PackagesadminMenu

@intelligo-dev/admin

The operational console: cross-tenant queries, health probes and impersonation.

Install

Terminal
pnpm add @intelligo-dev/admin drizzle-orm react

drizzle-orm and react (19 or later) are peers. intelligo add admin-page from @intelligo-dev/cli generates the mount below as source the application owns.

Use

TSX
// app/[locale]/admin/page.tsx
import {
  getPlatformOverview,
  listUnsettledExecutions,
  listWorkspaces,
  requireAdmin,
} from "@intelligo-dev/admin";
import { PlatformOverviewView } from "@intelligo-dev/admin/views";

export default async function AdminPage() {
  await requireAdmin("admin.overview.viewed");

  const [overview, workspaces, unsettled] = await Promise.all([
    getPlatformOverview(),
    listWorkspaces(20),
    listUnsettledExecutions(),
  ]);

  return (
    <PlatformOverviewView
      overview={overview}
      workspaces={workspaces}
      unsettled={unsettled}
    />
  );
}

The console is Intelligo-owned rather than consumer-owned source, and deliberately excluded from the page registry: what an operator can see across every tenant is not a per-product decision, and a fork could quietly stop showing unsettled executions. The application owns the route and the page chrome around the views.

The gate

Every query sits behind requireAdmin(action, resource?), which checks the platform admin role — users.role, a row rather than an environment variable, and never a workspace role: every signup owns a workspace. Each call writes an audit event with actorKind: "support", so looking is on the record too.

requireAdminOrRefuse is the gate for anything destructive: it refuses the action when the audit event cannot be written. Reading a customer’s data unrecorded is bad; acting as them unrecorded leaves no answer to “who did this”.

Impersonation

startImpersonation({ targetUserId, reason }) swaps the caller’s session for the target’s. The reason is mandatory and recorded, the audit write is part of the contract, and another platform admin cannot be impersonated. stopImpersonation({ targetUserId }) ends it and records the end first, so the trail does not depend on the happy path completing.

Health probes

getIntegrationHealth() reports the database, the job queue and execution settlement as ok, degraded, down or unconfigured, each with one line saying what to do about it. A product adds its own from the composition root:

TypeScript
import { registerIntegrationProbe } from "@intelligo-dev/admin/health";

registerIntegrationProbe({
  key: "search",
  label: "Search index",
  check: async () => ({ status: "ok", detail: "Reachable" }),
});

Entry points

  • @intelligo-dev/admin
  • @intelligo-dev/admin/views
  • @intelligo-dev/admin/health

npm · source