Overview
Platform-wide summary and health at a glance.
Service Status
Loading…
Traffic
platform activity — current, past, and where it's coming fromTraffic by country
Activity per day — last 30 days
By tenant
—
Admin sign-ins — last 30 days
Revenue — last 30 days (platform-wide)
New tenants — last 12 months
Most popular tenants
Loading…
Tenants by status
Loading…
Tenants by plan
Loading…
Tenants
Manage tenant accounts, statuses, and per-tenant configuration.
Loading…
Admins & Access
Administrator accounts and role-based permission matrix.
Add administrator
Creates the account with a temporary password and emails the sign-in credentials. Owner-only.
Admins
Loading…
RBAC Matrix
Loading…
Billing
Plans, pricing, and tenant subscription status.
Plans
Loading…
Tenant Billing
Loading…
Stripe / Payments
Platform-level Stripe API keys used for checkout, subscriptions, and webhooks across all tenants.
Loading…
Leave a field blank to keep the existing value.
Webhook setup
Configure this endpoint in the Stripe dashboard:
https://admin.earthbornroots.com/api/stripe/webhook
Events: checkout.session.completed, customer.subscription.*
Reminder: set per-plan Stripe price IDs (in the Plans panel above) so checkout references the right price.
Modules & Pricing
Set the monthly price and availability for each module shown in the public Root System builder on roots-hq.com. Prices are entered in dollars and stored as exact integer cents. Leave the price blank for "Custom".
Loading…
Packages
Curated bundles of modules sold together at a single bundle price. Shown as selectable presets in the public product-builder. Leave the price blank for "Custom".
Loading…
Add-ons
À la carte capabilities tenants can purchase outside their plan. Set an optional "feature key" to tie an add-on to an entitlement checked elsewhere in the app (e.g. feature_live_enabled unlocks the Live module even without plan support).
Loading…
Tenant Usage
Every workspace on one screen: Sage AI spend, billing state, and what each is actually doing. Read-only, and it reads the same usage records each workspace sees, so these figures cannot disagree with theirs.
Overview
Loading…
Sage spend by feature
Loading…
AI markup
Loading…
Metered Billing
Track the real cost of AI/LLM and SMS usage, apply markup or retail rates, and rebill each tenant. All amounts are exact (integer cents).
Loading…
Security
Audit chain integrity, recovery codes, and platform security status.
Audit Chain Integrity
Verify the append-only audit log has not been tampered with.
Recovery Codes
Loading remaining count…
Security Status
Informational — these reflect current platform configuration, not interactive controls.
Active sessions
Loading…
Security overview
Loading…
IP allow / deny
Loading…
SMTP alerts
Loading…
Email alert events
Choose which events send an email notification. High-signal events are enabled by default; routine changes are logged but not emailed.
Loading…
GeoIP & Maps
Platform GeoIP access rules and geographic visualizations.
GeoIP rule coverage
Platform admin surface — admin.roots-hq.comGoverns access to the platform admin console (the site you're on now) — not any tenant's own site. Red = blocked, green = allow-listed, grey = default allow.
Loading map…
GeoIP — platform admin
These rules govern access to the platform admin surface only (this console). They do not affect any tenant's own site.
Loading…
Audit Log
Recent platform events and tamper-evident chain verification.
Recent Audit Events
Loading…
System Health
Live server resource metrics for this host, plus email-alert thresholds.
Server resources
Loading…
Email alert settings
When a metric crosses its threshold, the recipients below are emailed (per-metric cooldown avoids repeats). Owner-only.
Loading…
Domain health
Live DNS / HTTPS reachability / TLS-certificate status for every tenant domain (all types). A background monitor also re-checks hourly and emails owners on SSL expiry or DNS misconfiguration.
Click “Run checks” to test all tenant domains.
Monitor settings
Controls the hourly background monitor above, not the manual “Run checks” button. Owner-only.
Loading…
Maintenance
Dependency, OS, and database health for this host. Checks are read-only; fix operations are owner-only, re-authentication-gated, typed-confirm, audited, and (for dependencies) auto-rolled-back if they break the type-check. Weekly checks run automatically with an email summary.
Weekly auto-check
Loading…
Dependency vulnerabilities
Runs npm audit against the API workspace — reports KNOWN published advisories (GHSA/CVE) in the installed dependency tree. This is not zero-day detection and not source-level SAST. Apply safe fixes runs npm audit fix (never --force): manifests are backed up first, then the API is type-checked, and it auto-rolls-back if the build breaks. A process restart is required afterward to load updated deps.
Click “Scan dependencies (CVEs)” to run a known-CVE scan.
Dependency updates
Runs npm outdated — packages with a newer wanted (semver-compatible) or latest version available. Apply safe updates runs npm update (semver-safe, non-breaking); backup + type-check verify + auto-rollback apply. Major bumps are flagged and left for manual review.
Click “Check dependency updates” to list outdated packages.
OS package updates
Runs apt list --upgradable (read-only). Apply OS updates is the highest-risk action: it runs a security-focused upgrade via sudo -n (passwordless sudo required) and can require a service restart or reboot. Owner-only; re-auth + typed UPGRADE confirm.
Click “Check OS updates” to list upgradable OS packages.
Database health
Read-only optimization stats: database size, largest tables, dead-tuple / last-vacuum status, and unused indexes (bloat candidates).
Click “Database stats” to read DB health.
Account
Your profile, permissions, and credentials.
Your Account
Loading…
Change Password
Passkeys
Loading…
Support
Tenant support tickets and impersonation sessions.
Tenant impersonation (support sessions)
Read-only by default; time-boxed; every access is audited.
Loading…
Loading…
Marketing Site
Build and publish the public marketing site (roots-hq.com) with a visual page editor — no code required.
Loading…
Feature Requests
Manage the full lifecycle of feature ideas across all 13 states. Actor, timestamps, and transitions are enforced server-side. Mark Complete sends only a mock notification — no real email.
Loading…
Layout Ideas
Upload reference or mockup images to collect visual layout inspiration. Max 25 MB. Allowed: jpeg, png, gif, webp.
Loading…
Roadmap
Internal feature roadmap & checklist for the Roots HQ platform. Check items off as they ship.
Loading…
Branding
Upload logos + favicon and set the brand tagline for Roots HQ. Unset slots fall back to the built-in default branding. Max 25 MB per file.
Loading…
Marketing logo
Shown in the roots-hq.com header & footer. Raster recommended (png/webp). Allowed: jpeg, png, gif, webp.
Admin logo
Shown in the admin.roots-hq.com header (this console). Allowed: jpeg, png, gif, webp.
Favicon
Browser tab icon. Allowed: png, ico, jpeg, gif, webp, or a safe SVG.
Brand tagline
Shown alongside the marketing logo. Leave blank to use the default: “Root here. Branch out.”
Settings
Platform configuration.
Maintenance mode
Loading…
General
Loading…
Email relay (SMTP)
Loading…