Administration
Administration
The Admin console for site administrators (users, projects, organizations, usage, audit log, invitations) and Organization Settings for org admins.
On this page
Holarch has two administrator roles. Site admins run the whole service from the Admin page: they manage every account, project and organization, invite people, and review storage, AI use and the audit log. Org admins manage one organization (a class or a team) from Organization Settings: its members, its AI keys and whether AI may be used in its projects.
Neither role gives access to project content. Administrators see names, members, sizes and dates; to open a project, an owner has to share it with them.
Concepts
| Term | Meaning |
|---|---|
| Site admin | An account with access to the Admin page. Holarch always keeps at least one active site admin. |
| Organization | A group of accounts for a class or a team. It can hold organization AI keys and an AI on/off setting. Membership gives no access to projects. |
| Org admin | A member who manages an organization's members, invitations, AI keys and AI setting. An organization keeps at least one org admin. |
| Member | A member of an organization. Members without their own AI key use the organization's key. |
| Project of an organization | A project whose owner chose the organization under Share → Organization. The organization's AI setting applies to it. |
| Password check | Before the first administrative change, Holarch asks for your password. The check lasts 10 minutes. |
| Grace period | A deleted account can be restored for 30 days, then it is removed for good. |
| Audit log | A record of sign-ins, account and sharing changes, administration and system events. |
How to use it
When and why
Administration sits outside the systems engineering lifecycle. Use it to:
- set up the people who work in Holarch before a project or a class starts (invitations, organizations, org admins);
- keep AI under control for a class or a team (organization keys, the AI switch, usage by member);
- respond to requests: a forgotten password, a person who left, a project whose only owner is gone, an erasure request;
- check the health of the service (storage against the limit, AI tokens this month, the running version) and investigate events in the audit log.
Open the Admin page
- Click your initials at the right of the top bar.
- Choose Admin (site admins) or Organization Settings (org admins). Result: the page opens with the tabs Users, Projects, Organizations, Usage, Audit and Invitations (site admins) or only your organizations (org admins).
You can also press ⌘K and type Admin. Site admins get Admin, Admin: Users, Admin: Projects, Admin: Organizations, Admin: Audit Log and Invite People…; org admins get Organization Settings. Site admins also find Invite People and Open Admin under Administration on the Account page.
Invite a new person
Sign-up is by invitation.
- Open Admin → Invitations.
- Enter the email address under Invite people. Tick Site admin to make the person a site admin when the account is created.
- Click Send Invitation. Result: “Invitation sent to …”. The person gets an email with a link to create an account. The link is valid for 7 days. The invitation appears in the list below with its expiry date.
To give someone a project, use Share in that project instead. To add someone to an organization, use the organization's Members list; people without an account get an invitation that adds them when they sign up.
Set up a class or a team
- Open Admin → Organizations and click New Organization….
- Enter the Name (for example SYSE 682 Fall 2026). Under Org admin (email of an existing account), enter the instructor's or team lead's email, or leave it empty to administer the organization yourself.
- Click Create. Result: “Organization “…” created.” and the organization's details open in the inspector.
- Under Members, enter each email address, choose Member or Org admin, and click Add Member. Result: an existing account is added at once (“… added.”). Any other address gets an invitation (“Invitation sent to …. They join when they create their account.”) listed under Pending invitations.
- Decide on AI: leave Allow AI in this organization's projects ticked, or clear it to turn AI off (see below).
- Ask the org admin to add an organization AI key on the Account page under Organizations → Organization keys, if members should use AI without their own keys.
- Ask each project owner to choose the organization in the project's Share dialog under Organization.
Tip: Any signed-in person can also create an organization on the Account page with Create Organization; they become its org admin.
Turn AI off for an organization
- Open the organization (site admins: Admin → Organizations, then the row; org admins: Organization Settings, then the row).
- Clear Allow AI in this organization's projects.
- Confirm Turn AI Off in the dialog. Result: “AI turned off for ….” Every AI request for the organization's projects is refused on the server, also with a member's own key, and the organization's keys are not used. In those projects the ✦ AI control is off and shows “AI is turned off for this organization by its administrator.”
Tick the box again to turn AI back on (“AI turned on for ….”).
Help a person who cannot sign in
- Open Admin → Users and type part of the name or email in Search name or email.
- Click the row. The details open in the inspector.
- Check Status and Email verified:
- Disabled: click Enable to let the person sign in again.
- Email verified: No: click Resend Verification.
- Forgotten password: click Send Password Reset and confirm. The link goes to the person's email address, works once and is valid for 1 hour. Administrators never see or set passwords.
A person leaves
- Open the person in Admin → Users.
- Click Delete User….
- For each project the person owns alone, choose Move to the Trash or Transfer to… and enter the email of the new owner.
- Type the person's email address to confirm, then click Delete User. Result: “User deleted. The account is purged on ….” The person is signed out at once and cannot sign in. Shared projects keep their other owners and members. The account can be restored for 30 days with Restore Account; it comes back disabled.
To stop someone temporarily instead, use Disable…: sessions end, projects and data stay.
Give an orphaned project a new owner
- Open Admin → Projects and search for the project by name or id, or filter by person.
- Click the row, then Transfer Ownership….
- Enter the New owner and choose what the Current owners afterwards become: Editor, Viewer, Owner (keep) or No access.
- Click Transfer. Result: “… is now an owner of “…”.” The new owner is added to the project if they were not a member.
Worked example: a class using the CubeSat EO-1 demo
An instructor runs a systems engineering class in which each team builds on the CubeSat EO-1 demo project.
- The site admin invites the instructor from Admin → Invitations and creates the organization EO-1 Design Class with the instructor as Org admin.
- The instructor opens Organization Settings, adds the students' email addresses as Member, and adds an Anthropic key under Account Settings → Organizations → Organization keys with a Monthly limit (tokens) of 2,000,000.
- Each team lead creates the demo (Manage Projects → Project Files ▾ → Create Demo Project), shares it with the team, and chooses EO-1 Design Class under Share → Organization.
- Students without their own key now use the organization key, for example to run Make Measurable… on requirement 2.5 Safe Mode Recovery. The instructor sees the requests under Usage this month by member.
- Before the exam, the instructor clears Allow AI in this organization's projects. AI requests in the class projects are refused until it is ticked again.
- The site admin checks Admin → Usage for AI tokens this month and File storage, and filters Admin → Projects by Organization to see every class project with its size and last activity.
Tips and common mistakes
- Membership is not access. Adding a person to an organization does not share any project with them. Share projects separately.
- Projects join an organization from the Share dialog. Admins cannot attach a project to an organization; a project owner chooses it under Share → Organization.
- Keep two site admins. Holarch refuses to remove, disable or delete the last active site admin. Make a second account a site admin first.
- Transfer before deleting. Projects that the person owns alone go to the Trash unless you transfer them in the delete dialog.
- Use Delete Permanently Now only for erasure requests and abuse. It skips the 30-day grace period and cannot be undone.
- Change your own account on the Account page. The Admin page does not offer Disable or Delete for yourself.
How it connects to other features
- Collaboration covers project sharing and roles (Owner, Editor, Viewer), which are separate from site and org administration.
- AI explains organization keys, which key is used, usage and the effect of the organization AI switch.
- Your account covers sign-in, verification and password reset from the person's side.
- Storage and limits explains the storage figures shown on the Usage tab.
The Admin page
The page header shows Admin and the running release (Holarch <version> · <build>). The tabs are links (#/admin/users, #/admin/projects, #/admin/orgs, #/admin/usage, #/admin/audit, #/admin/invites). Lists are loaded page by page from the server, 50 rows at a time, with ‹ Previous and Next › and a count such as 1–50 of 312. Click a row, or focus it and press Enter, to show its details in the inspector.
People who are neither site admins nor org admins see “This page is for administrators.” with “Ask a site administrator for access.”
Users tab
Filters
| Control | Options |
|---|---|
| Search name or email | Matches part of the name or email. |
| Status | Active and disabled (default), Active, Disabled, Deleted (grace period), All |
| Site admin | Site admin or not, Site admins, Not site admins |
| Email verified | Verified or not, Verified, Not verified |
| Sort | Newest first, Last sign-in, Storage used, Most projects, Name |
Columns
Name, Email, Status (Active, Disabled, Deleted), Site admin, Verified (Yes, or a No chip), Created, Last sign-in (or Never), Projects (n owned · n member), Storage and AI tokens (month).
When nothing matches: “No users match.” with “Change the search or the filters.”
User details (inspector)
Facts: Status, Site admin, Email verified, Created, Last sign-in, Signed-in devices, Projects (owned and as member), Storage (project data and files), AI tokens this month, Organizations (with the role in each), Data restriction confirmed (the date the person accepted the data policy, or No), and for deleted accounts Deleted and Purged on.
Below the actions, Projects this person owns alone lists those projects with their member counts; each name opens the project in the Projects tab.
User actions
| Action | What it does | Confirmation |
|---|---|---|
| View Projects | Opens the Projects tab filtered to this person (any role). | None |
| Rename… | Changes the account name. | Rename User with a Name field. Toast: “Name changed.” |
| Make Site Admin… | Gives access to the Admin page and to invitations. | “… can manage every account, project and organization, and invite people.” Toast: “… is now a site admin.” |
| Remove Site Admin… | Removes that access. | “… loses access to the Admin page and can no longer invite people.” Toast: “… is not a site admin now.” |
| Disable… | Ends every session and blocks sign-in. Projects and other data stay. Not offered for your own account. | Disable Account: “… is signed out on every device and cannot sign in. Projects and other data stay.” Toast: “Account disabled. n sessions ended.” |
| Enable | Allows sign-in again. | Toast: “Account enabled.” |
| Sign Out Everywhere | Ends every session; the person can sign in again. | “Every session of … ends. They can sign in again.” Toast: “Ended n sessions.” |
| Send Password Reset | Emails a link to choose a new password (active accounts). | “A link to choose a new password goes to …. It works once, for 1 hour.” Toast: “Reset link sent.” |
| Resend Verification | Emails a new verification link (active, unverified accounts). | Toast: “Verification link sent.” |
| Delete User… | Deletes the account with a 30-day grace period. Not offered for your own account. | See below. |
| Restore Account | For an account in its grace period. | Toast: “Account restored and disabled. Enable it to allow sign-in.” |
| Delete Permanently Now… / Purge Now… | Under Danger zone: deletes at once, without the grace period. Purge Now… is the label for an account already in its grace period. | See below. |
A disabled person who tries to sign in sees “This account is disabled. Contact the administrator.”
Delete User
The Delete User dialog says: “… is signed out and cannot sign in. The account is deleted for good after 30 days; until then it can be restored. Shared projects keep their other owners and members.”
- Projects this person owns alone. For each project (with its member count), choose Move to the Trash or Transfer to…, which shows an Email of the new owner field. When there are none: “This person owns no projects alone.”
- Type <email> to confirm. Delete User stays off until the address matches.
Toast: “User deleted. The account is purged on <date>.”
Delete User Permanently
For erasure requests and abuse. The Danger zone says: “For erasure requests and abuse. Deletes the account and the data you choose at once, without the 30-day grace period.”
The dialog states: “This cannot be undone. The account of … is deleted now, together with: their sessions and sign-in links, their memberships in projects and organizations, pending invitations they sent or received, their AI keys and their clipart library.” and “Projects chosen for deletion and their attachments are deleted for good. Kept: AI usage records without a link to the person, the audit log (with the person's id and name), and backups until they expire within 30 days. The email address can be invited again.”
- For each project the person owns alone, choose Delete permanently or Transfer to….
- Projects of the person that are already in the Trash are listed as “Also deleted for good from the Trash: …”.
- For each organization the person administers alone, enter the Email of the new administrator.
- Type the email address to confirm and click Delete Permanently.
Toast: “User deleted permanently.”
Projects tab
Filters
| Control | Options |
|---|---|
| Search name or id | Part of the name, or the project id. |
| Filter by person (email) | Suggests matching accounts as you type. The chosen person appears as a chip (Member: … or Owner: …); × clears it. An unknown address shows “No account has the email “…”.” |
| Person's role | Any role or Owner. |
| Organization | Any organization or one organization (the first 200 by name). |
| Status | Active, In the Trash, Active and Trash |
| Size (MB) | Min – Max |
| Last activity | From – to dates |
| Sort | Last activity, Size, Name |
| Clear Filters | Resets every filter. |
View Projects in a user's details and Show All Projects in an organization's details open this tab with the filter set.
Columns
Name, Owner, Members, Organization, Size (project data), Files (attachments), Last activity, Status (Active or In the Trash).
When nothing matches: “No projects match.” with “Change the search or the filters.” (or “This person has no projects that match the filters.”).
Project details and actions
Facts: Status (Active, or In the Trash since …), Owner, Members, Organization, Project data, Files, Items, Created, Last activity, Pending invitations, and the Members list with each role. The note says: “Site admins see project metadata only. To open the content, an owner has to share the project with you.”
| Action | What it does |
|---|---|
| Transfer Ownership… | Makes another active account an owner (see the workflow above). |
| Restore from Trash | For a project in the Trash. Toast: “Project restored from the Trash.” |
| Delete Permanently… | For a project in the Trash. “… its earlier versions and its attachments are deleted for good. This cannot be undone.” Type the project id to confirm. Toast: “Project deleted permanently.” |
Organizations tab
Site admins
Search organizations filters the list; New Organization… creates one. Columns: Name, Members, Org admins, Projects, AI keys, AI (On or Off), AI tokens (month), Created. With none: “No organizations.” and “Create one for a class or a team with New Organization.”
The New Organization dialog: “An organization groups people for a class or a team. Its org admins manage members, organization AI keys and whether AI may be used in its projects.” Fields: Name (up to 100 characters) and Org admin (email of an existing account) (“Leave empty to administer it yourself”).
Organization details
| Part | Contents |
|---|---|
| Header | Name, and n members · n projects · n AI keys |
| AI | Allow AI in this organization's projects. When on: “On. Members use their own AI keys or the organization's keys. A project belongs to the organization when its owner chooses it under Share → Organization.” When off: “Off. AI is turned off for this organization by its administrator: AI requests for its projects are refused, also with members' own keys.” |
| Members | Each member with a role list (Member, Org admin) and Remove. Below: an email field, a role list and Add Member. |
| Pending invitations | Email, role and expiry, with Revoke (“Invitation revoked.”). |
| AI use this month | Site admins: Requests, Tokens, Cost (estimate). |
| Projects | Site admins: up to 10 projects, then Show All Projects. With none: “No project belongs to this organization.” |
Remove asks “Remove … from …? They lose the organization's AI keys. Project access does not change.” Changing a role shows “… is now Member.” or “… is now Org admin.”
Organization Settings (org admins)
Org admins who are not site admins see the same page titled Organization Settings, with only their organizations: “Organizations you administer. Turn AI on or off for their projects, and manage members.” Columns: Name, Your role, AI. The details offer the AI switch, Members, Add Member and Pending invitations as above. “Org admins manage this organization's members, invitations and AI setting. They have no access to other organizations or to site administration.”
Organization keys and usage by member are on the Account page under Organizations: Organization keys (add, test, remove), Members and Usage this month by member (Member, Requests, Tokens, Cost (estimate), with a total). See AI.
Usage tab
| Tile | Shows |
|---|---|
| File storage | Stored attachments against the server limit, with the number of files and a meter (amber from 80 %), or “no server limit set”. |
| Project data | The size of the projects themselves, and the Per-person file limit when one is set. |
| Accounts | Active accounts, with disabled, deleted and site admin counts. |
| Projects | Active projects and those in the Trash. |
| AI tokens this month | Tokens and requests, the estimated cost, and the per-person monthly limit when set. |
| Server version | The running release, its build, the database migration level and the build time. |
Below the tiles, Most storage and Most AI tokens this month list the top accounts (click a row for the user's details). The note says: “File storage counts each stored file once. Project data is the size of the projects themselves. Costs are estimates from list prices; providers bill the key owners.”
Audit tab
The audit log lists events newest first, 50 per page, with ‹ Newer and Older ›.
Filters: Filter by person (email), Action and the From and To dates (both inclusive).
| Action filter | Covers |
|---|---|
| All actions | Everything |
| Sign-in and sessions | Sign-ins, sign-outs, password resets, email verification, ended sessions |
| Accounts | Account creation, data policy acceptance, email and password changes, account deletion |
| Administration | Every action on the Admin page (user, project, organization and invitation changes) |
| Projects and sharing | Invitations, role changes, transfers, leaving, organization changes, project deletion |
| Organizations | Organization creation and renaming, members, roles, invitations, the AI setting |
| AI keys | Keys added, changed and removed |
| System | Scheduled clean-ups (Trash and deleted accounts) |
| Contact form | Messages sent through the contact form |
Columns: Time, Action (an action code such as admin.user-disable), By (email, or System), Target, Project, Address, Browser, Details. With no results: “No events match.” and “Change the filters.”
Invitations tab
“Sign-up is by invitation. The invited person gets a link to create an account (valid 7 days). To give someone a project, use Share in that project instead; to add someone to an organization, use its Members list.”
- Email address, Site admin and Send Invitation. An empty address shows “Enter an email address.”
- The list of pending account invitations shows each address, administrator for site-admin invitations, who sent it and the expiry date. Revoke asks “The link sent to … stops working.” and shows “Invitation revoked.” With none: “No pending account invitations.”
Shortcuts
| Keys | Action |
|---|---|
| ⌘K then Admin | Admin, Admin: Users, Admin: Projects, Admin: Organizations, Admin: Audit Log, Invite People… |
| ⌘K then Organization | Organization Settings (org admins) |
| Enter on a focused row | Show its details in the inspector |
| Esc | Hide the inspector |
Messages
| Message | Meaning and fix |
|---|---|
| Confirm Your Password dialog | The server needs a recent password check before an administrative change. Enter your password; the check lasts 10 minutes. “The password is wrong. Try again.” means the password did not match. |
| “Holarch needs at least one active site administrator. Make someone else an administrator first.” | You tried to remove, disable or delete the last active site admin. |
| “Change your own account on the Account page.” | The Admin page does not change your own account. |
| “This account is deleted. Restore it first.” | Restore the account before changing it. |
| “This account is not active. Enable it first.” | Password reset and verification need an active account. |
| “This email address is already verified.” | No verification link is needed. |
| “No other active account has the email “…”. Enter the new owner of “…”.” | The transfer target in the delete dialog is unknown, inactive or the person being deleted. |
| “No active account has the email “…”.” | The new owner in Transfer Ownership is unknown or inactive. |
| “Choose for each project this person owns alone: transfer it or delete it.” | A sole-owned project has no choice. |
| “Choose a new administrator for each organization this person administers alone.” | Permanent deletion needs a replacement org admin. |
| “Type the account's email address to confirm.” / “Type the project id to confirm.” | The confirmation text does not match. |
| “Move the project to the Trash first.” | Only projects in the Trash can be deleted permanently. |
| “This project is not in the Trash.” | Restore from Trash applies only to projects in the Trash. |
| “No active account has this email address. Invite the person first.” | The org admin for a new organization must have an account. |
| “This person is already a member of the organization.” | No change needed. |
| “An organization needs at least one administrator.” | Make another member Org admin before changing or removing the last one. |
| “Only an administrator of this organization can do this.” | You are a member, not an org admin, of this organization. |
| “Use dates as YYYY-MM-DD.” | A date filter is not valid. |
| “This tab could not be shown. Reload the page.” | The tab failed to load. Reload the page. |
Limits
- Lists load 50 rows per page; the Organization filter lists the first 200 organizations by name.
- The password check lasts 10 minutes per session.
- Account invitations are valid for 7 days; password reset links for 1 hour.
- Deleted accounts can be restored for 30 days.
- Backups expire within 30 days. The audit log is kept for 400 days.
- Organization names are up to 100 characters.
Related pages
Last updated October 7, 2026