Team admin setup
A Team Brain is one shared service per team. It is not a multi-user personal workspace and does not replace the workspace each person owns.
The end state
Section titled “The end state”Person A workspace ─┐Person B workspace ─┼─ explicit aios push/query ─ Team BrainPerson C workspace ─┘The Brain owns membership, authentication, shared storage, tier-filtered retrieval, and team-facing administration. Each individual workspace owns local files, harnesses, validation, and the decision to share.
Admin sequence
Section titled “Admin sequence”-
Set up your own individual workspace
Follow Individual workspace setup. This gives the administrator the same private operating surface every other member uses.
-
Deploy one Team Brain
Follow Run your own Team Brain to configure Postgres, environment variables, schema, and the Next.js service.
-
Establish the team and administrator
Use the Brain’s documented bootstrap/admin flow. Confirm that the admin can sign in, open the team dashboard, and create a per-machine API key.
-
Invite members to the Team Brain
Use Admin → Members in the dashboard or:
Terminal window aios member invite person@example.com --name "Person Name" \--handle person --role member --tools allThe caller must use a team-tier admin key. The route is rate-limited and audited.
--tools allcascades the invite to Linear, Slack, and GitHub — but each tool has its own prerequisite, and an unconfigured one reportsskippedand says nothing else, so the invite appears to succeed while inviting the person to nothing but the Brain:- Linear needs an enabled Linear integration with its API key stored in Admin → Integrations. The Member onboarding panel alone is not enough.
- Slack needs an invite link in Admin → Integrations → Member onboarding, and can only ever hand that link back — it never sends an invite.
- GitHub needs an org in that same panel, plus a token with
admin:org.
Set these up before the first real onboarding. See Member onboarding prerequisites.
-
Have each member create their own workspace
Send each person Join a Team Brain. They create or repair their own workspace, sign in, generate their own API key, approve the Brain origin, and preview their first push.
-
Verify the boundary
Each member should run:
Terminal window aios whoamiaios statusaios push --dry-runDo not ask members to clone an administrator’s personal workspace. Share team context through the Brain and deliberately shared source repositories.
-
Wire your code repositories into Codebases
Content arrives via
aios push; code does not. Each repo you want on the Codebases dashboard needs thescan-on-mergeworkflow plus its own three Actions secrets —AIOS_BRAIN_URL,AIOS_TEAM, and a team-tierAIOS_API_KEY. Secrets do not inherit between repositories.Follow Wire a repository into Codebases, then verify the first run really scanned rather than silently skipping — the workflow is fail-open, so a green check alone proves nothing.
Operations and reference
Section titled “Operations and reference”- Team Brain guide — product behavior and self-hosting
- Brain API — pinned member-facing sync contract
- Source-of-truth map — which repository governs each claim