Enterprise Server

The console

Every Enterprise Server serves its own web console at its URL — the same address the CLI talks to. There is nothing else to deploy: the console is part of the server.

Open the console

Go to your server's URL, for example https://knwlge.acme.example. The sign-in page shows your server's logo and background when an admin has set them (Branding), and a button for each way the server accepts.

The Overview, as a server admin sees it (illustration with sample data).

Signing in

The console has no passwords of its own. Sign in with Knwlge, Microsoft or GitHub sends your browser to knwlge.com, which signs you in that way and asks you to approve this server — exactly as it does for the CLI — then brings you back signed in.

  • The server checks the token it receives against Knwlge Global's keys and against its own sign-in settings. A sign-in it does not accept — a method turned off, an address outside the allowed domains — gets no session, and the page says why.
  • The session is sealed in an HttpOnly cookie, refreshed by the server itself two minutes before it expires. There is no session table to leak.
  • Sign out, at the foot of the sidebar, revokes the session at Knwlge Global and clears the cookie.

Who sees what

Knwlge decides who belongs to the project; the roles it puts in each token decide the pages.

PagesWho sees them
Workspace: Overview, Guardrails, Knowledge, Context, My memory, InsightsEvery member of the server's project.
Administration: Repositories, Memory review, Team, Prompts, Activity, Alerts, Audit, SettingsServer admins: organization admins, and members ticked as Server admin on the project's members page in the Knwlge app.

The server enforces the same rule on every admin route, so the sidebar only reflects it. Membership itself — who may sign in, organization roles, teams — is managed in the Knwlge app; removing someone from the project there ends their access here.

Finding your way

A sidebar on the left lists the workspace pages, then — for server admins — the administration pages. The top of each page says what it is for; filters, tabs and chart windows are kept in the address, so a link shows what you saw. Settings is one page per section, listed beside it in four groups: Server, Sources, AI and Governance.

When the server needs a key

If Knwlge Global refuses the server's enrollment key — deactivated, past its date, or the server forgotten — every page shows a banner, and developers' assistants get 503 server_enrollment_required until a new key is entered. The console keeps working behind the banner: admins get a link to Settings → Knwlge Global, where entering a new key re-enrolls the server without losing anything; everyone else is told to ask one. An outage at Knwlge never causes this.