Skip to content
YAADMIN
Download

YAADMIN DOCUMENTATION

Users and identity

Local and AD identities, role assignments and owner-scoped state.

PartialSource snapshot · 2026-10-02

Local and AD identity#

Local and AD login paths exist. AD authentication uses a configured provider/PowerShell worker and maps canonical directory identity to an AD-source user. Successful first login may provision a user, but automatic role assignment is not verified.

The native ad module exposes read-only directory tools. Authentication and directory tools are separate surfaces; creating a YAADMIN user does not create or modify an AD account.

User lifecycle#

Administrators can create, update, delete, enable/disable users and replace role assignments. A user record includes id, username, display_name, source, is_active and timestamps.

The administration layer prevents deleting the acting account or removing/deactivating the last active local recovery administrator. The verified system role is ControlHub Administrators.

Owner-scoped state#

Chat history/folders, snippets/quick commands, UI language and personal preferences are owner-scoped. Codex preferences/thread bindings and personal MCP credentials use the YAADMIN user ID. Administrator-managed per-user RAG profiles/documents are also represented in the UI/API.

Language and personal connections#

Users can store English, Ukrainian or Russian interface preferences. Personal MCP connections apply only to administrator-defined HTTP profiles configured as per_user; users do not own independent server profiles.

Current implementation notes#

AD unavailability is distinguished from invalid credentials; local recovery remains available. No invitation-email, self-service registration, AD write/offboarding tool or automatic AD group-to-role synchronization is verified.

See Users / Identity API and Roles & Permissions.

Implementation reference: 2026-10-02. Labels distinguish verified behavior, partial implementation and architectural intent.

Search documentation

Search stays in your browser.