Agent Capabilities — Admin Role
Admins have full access to every platform capability. In addition to all User and Builder features, the Agent gives Admins access to user management, group management, platform monitoring, and low-level infrastructure operations.
All User and Builder Capabilities
Admins have access to everything in User Capabilities and Builder Capabilities.
User Management
Admins can manage user accounts through the Agent.
| Request | What the Agent does |
|---|---|
| "List all users" | Returns the full user list |
| "Find users with the Builder role" | Filters users by role |
| "Update Anna's role to Builder" | Changes a user's role |
| "Show statistics for user X" | Returns activity stats |
| "Delete user account X" | Removes a user account |
Group Management
Groups control shared access to models, datasources, charts, and dashboards.
| Request | What the Agent does |
|---|---|
| "List all groups" | Returns all groups |
| "Create a group called Analytics Team" | Creates a new group |
| "Add user anna@example.com to the Analytics Team group" | Adds a member |
| "Remove user X from group Y" | Removes a member |
| "Delete the Marketing group" | Removes a group |
Platform Instance & License
Admins can query the current state of the Lakehousecat instance.
| Request | What the Agent does |
|---|---|
| "What version is this instance running?" | Returns the current version |
| "Check the license state" | Returns subscription and license info |
| "What is the instance name?" | Returns the configured instance identifier |
Sample Packages
Admins can populate an instance with a ready-made example — datasources, a custom model, warehouse data, and dashboards — in a single step. This is the fastest way to turn an empty instance into something to explore for a demo or evaluation.
| Request | What the Agent does |
|---|---|
| "Install the retail demo sample" | Installs a sample package after confirming which instance it targets |
| "What did the sample create?" | Lists the models, datasources, and dashboards that were added |
The Agent tells you what the package creates and asks for confirmation first. The data load and semantic extraction behind it run for minutes, not seconds. The created objects are ordinary datasources, models, and dashboards afterwards — there is no one-step uninstall; each object is removed individually.
Backup & Restore
Admins can trigger the built-in backup and restore jobs for the instance's PostgreSQL, ClickHouse, and object-storage data.
| Request | What the Agent does |
|---|---|
| "Back up this instance" | Triggers the backup jobs, waits for them to finish, and reports the status of each |
| "Back up everything except object storage" | Runs the backup with object storage skipped |
| "Did the last backup succeed?" | Reports the status of the most recent backup jobs |
| "Restore this instance from the backup taken this morning" | Walks through the restore confirmation, then runs it |
A backup is a minutes-scale operation. When reporting a successful backup, the Agent notes that the Kubernetes secrets — including database encryption keys — are backed up encrypted to your age key, and are readable only with the private key you keep outside the cluster; lhc restore does not restore them, so a restore onto a fresh cluster needs them restored separately first.
A restore overwrites the current contents of the instance — everything created since the chosen backup is lost, and there is no undo. The Agent confirms the target instance, the backup to restore from, and what will be lost before running it, and never starts a restore on its own initiative.
Audit Log
Admins can ask the Agent who created, changed, deleted, shared, or approved an object, and when.
| Request | What the Agent does |
|---|---|
| "Who deleted the Marketing dashboard?" | Looks up the audit log entry for that action |
| "Show me all changes to the Revenue model this week" | Returns a filtered history of that object |
| "Did anyone change user roles recently?" | Returns matching audit log entries |
| "Give me a change report for an auditor" | Compiles the relevant audit log entries |
The audit log only tells you who did something and when — for the current state of an object, ask the Agent about that object directly instead.