Docs · AI, integrations and administration
Administration
For administrators: users, audit log, analytics, system health, flags, models and keys, evaluations, moderation and support — all stored in the database, no env files.
Who sees it
Accounts with the administrator role see Administration in the sidebar. The operator names the first administrators in the deployment's environment (HIKMA_ADMIN_EMAILS) — they are promoted the moment they sign up; further administrators are promoted under Users. Every administrative action is written to the audit log with the actor, the target and the details.
Users
- Search by name or e-mail; filter by role and status (active, suspended, e-mail not verified).
- Manage opens the account in tabs: Overview (counts, institution, role, verification and two-factor state, plan), Projects & work, Activity (audited actions), Sessions, and Plan & credits (subscription, monthly model spend, grant credits). Support actions: mark the e-mail verified when the message never arrived, reset two-factor for someone locked out, sign out everywhere, suspend with a reason and optional length. The list accepts ?q= in the URL so other pages can link straight to an account. Also shown: projects, manuscripts, library items, model spend, sessions with device and address, recent actions and reports against the person.
- Change the role, sign the person out everywhere, or suspend with a reason and an optional duration. Suspension takes effect immediately and blocks sign-in until lifted or expired.
Audit log
Filter by actor, action, target type and date range; export the current filter as CSV (up to 5,000 rows). Actions are dotted names such as admin.user.suspend or manuscript.export.
Analytics
Sign-ups and active users per day for the chosen range, with totals for projects, manuscripts, library additions, course enrolments, posts, messages, model calls, spend and tokens, and open reports. The chart has a table view for screen readers and copying.
System
- Health and latency of PostgreSQL (with database size), Valkey, object storage, GROBID and the collaboration server.
- Slowest procedures: every API call is timed; the table shows calls, p50, p95 and maximum per procedure with slow (> 500 ms) and error counts since the last reset — the budget is p95 under 300 ms for reads and 500 ms for writes.
- Every background queue with waiting, active, delayed, completed and failed counts; failed jobs list their reason and can be retried in one click.
- The API process: uptime, memory, Node version, environment and version. Refreshes every 30 seconds.
AI mode, provider keys and the task-class registry
- AI mode decides who pays for the thinking. *Bring your own agent* (the default): researchers connect Claude Code, Codex, Cursor, Claude Desktop, ChatGPT or any MCP client on their own subscription; the built-in assistant and every model-backed tool are hidden, and the stored keys serve only embeddings (semantic search) and your tests. *Platform AI as well*: the built-in assistant, AI writing actions, screening, extraction, verification and unattended runs run on the keys stored here, metered by the budgets at the bottom of the page. The switch applies within seconds to the web app and to every MCP connection.
- Provider keys are grouped the way you shop for them — major vendors (Anthropic, OpenAI, Google, xAI, Mistral, Cohere), China (DeepSeek, Qwen, Z.AI GLM, Moonshot Kimi, MiniMax, Doubao, Baidu Qianfan, Tencent Hunyuan, StepFun, SiliconFlow, iFlytek Spark), aggregators and fast inference (OpenRouter, Groq, Together, Fireworks, Cerebras, SambaNova, NVIDIA NIM, Perplexity) and self-hosted (Ollama, any OpenAI-compatible endpoint such as vLLM or LM Studio). Each card links to the vendor's key page, presets the API address (editable for regional endpoints), and once a key is stored fetches the live model list, so the pickers below offer real ids. Keys are encrypted at rest and never shown again; Test sends a one-line request to the model you pick and reports latency and cost; Disable keeps a key but makes routing skip it; Remove deletes it.
- Bibliographic source keys (NCBI, Semantic Scholar, OpenAlex, the Unpaywall contact e-mail) are optional: searches work through the public tiers without them, a key only raises the rate limit or unlocks a premium tier for everyone.
- The task-class registry lists every model dispatch in the platform (search planning, screening, extraction, source notes, classification, verification judge, critique, assistant planning, drafting, revision, analysis code, embeddings) with its purpose. For each: provider and model, an ordered fallback chain (providers without a key are skipped), an on/off switch and a per-person daily cap. Changes apply within 15 seconds without a restart. The verification judge should not share a model family with drafting.
- Budget defaults — per narrative review, per systematic review and per project per month — apply to the platform's own model calls only.
AI costs
The platform's own model spend. In bring-your-own-agent mode there is nothing to report here: researchers’ agents are billed by their own providers, and only embeddings and your provider tests reach the ledger.
- Windows of 24 hours, 7, 30 or 90 days: spend, calls, failed calls, tokens (with the share served from the prompt cache), average and p95 latency, month-to-date spend against the monthly budget default and the alert threshold from Settings.
- Spend and calls over time; spend by task class with a 30-day trend, by provider and model, top people (opens their account) and top projects; prompt-cache hit rate per provider; the twenty most recent failures with their error text.
- Export every call in the window as CSV (up to 20,000 rows) for finance or audit.
Quality
Platform-AI deployments only — it reads the run ledger, which stays empty while researchers bring their own agents.
- The last 50–500 finished assistant runs across every workflow: success rate, median cost and duration, tool calls per run, budget and round-limit stops, model failures and rate-limited runs, checks passed versus failed.
- Breakdown by workflow and mode, the most frequent failure reasons, claim–evidence verification links for the last 30 days by relation and acceptance, and manuscript checks by identifier and severity.
- Each run links to its transcript in the project's assistant. Read-only; use it to compare prompt or routing changes before and after.
Mentorship
- Open or close the programme: while closed the directory hides and no new requests are accepted; active mentorships continue.
- Listed mentors with interests, methods and workload (active, pending, completed); Unlist removes someone from the directory without touching the rest of their profile.
- Every request with its state (looking for a mentor, awaiting the mentor's answer, active, declined, ended); End closes one on the programme's behalf with an audited reason.
Feature flags
Flags gate features at runtime by key; toggling takes effect within seconds and needs no deploy. Add a description so the next operator knows what a flag does.
Sign-in providers and e-mail
Google and ORCID client credentials, institution SSO providers (OIDC, by e-mail domain) and the outgoing SMTP server are platform settings under Administration → Settings. Until SMTP is configured, account e-mails are logged instead of sent and the settings pages say so.
Billing
Administration → Billing: switch billing on for launch, store the Stripe secret and webhook signing secret (encrypted), edit plans (price, assistant allowance, unattended runs, project and collaborator limits, features) and sync them to Stripe with one click, define credit packs, create named or bulk single-use codes (credits, free days, percentage or fixed discounts), grant credits to a person, and watch subscriptions and revenue. While billing is off, the whole platform is free and the pricing page shows plans without prices.
Evaluations
Evals runs the platform's own assistant against a fixed suite of research tasks and reports groundedness, citation validity and cost per task, so a model or routing change can be judged before it reaches researchers. It needs platform AI switched on and provider keys stored; it says nothing about the agents researchers connect themselves.
Moderation engine
Administration → Moderation brings everything together: the reports people file, the flags raised automatically, the rules that raise them, every hidden post or comment (restorable), and the log of every action with who took it.
| Rule | What it does |
|---|---|
| Keyword list | Flags, hides or blocks posts and comments containing listed words or phrases (* wildcard) |
| Link limit | Flags posts with more than N links |
| Posting velocity | Flags accounts posting more than N times in M minutes |
| New-account review | Flags the first posts of accounts younger than N days |
| Media review | Flags posts with video (or images) for a human look |
- Decisions: dismiss, hide (reversible), warn the author, suspend for 1 / 7 / 30 days or until lifted.
- Hiding keeps the content in the database with the reason and the moderator; restoring it is one click under Hidden content.
- Every decision is written to the audit log and to the moderation action log.
Related
Something missing or wrong? Tell us.