Admin portal
Admin portal
What this area does
The admin portal is the management half of the application. It exposes operational screens for dashboard analytics, document types/agents, model types, use case configuration, prompt library management, countries, and activity logging.
Access control
Admin access is gated in src/admin/AdminRoute.jsx. The gate considers:
- legacy Firebase auth state,
- Azure AD/MSAL auth state,
- the role resolved by
resolveEffectiveRole, and canAccessAdminPortal().
If the user is not authenticated, they are redirected to login. If they are authenticated but lack admin access, they are redirected back to the main workspace.
Shell and layout
AdminLayout owns the admin chrome:
- collapsible sidebar,
- top bar,
- tenant branding display,
- theme toggle,
- user menu and logout handling.
The layout is intentionally separate from the workspace shell so the admin portal can maintain its own navigation and branding without polluting the main document-processing workflow.
Major subdomains
Dashboard
src/admin/dashboard/AdminDashboard.jsx and its chart/table components show operational analytics for document processing and model performance.
Document types / agents
src/admin/document_types/DocumentTypes.jsx manages the agent/document-type taxonomy and the related drawer/table flows.
Model types
src/admin/model_type/ModelType.jsx manages model definitions used elsewhere in the workspace.
Use case configuration
src/admin/usecaseconfiguration/UseCaseConfiguration.jsx and CreateUseCaseConfiguration.jsx manage the mapping between prompts, schemas, credentials, drafts, and use cases.
Prompt library
src/admin/availble_prompts/PromptLibrary.jsx is the admin prompt management surface. See Prompt library.
Countries
src/admin/countries/Countries.jsx manages country configuration and is linked to sub-agent logic elsewhere in the app.
Activity log
src/admin/activitylog/ActivityLog.jsx exposes filtered telemetry and audit-style history.
Navigation and entrypoints
The admin navigation is split between the route gate and the shell:
App.jsxmounts the admin route group.AdminRouteauthorizes entry.AdminLayoutrenders the sidebar and page outlet.AdminSidebar.jsxprovides the navigation items and tenant branding.
Invariants
- Admin pages should never be reachable through the main workspace chrome without the gate.
- Admin sections should respect the tenant context exposed by the auth layer.
- Prompt, use case, and document-type changes are operationally significant and should be versioned/validated through their respective services.
Evidence-backed tests
tests/unit/rbac.test.jscovers access rules and role precedence.tests/contract/client.test.jsproves the shared auth/tenant header behavior that admin pages rely on.e2e/tests/workflow/list-agents.spec.js,verify-agent-preflight.spec.js,verify-prompt-preflight.spec.js, andverify-schema-preflight.spec.jsexercise major admin-facing journeys.