Sign in as yourself
Use your company login or a linked passkey. The Hub connects that sign-in to your work profile and checks which apps you can use.
Choose how you’d like to sign in.
Use your company account or a passkey already linked to your profile.
Passkeys are provided by Internet Identity. Your company controls access to its workspace.
| Taken | Size | Note |
|---|
entity=LLC).field=value = exact, field^=prefix = starts with. Matching accounts are hidden from THIS tool only. Empty = no filtering.npx kebab-mcp connect <code>). First time? Setup guide.Your sign-in, apps and notifications work together. Here’s how.
One place to find your tools, move between them and stay on top of what needs you. Here’s what to expect.
Use your company login or a linked passkey. The Hub connects that sign-in to your work profile and checks which apps you can use.
Choose a connected app and the Hub signs you into it. Website links open separately and may have their own login.
The Apps button follows you between tools. The bell brings together Hub notifications, with links back to the work that needs your attention.
Star an app to add it to Your favourites. Search by name or description; on a keyboard, press / to search and Enter to open the first result. Favourites and recent-use hints stay in this browser; they do not sync to other devices.
Open the bell from any connected app. For Hub notifications, you can enable Slack direct messages in the notification panel if your organisation has connected Slack and your account can be matched. Some tools also have their own channels, such as Desk ticket threads.
Your menu reflects the apps your organisation has made available to you. If Request access is shown, use it to explain what you need. Otherwise, contact your IT team. Access to an app does not automatically give you access to every record, teamspace or administrative setting inside it.
Open your profile at the top right to manage the options available to you, including your picture and sign-out. Company-managed profile information comes from your organisation’s directory. If a session expires, sign in again through the Hub; your work stays in the app.
The Hub shares your identity and the directory fields allowed for that app. Your administrator controls additional access, such as profile information, groups, roles and pictures. Each app controls access to its own records. Public features, such as the game leaderboard, have their own sharing rules.
For bundled apps, the Hub issues a single-use ticket valid for 90 seconds, bound to the intended app. That app redeems the ticket with the Hub and creates its own session. External software connected through OpenID Connect follows its configured sign-in flow; ordinary website links receive no Hub sign-in ticket.
Once the Hub records an account or access change, it sends a revocation update. Bundled apps also recheck their access data and deny access when it is 60 seconds old. Changes in an upstream HR or identity system take effect after they reach the Hub. External software has its own session policies.
Opening connected apps requires the Hub. Bundled apps also stop accepting access when their authorisation data becomes too old. Try again once the connection returns; contact IT if the problem continues. A saved menu is a convenience, not a guarantee that an app is currently reachable.
Kebabstack’s Hub and bundled apps run as application services on a Cloud Engine. Your organisation chooses and operates its setup with its infrastructure provider. External websites, identity providers, Slack and optional AI services keep their own hosting and data flows.
Confirming your access…
Your sign-in stays with your company Hub.Your workspace at a glance. Start with what needs your attention.
Find a person, manage their access or help them sign in.
| Person | Source | Access | Hub role |
|---|
| Name | Source | Members | Note |
|---|
Keep people and groups up to date from your identity provider.
userName, HTTP Header auth with the source's connection key (bearer token). Entra: Enterprise app → Provisioning → Tenant URL = the address, Secret Token = the key. Users and groups (Okta "Push Groups", Entra group provisioning). Two identity providers? Two sources, two keys — the same address can only be provisioned by one of them, and a group name must be unique across the hub. Attributes that arrive (title, department, division, organization, cost centre, employee number, manager, the work address as city/state/country, and any custom attribute your provider maps into its SCIM schema) show on the person card and can drive an app's exclude filters (Apps → the app → Who may use it → Advanced → Attribute filters, e.g. city^=Remote).Connect tools, choose the data they receive and manage your team’s menu.
Requests, temporary grants and reviews for apps using access lists. Manage central app roles →
| Who | App | Why | Asked for | When |
|---|
| Who | App | Outcome | By | When |
|---|
| Who | To | Ends | Given by | Why |
|---|
| Name | Apps | Progress | Removed | Due | State |
|---|
Hand over a departing colleague’s work without changing their identity.
A searchable record of changes, sign-ins and syncs.
People, access and tools. A practical guide to running your workspace.
Connect your directory or add people manually. Company SSO and passkeys are two ways to sign into the same profile.
Open People →Choose an app, find a person and review their effective role. Hub shows where that role comes from.
Open Permissions →Connect apps, check sync and backups, and handle the items that need your attention.
Open Overview →People: profiles, global Hub roles, groups and invitations. Permissions: roles in the six suite tools. Apps: connections, shared data and menu entries. Directory sync: people sources. Settings: company identity, sign-in and shared services.
The Hub keeps a stable person ID. Email changes follow that person; reusing a departed person’s address must not transfer their access. A company account or an invited passkey connects the sign-in to that profile.
Company sign-in uses a configured provider such as Okta or Google. A passkey requires a linked profile, usually through a one-time invitation. People using company SSO do not also need a passkey. Configure company sign-in or view passkeys and invitations.
The Hub checks your session and app access, then issues a single-use ticket valid for 90 seconds. The destination app redeems it and creates its own session. During the handoff you see progress, with retry or return options if it fails. A direct app link preserves its destination through the sign-in. Ordinary website links use their own authentication.
Manually created groups are edited in People. Active SCIM groups follow the identity provider. Manual groups that grant app roles can only be changed by a Hub owner. Assigning an IdP-managed group trusts that provider’s membership management.
Each SCIM source manages its own people and groups. Existing directory-only integrations such as Lunch retain their configured filters and sharing fields; they do not use the six-app permission model. Manage sources →
Deactivate the account in its source system, or lock it out in the Hub when immediate intervention is needed. Use the person’s Offboard action to review and transfer supported work. Retained app records do not become somebody else’s simply because an email address is reused.
For Assets, Contracts, Desk, Forms, Trust and Watch, Hub Permissions is the authority. Active global Hub owners and admins inherit Admin everywhere. App-specific assignments affect only that app. Endtools cannot add local administrators.
Employees see their own and explicitly shared or assigned records. App Admin includes all app content and settings, including personal Forms and Contracts areas. Desk Agent handles all tickets without app settings. Trust Fleet viewer reads the fleet. Watch Viewer reads all monitoring, so ordinary employees have no Watch access by default. Hub Helpdesk does not automatically grant an app role.
Inactive accounts have no access. For active people: global Owner/Admin → individual assignment → highest group role → app default. The effective role and its reason are visible before saving. Only Hub owners can delegate app roles; global Hub admins can inspect them.
Apps refresh their directory every 30 seconds and refuse protected access when it is 60 seconds old. The bound starts after the Hub knows a change; upstream sync can add delay. “Confirmed by app” verifies the current snapshot and expires. Use Check app enforcement for a fresh observation; already downloaded data cannot be recalled.
Connect an app offers three paths. Hub apps receive ticket sign-in and an allowed directory. External software uses OpenID Connect. A website is only a link and receives no Hub ticket. Menu visibility and access are separate choices.
Apps → the app → shared data controls optional profile, groups, avatars, notifications and service credentials. Identity and the central permission decision are essential to authorization. Turning off a profile field is not a way to revoke an app role.
They manage access-list apps and temporary group membership. They do not replace the central policies of the six tools. Previous reviews for centralized apps are historical records; use Permissions for their current roles.
Notifications contain a title and a link; content stays in its app. Slack delivery is optional and follows user preferences. Apps with AI access receive the configured provider credentials and send their own requests. Personal assistants use their owner’s app rights, not independent administrator rights.
Check protected services and schedules in Backups. Snapshots belong to individual services, not an atomic copy of the entire suite. Taking one can briefly pause that service. A restore replaces current data with the snapshot, so review the selected service and timestamp carefully.
Install & update uses the connected Kitchen service and its published recipes. Review a version before starting. A new central-permission app also needs a saved Hub policy before its first protected login. Failed jobs expose their stage and result for investigation.
Restoring old app code also restores its old authorization rules and potentially retained local grants. Review matching Hub and app releases, data and access configuration together. A frontend-only rollback does not change backend access checks.
Keep a working Hub owner and a documented controller recovery path. Older principal-based grants appear under Settings → Hub administrators → Recovery access only if they exist. Link the holder to a person and verify the intended role before removing an old grant. Setup requires its one-time code or the actual controller; an unclaimed Hub is not open to its first visitor.
Application roles control normal app use. Infrastructure controllers can replace code or restore state and are outside that boundary. Your organisation chooses its Cloud Engine and operators; this alone does not guarantee confidentiality from infrastructure operators or a particular data location.
New app sign-in needs the Hub. Existing protected sessions stop working once authorization data is 60 seconds old. A progress screen shows a failed handoff with retry and return options. External software follows its own session policies.
Activity records Hub events. Search by person, app or change. Stable identity, one-time app tickets and current backend permission checks remain the access boundary; hiding a control is not authorization.
Use the served SDK and onboarding guide. The backend redeems tickets, pulls the allowed directory and rejects stale authorization. The browser uses the shared sign-in and topbar components. Always enforce record access on the backend.
Preserve stable state, compare signatures to committed baselines and exercise populated upgrades. Generate Candid and browser bindings from compiled code. Existing directory consumers keep their contract. Match frontend, backend, SDK copies and published recipes for a release.
The kebab-mcp client connects with a person’s own Hub permission scope. See the assistant integration guide.
Check protection, manage schedules and restore a snapshot. A restore replaces the service’s current data.
| Service | Protected | State | Snapshots | Schedule |
|---|
| Service | Plan | Keep | Last run | Result |
|---|
| When | Who | What |
|---|
-f skips the confirmation prompt, which otherwise swallows the run); the vault becomes a co-controller — you keep yours. Then Re-check all on the Services tab.icp canister status.Install suite apps and keep them current. Updates take a snapshot before changing code.
| When | What | State | Steps |
|---|
| When | Who | What |
|---|
-f skips the prompt.Company identity, sign-in and shared services.
| Person | Assistant | Connected | Last used | Uses | Until |
|---|
| App | Lane AI | Calls reported | Key fetched |
|---|
| Bot | Workspace | Token | Signing secret | Status |
|---|
chat:write + users:read.email (add intake scopes if tools will reuse this bot for Events intake) → Install → paste the xoxb token here. The token is verified against auth.test on save. Users opt out of DMs in their portal bell — the inbox always works.hub_slackCredentials. Tools stop owning Slack config: rotate a token here and every assigned tool picks it up on its next hub pull.| When | To | App | Title | Slack |
|---|
| ID | Name | Type | Client ID | Status |
|---|
| Person | Role | Status |
|---|