App Admin
The App Admin role (app_admin) manages the application for its people:
users, teams, and keys — without touching the platform-level settings
(providers, policies, billing, agent sessions), which stay with the
Logos Admin. On the identity provider, an account becomes
an App Admin when it carries the OIDC role configured in
KEYCLOAK_ROLES_APP_ADMIN (see the
installation guide).
The UI shows the role badge "App Admin" in the header menu.
Models
The deployment's model catalogue: name, description, and capabilities. App Admins see the list but not the per-model operator controls (weights, aliases, add/delete).

Users
The users of the deployment: their role, teams, and status. An App Admin can create users and assign them to teams — but can only create App Developers, never higher roles.

Teams
Teams, their owners, and members. App Admins can create teams, add members, and manage the team's API keys — for the teams they own.

Opening a team opens its detail view. Owners (and Logos Admins) get the full tab set below; other members only see Overview and Members.
Overview
Headcount, active keys, permitted models, member budget usage, and the defaults applied when a key or member has no individual limit.

Members
Owners and members, with per-person budget and rate-limit overrides. Add or remove people here (unless the team is Keycloak-managed).

Application Keys
Application (service) keys that belong to the team — create, rotate, revoke, and set per-key limits / model permissions.

Models
Which catalogue models this team may use.

Activity
Live queue state for the team, recent request log, token totals, and export.

Cloud Usage
What cloud providers charged for this team's off-site traffic (local models do not appear here — see Activity for that).

Settings
Team monthly budget, default key budget, and default cloud/local rate limits. Also where an owner deletes the team.

My Workspace
The developer-facing view of the signed-in user: their teams, their API keys (create, rotate, revoke), and per-key model permissions. Available to every role that has at least one team and key.

AI Tools
Same guided setup as for every other role — pick a coding assistant, team key, and model, then install and connect. The page does not change with the role; see the step-by-step walkthrough under App Developer → AI Tools.
Batches
The OpenAI Batch API in the browser: upload a .jsonl file, watch the job's
progress, download the result file. See batch processing
for what happens server-side. The page is the same for every role that can
open it (App Admin and Logos Admin).
