System admin
Global user management via Better Auth's admin plugin, distinct from any Workspace Role.
adminsystem-admin
Global user management via Better Auth's admin plugin, distinct from any Workspace Role.
A System Admin is a user with global user-management permissions through Better Auth's admin plugin. System Admin is not a Workspace Role; it operates at the user level. packages/auth/src/index.ts registers admin({ adminRoles: ['admin'] }), so users whose user.role = 'admin' are System Admins.
The /admin route renders a global users table (name, email, system role, status) with per-row actions, a cross-workspace role editor, and a global audit-event table sourced from AuditEventLog.listGlobal. The actions go through the PlatformUserAdmin capability, never straight to the plugin:
system_admin.user_banned / system_admin.user_unbanned.system_admin.user_role_changed.system_admin.impersonation_started / system_admin.impersonation_stopped.Password reset and account creation from /admin are not surfaced.
A System Admin can browse the app as another user to reproduce what they see. The session is Better Auth's admin-plugin impersonation (ADR 0054):
/admin./admin, and a workspace the user is not a member of stays a 404. System Admins cannot be impersonated./account. The real account holder makes those changes.system_admin.impersonation_started and system_admin.impersonation_stopped name the admin as actor and the user as target, so both /admin's trail and the user's workspace audit page show it. The impersonated user also receives a Notification in each of their workspaces saying who started the session.Every System Admin action emits an Audit Event with actor, target user, and action type, through the same AuditEventLog capability the rest of the app writes to. The Better Auth admin endpoints called directly from a client are audited by the auth catchall as system_admin.* success/failure pairs; the /admin UI's own actions are audited by the capability. See ARCHITECTURE.md §Audit log.