Use case · Internal
Admin panels, support inboxes, audit tools. Same Better Auth, same RBAC, same audit trail as the customer-facing app. The four sub-systems an internal tool needs are wired into the registry before your first commit.
What's in the box
Eleven capabilities grouped by the buyer-side question they answer. Pick a cluster, read what you actually get.
Operator identity sits behind the same wall as customer identity, with role-based gating.
Better Auth wires the operator console against the same user table your customer app uses. No separate password store to provision, no separate rotation cycle.
Scoped roles per operator: read-only, support, finance, ops. Role gates live on the procedure definition, not in a separate middleware you forget to wire up.
Every operator action records the actor, the action, and the target. Buyers in regulated verticals audit this in the first call.
The surface the support team operates from. Same data the customer sees, scoped to the operator's role.
Searchable user table with role filters and bulk operations (impersonate, suspend, reset). Bulk actions hit the same RPC the customer API does, so the two never drift.
Override plans, refund invoices, extend trials — without writing SQL. Every override records the actor and the reason.
MRR, churn, active users, p95 latency. The numbers come from the same queries the product runs, so they're never a stale export.
The inbox your support team works in. Tied to the product surface, not a separate vendor.
Support tickets open from any user detail and carry the full session history. No context-switching to a separate Zendesk tab to find what the customer did.
Support can read everything; can write only the fields their role allows. The same typed schema governs both customer and operator actions.
Per-operator response time and customer rating surface in the same dashboard. The data the support manager needs is on the same screen as the team.
Background work the operator team sets up once and forgets.
Queues and retries wired against the same contract the rest of the app uses. Failed jobs visible in the same dashboard; retries are typed.
Per-org, per-plan flag targeting with history. A flag turned off for an enterprise account last Tuesday is still queryable today.
Cron-style tasks read the same schema, log to the same trace, fail with the same retry policy.
{
"id": "org_2nK9xR",
"name": "Acme Labs",
"plan": "pro",
"mrr": 1127,
"seats": 8,
"stripe_customer_id": "cus_R8x2Wq"
}Stack
Process
Better Auth on the admin subdomain. SSO and roles wired against your existing user table.
Scoped roles, audit log, and rate limits. The contract that gates your customer app gates your support console too.
The operator console consumes the same Drizzle schema and the same Better Auth sessions as the customer surface. One type system, one deploy.
Built on this
Production-ready starter templates, each deployed at its own URL. Used as the reference set for what the registry can ship.
Explore
Related
Multi-tenant B2B SaaS with auth, billing, and a working dashboard on day one.
Read more
Related
Maintainer-friendly starters, MIT-licensed, versioned through the same registry.
Read more
Related
RAG, chat, and agents wired against the same contracts your app uses.
Read more
Two doors
Self-serve gives you the registry and the templates. Engagement gives you the team that built it. Pick the door that fits the timeline.