Local and AD identity#
Local and AD login paths exist. AD authentication uses a configured provider/PowerShell worker and maps canonical directory identity to an AD-source user. Successful first login may provision a user, but automatic role assignment is not verified.
The native ad module exposes read-only directory tools. Authentication and directory tools are separate surfaces; creating a YAADMIN user does not create or modify an AD account.
User lifecycle#
Administrators can create, update, delete, enable/disable users and replace role assignments. A user record includes id, username, display_name, source, is_active and timestamps.
The administration layer prevents deleting the acting account or removing/deactivating the last active local recovery administrator. The verified system role is ControlHub Administrators.
Owner-scoped state#
Chat history/folders, snippets/quick commands, UI language and personal preferences are owner-scoped. Codex preferences/thread bindings and personal MCP credentials use the YAADMIN user ID. Administrator-managed per-user RAG profiles/documents are also represented in the UI/API.
Language and personal connections#
Users can store English, Ukrainian or Russian interface preferences. Personal MCP connections apply only to administrator-defined HTTP profiles configured as per_user; users do not own independent server profiles.
Current implementation notes#
AD unavailability is distinguished from invalid credentials; local recovery remains available. No invitation-email, self-service registration, AD write/offboarding tool or automatic AD group-to-role synchronization is verified.
See Users / Identity API and Roles & Permissions.