Installation identity#
The web startup path initializes a local installation UUID. Commercial status can report fresh, registration_required or registered. A first-run administrator page exists.
Administrator and identity#
The verified administrator role is ControlHub Administrators. Local administrator recovery is preserved; management prevents removal or disabling of the last active local recovery administrator.
Local and AD authentication paths exist. AD first login can create/link an AD identity, but no automatic role grant is verified. The read-only AD module and the AD authentication provider are separate components.
Choose a language#
Each user can store an English, Ukrainian or Russian UI preference. Personal preferences are owner-scoped rather than a global setting for all users.
HTTPS and certificates#
Local CA/server certificate generation and certificate help/download exist. HTTPS depends on deployment configuration; every launch mode is not automatically HTTPS-only. Follow your administrator's certificate trust process. Do not distribute private keys.
Connect the first provider#
Configure one native module or MCP server, inspect health/discovery, assign a role and run a read operation. Review the exact permission identifier for the tool rather than assuming login is sufficient.
- Authenticate
- Configure a provider
- Verify health
- Assign access
- Ask