_event's conn and the remaining unannotated helpers.
2026-09-22 12:47:40 +01:00
arc53-machine f6f8af8cef docs: document the activity feed, actor/target and usage spend
Covers what the previous commits changed: the actor_id / target_id split and
the system actors, the data-plane events, the merged Activity feed and its
export, and the new usage and per-user spend endpoints.

Also corrects "there is no UI for these events yet" in the OIDC login
auditing section, which is no longer true.
2026-09-22 10:35:17 +01:00
Alex 1eacfdd3d0 docs: usage quotas
How the instance default, team allowances and user overrides resolve
(including users in several teams), the quota window, who is charged for
agent traffic, how cost budgets price models and what happens to unpriced
ones, and the admin and user API.
2026-09-21 12:11:38 +01:00
Pavel 5c19d972d2 Docs revamp 2026-06-26 11:56:20 +04:00