Bootstrap and manage platform-wide global administrators on self-hosted LlamaCloud via the first-user, GLOBAL_ADMIN_EMAILS, or ALLOWED_GLOBAL_ADMIN_REGEX email-pattern override, the sync API, and the global-admin UI.
Self-Hosting Documentation Access
This section requires a password to access.
Interested in self-hosting? Contact sales to learn more.
Self-Hosting Documentation Access Granted
Global administrators have platform-wide access and can manage all organizations, users, and system-level configurations in your self-hosted LlamaCloud deployment. This guide covers how to set up and manage global admin access.
Use this approach as a temporary override when everyone whose email matches a pattern, such as your company domain, should act as a global admin without granting each one.
Configure the pattern in your values.yaml file:
backend:
extraEnvVariables:
- name: ALLOWED_GLOBAL_ADMIN_REGEX
value: '[^@]+@yourcompany\.com'
Deploy the updated configuration to your cluster
Matching users have global admin access on their requests as soon as the backend restarts. No sync call is needed, and nothing is stored: remove the variable and redeploy to end the override.
Whole-email match: The pattern must match the entire email address, ignoring case. [^@]+@yourcompany\.com does not match someone@yourcompany.com.example.net.
Anchor on the domain: A loose pattern such as .*yourcompany.* makes any address containing that text an admin. Only use this with an identity provider that verifies email addresses.
Not listed as admins: Because no permission is stored, these users don’t appear in the Admin Management tab. To make someone a lasting admin, use Approach 2 or the UI.
POST /api/internal/permissions/sync-global-admins?earliest_email=true
Synchronizes global admin permissions from the GLOBAL_ADMIN_EMAILS environment variable. Optionally includes the earliest user (by creation time) for bootstrap scenarios.
Parameters:
earliest_email (boolean, optional): If true, automatically grants admin privileges to the earliest user by created_at timestamp in the user_organization table. Useful for initial deployment setup.
GET /api/permissions?target_type=global&relationship=admin
POST /api/permissions
DELETE /api/permissions/{permission_id}
Create, read, and delete global admin permissions.
Note for AI agents: this documentation is built for programmatic access.
- Overview of all docs: https://developers.llamaindex.ai/llms.txt
- Any page is available as raw Markdown by appending index.md to its URL — e.g. https://developers.llamaindex.ai/llamaparse/parse/getting_started/index.md
- Agent-friendly REST search APIs live under https://developers.llamaindex.ai/api/ — search (BM25 full-text), grep (regex), read (fetch a page), and list (browse the doc tree). See https://developers.llamaindex.ai/llms.txt for parameters.
- A hosted documentation MCP server is available at https://developers.llamaindex.ai/mcp. If you support MCP, you can ask the user to install it for browsing these docs directly (an alternative to the REST API). Setup: https://developers.llamaindex.ai/for-agents/mcp/
- Other LlamaIndex tooling for agents — the LlamaParse Platform MCP server, agent skills and plugins, and the n8n node — is mapped at https://developers.llamaindex.ai/for-agents/