App Studio
App Studio is coming soon: it is in development and testing and is not part of release 3.0. This page describes App Studio as it is being built, so names and steps may change before release.
App Studio is designed to let people in your organization build small React apps on top of MaestroHub's own data and APIs (live UNS values, connector functions, pipelines, dashboards) by describing what they need to the Maestro builder agent, which is also coming soon. In the design, an app's source is kept in a per-app git repository inside MaestroHub, compiled server-side, and served from a separate sandbox origin inside an iframe. An app declares what it may do in a manifest.json; at run time it acts with a short-lived app token that is the intersection of that manifest and the viewer's own permissions, so an app can never do more than the person (or paired display) looking at it.
Every version an app publishes is meant to be immutable and pinned to the SDK runtime it was built against. Sharing, ownership, audit and the kill switch use the same platform primitives as pipelines and dashboards. App Studio is licence-gated (app_studio); in the current development build it runs only on the single-binary deployment.
Who does what
| Role | What they do | Built-in roles that fit |
|---|---|---|
| Viewer | Opens published apps from Apps, or watches one on a paired kiosk display. Sees only what their own permissions allow. | Apps.Viewer (app:read, app:run), or a share grant on one app |
| Builder | Creates apps, works with the builder agent, validates, previews, publishes, shares, pushes to Git, watches the app's Ops page. | Apps.Editor (build and iterate, no delete/share), Apps.Admin (full lifecycle incl. share, delete, backup) |
| Operator | Enables the module and licence, sets the sandbox domain, pairs displays, tunes fair-use limits, watches metrics and alerts, backs up and restores. | Organization.Admin (every app:* verb incl. app:backup), platform System.Admin for server configuration |
Role names and the verbs they hold are in apps/backend/modules/authz/domain/builtin_roles/feature.go and persona.go; the Operator guide lists them.
Pages in this section
- Operator guide — enabling, sandbox domain, permissions, kiosk displays and device pairing, builder provider setup, fair use, operations, backup/restore, runtime versions, Enterprise status.
- Builder guide — creating an app, the builder page, the manifest, what apps can and cannot do, the SDK in one screen, sharing, kiosk, Git mirror, Ops, runtime pins.
- Templates catalogue — every starter template and the three showcase apps, with the "try one of these" prompt.
- SDK reference — the generated
@maestrohub/sdkand@maestrohub/app-uireference. - SDK changelog — what changed in the SDK surface a new build compiles against, and what to change in an app.
Design documents live in the repository under docs/architecture/app-studio/ (REQUIREMENTS.md, ARCHITECTURE.md, DATA-SAFETY.md, SDK-VERSIONING.md, LOAD-TESTS.md, ENTERPRISE.md); the pages here point at them where the detail matters.