Administrator guide

For the people who set up, connect and run the deployment.

Setup and access

Create the first administrator, invite and manage people, and assign abilities and Teams.

  • First-run setupFind the one-time setup token on a fresh deployment and use it to create the first administrator.
  • Inviting peopleInvite teammates from Settings, choose their abilities, and share the setup link by email or by hand.
  • AbilitiesWhat each ability allows, how the Team page assigns them, and how Admin relates to the others.
  • Managing peopleChange abilities, revoke and reactivate access, resend invites, delete people, and allow password sign-in.
  • TeamsCreate Teams, manage their members, and understand what a Team limits.

Sign-in and SSO

Set up single sign-on and see how the sign-in page chooses between it and a password.

  • Set up single sign-onConnect your identity provider with OpenID Connect, verify your domain, and register the redirect URI.
  • How sign-in chooses a methodHow the sign-in page decides between a password and your company's single sign-on, and how to exempt a person.

AI providers

Connect model providers, manage their keys, and set the default models.

  • Adding a model providerConnect Workforce Intelligence to a model provider such as Anthropic, OpenAI, Ollama or any OpenAI-compatible endpoint, and edit it later.
  • Provider keys and how they are storedAdd, replace or remove a provider's API key, and what protects stored keys, including why you must keep the master key.
  • Testing, activating and removing a providerCheck that a provider is reachable, bring a keyless provider back online, and remove a provider you no longer use.
  • Default modelsSet the company default chat model and the default embeddings model, and what each one is used for.

Company settings

Change the company name, configure outgoing email, and export the company archive.

  • Company nameWhere to find the Company settings page and how to change your company's name.
  • Outgoing emailConfigure the SMTP server the product uses to send invitations, test it, and what to do when email is not set up.
  • Exporting the company archiveDownload all Coworkers, knowledge bases and conversations as a single portable ZIP archive.

Keys

Create and revoke API keys, and register and review SSH keys.

  • API keysCreate and revoke personal API keys, and issue Coworker and App keys from the company-wide list.
  • SSH keysRegister the public key people use to push App code, and review every registered key as an administrator.

Deployment and install

Install on AWS or your own server, set up HTTPS, and run and back up a deployment.

  • Deployment requirementsWhat you need before installing Workforce Intelligence: a box, open ports, a GitHub token for the image registry, and a public address.
  • Install on AWS with CloudFormationProvision a Workforce Intelligence box with the CloudFormation template: parameters, access over Session Manager, outputs, generated secrets, and data protection.
  • Install on your own serverInstall Workforce Intelligence on a Linux server you manage, using install.sh and an .env file you prepare.
  • First-run setup tokenFind the one-time setup token that the setup wizard asks for on a new installation.
  • Configuration referenceEvery environment variable an operator sets for a production deployment, which are required, and which are fixed by the compose file.
  • Domains and automatic HTTPSServe Workforce Intelligence on your own domain with a certificate that Caddy obtains and renews for you.
  • Day-two operationsCheck status, stop, start, restart, and pull images on a running deployment with Docker Compose.
  • Containers and volumesThe containers and Docker volumes that make up a Workforce Intelligence deployment, and what each one holds.
  • Master key custodyWI_MASTER_KEY encrypts every stored provider key. It is generated once, cannot be regenerated, and must be backed up off the box.
  • Backups and recovery on AWSHow the CloudFormation deployment protects its root volume, how to check the backups, how to recover a lost instance, and what to arrange on your own server.
  • Production boot checksThe configuration problems that make the application refuse to start in production, and how to fix each one.

Updates

Check for and install updates, and see how an update runs and what to do if one fails.

  • Checking for and installing updatesUse Settings → Updates to see the running version, check the registry for a newer one, and install it with a guarded, backed-up switchover.
  • What an update changesAn in-app update replaces only the app and web images. When a release changes the stack itself, re-run install.sh first, and what you see if you skip that.
  • How an update runsThe ordered steps of a guarded install: database backup, image pull by digest, a new app container beside the old one, a health check, then the switchover.
  • When an update failsWhat a failed install looks like, what state your deployment is left in, and what is kept for inspection.
  • Registry credentials for updatesHow the in-app updater authenticates to ghcr.io, and what to do when the token expires or the registry refuses it.

Usage and cost

Read company-wide model usage and spend, and see how cost is calculated.

  • The Usage & cost viewRead company-wide model usage and spend by Coworker, knowledge base, system job and team, for any month or custom date range.
  • How cost is calculatedWhere the cost figures come from, why some models show a cost of zero, and what that means for self-hosted models.

Infrastructure

Check the status of the Agent VM and the disk usage of the data volume.

  • Agent VM statusRead-only view of the sandbox where Coworkers run their tools, plus disk usage of the data volume.