> ## Documentation Index
> Fetch the complete documentation index at: https://documentation.orbitdev.org/llms.txt
> Use this file to discover all available pages before exploring further.

# Control Center Console: Sections, Guards, and Data Loading

> How Orbit Control Center organizes admin sections, loads data with TanStack Query, and keeps authorization on the server with narrow RPCs and protected fallbacks.

Orbit Control Center is the authenticated internal operations console for the Orbit engineering and operations team. It is organized into route-aware sections under the `/admin` prefix, each backed by targeted data loading and server-side authorization.

## Console sections

The Control Center exposes the following sections:

| Route | Section |
| - | - |
| `/admin/users` | Users |
| `/admin/history` | History |
| `/admin/codes` | Codes |
| `/admin/notifications` | Notifications |
| `/admin/moderation` | Moderation |
| `/admin/audit` | Audit |

<Note>
  Source material does not describe the internal behavior of each section beyond its route name. Treat the table above as the current surface area.
</Note>

## Frontend guards

Frontend guards provide navigation safety, such as hiding links or redirecting non-admin users. They are not the real authorization boundary. The true boundary is enforced by Supabase RLS, permission helpers, protected RPCs, and the moderation Edge Function.

## Shell and data loading

`AdminPage.tsx` owns the current console shell and route-aware sections. TanStack Query loads only the active section and invalidates targeted cache keys after writes. This keeps network traffic minimal and cache updates precise.

Administrative writes use narrow RPCs. Each write operation calls a specific function rather than a broad mutation endpoint, which reduces blast radius and makes audit logging easier.

## Moderation path

Moderation uses the authenticated moderation Edge Function with protected RPC fallbacks. See [engineering/moderation](/engineering/moderation) for details on JWT auth, server-side role resolution, and batch revocation.

## Planned refactor

The next refactor boundary is extracting each route-aware section into its own page without changing its server contract. This will simplify `AdminPage.tsx` and improve code splitting, but the RPCs and RLS policies remain the same.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.