AverQel OS
Technical Guidebook

Admin

Admin is for platform operation, security, support, and compliance handling. It is not a normal user role.

Who Can Be Admin

Admin access is controlled by configured allowlisted admin emails and roles. Normal users and editors cannot enter admin routes.

What Admin Can See

User metadata, role/status, 2FA state, usage counts, audit/security events, document processing counts, and deletion records.

What Admin Should Not See By Default

Document text, chat prompts, generated answers, provider API keys, OAuth tokens, or private endpoint secrets.

Sensitive Actions

Disable/reactivate users, force logout, terminate accounts, run deletion workflows, and any exceptional privileged actions must be audited.

Admin Privacy Rule

The admin dashboard is metadata-first. Admin exists to operate the SaaS safely, not to browse user content. User deletion and account control can happen without exposing raw provider secrets or normal private content in the admin UI.

That boundary matters in production because the operational team needs visibility into system health, not user payloads. The audit trail is the source of truth for sensitive actions.