Skip to main content
Version: Next

Administration

Administration covers system-level management tasks — user management, backup and restore, scaling, and upgrades. For data and workflow operations, see Operations.

Administration covers all tasks that require elevated permissions and affect the entire workspace. The Administrator role has unrestricted access to every section of Lakehousecat — including areas not available to Builders or Users.

Roles​

Lakehousecat has three roles:

RoleDescription
AdministratorFull access to all areas. Manages users, configures providers, controls scaling, oversees operations, and handles backup and monitoring.
BuilderCan create and manage Custom Models and Job Definitions. Cannot manage users, configure provider models, or access system-level settings.
UserCan use chat, view analytics, and interact with published dashboards and charts. Cannot create models or modify any configuration.

Administrator Responsibilities​

User Management​

Administrators invite users, assign roles, and manage access. Because Lakehousecat is a seed-based service, the number of active users directly affects licensing costs. User management is therefore an exclusively administrative action.

See User Management for details.

Provider Models​

The configuration of AI provider models (OpenAI, Google, Anthropic, Azure, AWS, xAI) is restricted to Administrators. This includes adding, updating, and removing models available to the workspace. Builders and Users can select from configured models but cannot modify them.

Access & Groups​

Administrators control workspace-level access configuration through the Access section:

  • General — Role distribution overview and access statistics
  • Instance — Instance-level configuration
  • Users — Invite, role-assign, and remove users
  • Groups — Create groups and assign group-level permissions

Scaling​

Scaling Lakehousecat requires modifying the Kubernetes Operator configuration — this is a cluster-level operation requiring administrative access both within Lakehousecat and to the underlying Kubernetes cluster.

See Scaling for configuration guidance.

Operations​

While Builders can also create Job Definitions, the built-in system job definitions — datasource loads, semantic layer operations, database backups — are managed exclusively at the administrator level and are locked against deletion.

See Operations for details.

Backup & Restore​

Backup jobs run automatically via scheduled Job Definitions. Restore operations affect all core storage components and should be performed with caution and in coordination with Lakehousecat support.

See Backup and Restore for details.

Monitoring​

Lakehousecat exposes observability data through open interfaces: a Prometheus-format /metrics endpoint on each backend service and structured application logs in object storage. The Operator does not deploy its own Prometheus or Grafana — administrators integrate Lakehousecat with the customer's existing monitoring stack (Prometheus, Datadog, Grafana Mimir, etc.).

See Monitoring for details.

Security​

Lakehousecat encrypts sensitive data at rest with three independent keys. Rotating the main content-encryption key (ENCRYPT_KEY) is a CLI-driven Admin operation; the other two follow their own procedures.

See Encryption Key Rotation for details.