Monitor

Web UI

Nodes, agents, plugins, jobs and their cost in a browser, with the commands to add nodes.

Every server serves the web UI on its management port, 8443: the same address the CLI's context points at. It uses the same APIs as the CLI, so everything it shows, the CLI can show too.

Sign in

Open https://<server>:8443 and sign in as admin:

  • A cluster: orchestrator-zero server init prints the first password once, under Web UI.
  • Dev mode: the password is in admin-password in the data directory, and the server logs the address and the file when it starts.

The browser warns about the certificate: the server's certificate comes from the cluster's own CA. Trust the CA on your machine (ca.crt in the operator context's folder), or accept the warning on a dev machine.

What you can do

The sidebar groups the pages by what you do: Operate (Overview, Jobs, Approvals), Build (Agents, Tools and skills, Plugins), Quality (Findings), Fleet (Nodes), Spend (Cost) and Admin (Settings).

Lists filter at the top and open a row in a drawer beside them, so you can look at one thing without losing your place. A page's address keeps its filters, its open tab, the row in the drawer and the step you opened, so a link shows what you saw. Hover over a job's ID anywhere to see what the job is.

PageWhat it shows and does
OverviewNodes online and waiting, agents, jobs running, the last day's cost, recent jobs, the servers; each number links to its page
NodesEvery node with its state, health, runtime, labels and last heartbeat, filtered by status or by ID, name, label or host; a node's drawer adds its machine, certificate and health penalties. Accept, reject, block, unblock and delete. Add nodes creates a join token and shows the two commands to run on the machine, ready to copy. Upgrade rolls a runtime out to every node, a canary first, and a panel above the nodes follows each step to its verdict, with Roll back while it runs
AgentsThe agents of the tenant's plugins and where they can run, filtered by name or plugin, and a Run button that starts a job with an input and a budget; an agent's drawer links to its jobs
Tools and skillsThe tenant's tools with their functions and the nodes that run them, and its skills
PluginsInstalled plugins with their version, commit, nodes and quality gate; a plugin's drawer has its source, tools, agents, the gate's report and its status on each node. Install from a Git URL, update, remove
ApprovalsWhat waits for a person across the tenant's jobs; open one in the drawer to approve or deny it, with a comment
JobsRecent jobs, filtered by status, agent or ID; click a row to peek at a job without leaving the list. A job's page has a tab for its steps, a waterfall with findings and an inspector for each step; its live stream while it runs, child jobs on other nodes included; its answer; and its cost per branch. Beside them are the job's facts, its child jobs, and a link to its history in Temporal's own UI, which admins reach at /temporal/
FindingsJobs whose steps look wrong: loops, retries, idle time, waits for a node, budgets, workflow failures, filtered by rule, agent and period; a job's drawer has all its findings, its cost and a link to its steps
CostCost and model calls over the last day, week or month, and this month against the tenant's budget; then by agent, model, node and job, each with a bar for its share
Audit logUnder Admin, for the tenant's admins: who changed what, and what the platform did by itself, filtered by action and target; an entry's drawer has its detail
SettingsTenants, join tokens, secrets (set and delete; values are never shown) and API keys (shown once) for admins, people and their roles for owners, and your own password

Accounts and roles

Terminal
orchestrator-zero user add kim --role member         # prints a generated password, once
orchestrator-zero user grant kim --role operator     # kim's role in the default tenant
orchestrator-zero user grant kim --role reader --tenant acme --content
orchestrator-zero user add sam --role admin --password-stdin < password.txt
orchestrator-zero user list
orchestrator-zero user revoke kim --tenant acme
orchestrator-zero user password kim                  # a new password; signs kim out everywhere
orchestrator-zero user remove kim

An account has a role in each tenant it is a member of. Each role can do what the ones before it can:

RoleMay
readerLook: nodes, agents, plugins, jobs and their steps, cost, findings
operatorAlso start and cancel jobs, and decide approvals
adminAlso change the tenant: nodes and rollouts, plugins, secrets, join tokens, the budget; and read its audit log
ownerAlso decide who is a member, under Settings, People, or with user grant

Seeing what jobs read and wrote, such as prompts, answers, tool arguments and results, and each step's input and output, is a permission of its own. Operators, admins and owners have it unless an owner takes it away (--content=false), and readers do not unless an owner gives it (--content). Without it, the job page shows the shape of each job: which tools it called and when, its steps and their cost, but not their content.

The account itself has a cluster role: admin (the owner of every tenant, who also adds tenants and accounts), reader (reads every tenant) or member (only its tenants). server init and dev mode create one admin. Everyone can change their own password under Settings.

  • Sessions last seven days and end when the password changes. Five wrong passwords for one name from one address within 15 minutes cost a minute's wait.
  • The session cookie only works for requests from the app itself: other sites cannot use it, and the app loads nothing from anywhere else, so it works without internet access.
  • The CLI keeps using its operator certificate; accounts are for people in a browser.
The app shows the default tenant. A tenant switcher and sign-in with OIDC come later.
Copyright © 2026