# Tia, the AI assistant, and AI monitoring

> Source: https://test-allsweb.allsweb.net/sixpanel/docs/ai-assistant
> Markdown for agents: https://test-allsweb.allsweb.net/sixpanel/docs/ai-assistant.md
> Publisher: AllsWeb (www.allsweb.com)

Part of: SixPanel documentation

**What this page is for:** let an AI run this server with you. Tia, SixPanel's own
assistant, answers questions about the server and does the work — create a website,
deploy, add a domain and HTTPS, take a backup, read the logs, restart what is stuck —
through the same checks as the panel's buttons. AI monitoring watches the server all
the time and explains what goes wrong. And your own AI agent (Claude Code, Claude
Desktop, Cursor, VS Code, Windsurf, Hermes Agent …) can connect to the server the
same way.

Everything is on **AI** in the main menu, in five tabs: **Tia**, **Monitoring**,
**Connect**, **Providers** and **Settings**. The **Ask Tia** button at the bottom corner
of every other page opens Tia over the page you are on — she knows the page, and the
project or website it belongs to, and her first suggestion is about that page (see [Ask Tia on any page](#ask-tia-on-any-page)).

---

## Providers

The AI comes from a provider you choose, with your own key — one list for the whole
panel: Tia, monitoring and **Create with AI**. Until there is one, the setup
itself appears wherever the AI is needed — on **AI → Providers**, in Tia's empty
chat, in the **Ask Tia** panel and in a Create-with-AI website's conversation —
so there is nothing to go looking for.

Pick a card:

| Card | What to fill in |
|---|---|
| **Anthropic (Claude)** | your Anthropic API key |
| **OpenAI**, **Google Gemini**, **DeepSeek**, **Groq**, **Mistral**, **xAI (Grok)** | that provider's key |
| **OpenRouter** | your OpenRouter key — hundreds of models behind one key |
| **Nous Portal (Hermes)** | your Nous Portal key |
| **On this server** — Ollama or LM Studio | nothing: a model running on the server itself, and nothing leaves the server |
| **Custom endpoint** — OpenAI- or Anthropic-compatible | a name, the address (`https://…/v1`) and the key of any gateway — OmniRoute, LiteLLM, your own |

**Get a key** beside the key field opens that provider's own key page. Once the key is
in, the models load by themselves into a list you search by typing (**Load models**
loads them again), and one is suggested for you: the newest of the provider's
strongest models — never an embedding, image or preview model. You can pick any other.
**More options** holds the provider's name and the longest answer it may write.

**Save and check** asks the chosen model one short question with your key — a few
tokens — and says in one line what happened:

- **it answered** — *"answered in 850 ms"*, with how many models the key can use. It is
  saved.
- **the key, the address or the model is wrong** — the provider's exact error, ending
  in what to do (paste the key again, check the address, choose another model).
  Nothing is saved.
- **the key works, but the provider is out of credit, rate-limiting or down** — it is
  saved, with that warning: the form is right, the provider is not answering yet.

The check gives up after 40 seconds (85 for a model on this server, which may still be
loading into memory) rather than leaving the page waiting.

Once one is saved, adding another sits behind **Add a provider**. Each saved provider
shows its model, what it answers for, and its last check; **Check** asks it again,
**Edit** changes the model or the key (the models load straight away — its saved key
never leaves the server), and **Use** makes it the one in use. Keys stay on the server
and are never shown again — the page shows only their last four characters.

The provider bills you for what the AI asks it. Tia has a daily token budget
(**AI → Settings**) and monitoring has its own (**AI → Monitoring → The AI for
monitoring**); when one is used up it stops until midnight (the server's own clock) and
tells you so. **AI → Settings** shows what each used today.

---

## Tia, the assistant

Tia is SixPanel's AI assistant. Ask in your own words, in your own language — she
answers in the language you write in. Some things she does well:

- *"Is my server healthy?"* — she runs the full health check and tells you what needs
  attention first.
- *"Why is the shop slow?"* — CPU, memory and disk history, the slowest database
  queries, the PHP slow log, the error logs.
- *"Create a WordPress site on blog.example.com"* — creates the site, points the domain
  at the server through Cloudflare, gets the HTTPS certificate and installs WordPress.
- *"Deploy the latest code to the shop"*, *"roll the storefront back"*.
- *"Take a backup now"*, *"restore yesterday's database"* (she asks you first).
- *"Who tried to log in last night?"*, *"block that address"*.
- *"Set the Stripe key on my Node.js app"* — she asks you for the key in a secure field
  (see below) and restarts the app if it needs to.

**Run a full check-up**, on an empty conversation, asks for one report of
everything — health, services, CPU, memory and disk, the last hour's errors, backups,
domains and certificates, sign-ins and the firewall, updates — worst first, with what
she can fix. It only reads; nothing is changed.

While she works, the steps she takes fold into one line — *✓ 3 steps · Health check,
Read logs, Backups* — that opens to each step; a step that starts a job has **Open the
log** to watch it, and the header says what she is on. Her answer appears word by word.
After an answer she suggests what you might ask next.

- **Copy** beside an answer copies it; a block of code has its own **Copy**.
- **Try again** beside the newest answer asks the same question again; if a turn failed,
  the reason is shown where it happened, with **Try again**.
- **Edit** beside your last message (or **↑** in an empty box) puts it back in the box
  to change and send again; **Save as a prompt** keeps it for later.
- Type **/** in the box for commands — `/checkup`, `/backup`, `/logs`, `/deploy`,
  `/automate`, `/new` — and your saved prompts. **↑ ↓** move, **Enter** picks one.
- **Enter** sends, **Shift+Enter** starts a new line, **Esc** stops Tia while she works,
  **Ctrl+K** (⌘K) puts the cursor in the box.

Under the message box: **Ask mode / Auto mode** — switch between them right there — and
which provider and model answer, with the tokens used today; click that line to change
them on **AI → Settings**.

**Conversations.** On the AI page the list on the left holds your conversations, newest
first, grouped *Today*, *Yesterday*, *Previous 7 days* and *Earlier*; runs of an
automation have a group of their own. Each one is named from its first message —
**Rename** or **Delete** it from its row, or search the list. The one Tia is answering
shows a spinner. The list folds away for more room, and on a phone it opens from
**Conversations**.

She knows every kind of project on the server: 6amMart projects (the admin panel, the
storefront, the apps' backend) and websites — static, Node.js, PHP, WordPress and
Create with AI.

### Ask Tia on any page

The **Ask Tia** button opens Tia beside the page you are on. She is told the
page — "about: Backups" under the box says so — and the project or website it belongs
to, and her suggestions start with one for that page: on a website's **Domain &
HTTPS**, *"Check shop's domains and HTTPS certificates, and fix what is wrong."*; on
**Backups**, *"When was the last backup, and is it safe? Take one now if it is old."*
Move to another page and she follows. **Open the AI page** carries the same
conversation over to the full page.

### Ask mode and Auto mode

**AI → Settings → What Tia may do on her own**:

- **Ask mode** (the default) — every change waits for your approval. Reading never
  asks.
- **Auto mode** — a change the server can take back (a restart, a deploy, a new
  domain, a setting) runs on its own; the rest still asks.

Whatever the mode, a change that **cannot** be taken back always asks first: deleting
a project or files, restoring a backup over live data, writing a file, running a real
database search-and-replace, stopping the database or the web server, updating the
panel or the operating system, restarting the server.

### Approving

An approval appears in the conversation as a card: what she wants to do, in plain
words, whether it can be taken back, and **What exactly will run**. A file change
shows the lines before and after. **Approve** or **Decline** — a decline is final: Tia
is told not to reach the same result another way, and anything else she then tries
asks you on a card of its own.

A few actions also need **your admin password** on the card (and your two-factor code
when two-factor login is on). The password is checked by the panel and never reaches
Tia or the conversation.

### Giving her a password or key

When a step needs a secret — an SMTP password, a Stripe key, a git token — Tia asks
for it in a **secure field** in the conversation. What you type goes
straight to the server; Tia only ever gets a placeholder, and the value is masked
in every log.

### What she can never do

- change who gets into this panel — the admin password, two-factor login, the login
  allowlist, temporary logins, the entry code;
- read your passwords or keys back (provider keys, the backup password, `.env`
  secrets, database passwords);
- approve her own request, turn on her own root commands or make herself a token.

Every change the AI makes is on the **Activity** page, marked **AI** — hover the badge to
see who asked: Tia, AI monitoring, or an MCP client by its token's name.

### Root commands

Off by default. **AI → Settings → Root commands** lets Tia run a shell
command as root for what the panel's own tools cannot do. Turning it on needs your
password, and then **every single command** asks for your password again on its
approval card.

Without it, Tia still reads the machine through a fixed list of read-only
programs (`df`, `free`, `journalctl`, `systemctl status`, `nginx -t`, `tail` of the
logs, `dig`, `curl` …) — no shell, nothing that changes anything.

### Automations: what she does on a schedule

**AI → Automations** — tell Tia what to do on a schedule and where to send her report:

- *"Every morning at 9, check the backups and the disk and send me a summary on
  Telegram"* — ask her in the chat, and she sets it up once you approve it; or press
  **New automation** and fill in the name, what she should do, when (every hour, every
  few hours, every day, every week — in the server's own time) and where the report
  goes: only this page, the alert email, or one of your alert channels (Telegram,
  Slack, Discord, a webhook — added under **AI → Monitoring**).
- **Start from one** offers four ready ones: a daily health report, a weekly security
  review, *tell me when the disk is above 85%* and *confirm last night's backup*.
- **Only when something needs me** keeps a watch quiet: the run is recorded, and a
  report is sent only when there is something to say.

Each run is a conversation of its own — **Open the run** shows every step she took —
and is on the **Activity** page. **Run now** runs it at once; **Pause** stops it until
you resume it.

What a run may do, with nobody watching:

- On its own she **only reads**. Tick **May make safe changes** and a run may make
  changes the server can take back — and only while Tia is in **Auto mode**; in Ask
  mode each one waits for your approval.
- Anything that **cannot** be taken back never runs unattended: it waits on the AI page
  for your approval, and you are told. Root commands are never available to a run.
- A run counts against Tia's daily token budget and is skipped when it is used up.
- A run that was going when the panel restarted is marked *interrupted* and is not run
  twice; one that fell due while the panel was down runs once when it is back.

Tia can list, create, pause and delete automations for you from the chat — each of
those asks you first, in Auto mode too.

### What she remembers

Tia keeps short notes across conversations ("the shop runs the untouched
vendor code", "reports in Hindi"). **AI → Settings → What Tia remembers**
shows them; delete anything wrong, or add what she should know.

---

## Monitoring

**AI → Monitoring.** The panel checks the server all the time — with or without AI,
and without spending a token:

- every minute: services that stayed failed (two checks in a row — the server's own
  restarts and self-healing get their minute first), jobs that failed, CPU, memory and
  disk pressure, a forecast of when the disk fills up, sign-in attacks;
- every five minutes: every project's and website's address, asked through this
  server;
- every ten minutes: the health checks and each website's new errors.

**What it watches** lists each of those checks with how often it runs, when it last
ran and what it found. Watching is on from the start and costs nothing; the switches
under **What it does** turn it, Tia's part and the alerts on or off. If monitoring
is switched on but its checks are not running in the panel, the tab says so in place
of "Watching this server" — restart the panel (`sudo sixpanel panel restart`).

A problem opens an **incident**; one that stays gone for two checks closes itself.
An open incident that gets worse is alerted again, and its title keeps up ("Disk 97%
full", not the 90 it opened at). A website with errors stays one incident while they
keep coming within the hour. **Check now** runs every check at once, the address and
health checks included; **Full check-up with AI** opens Tia on the full
check-up. On an open incident, **Ask Tia** starts a conversation about it, and
**Analyse with AI** has Tia read it now. **Dismiss** says you know about it: the
incident stays quiet for as long as the problem lasts and closes by itself when it is
gone. If it gets worse — a warning becomes critical — it opens again.

### AI analysis and auto-fix

With **Let Tia analyse new warning and critical incidents** on, Tia reads each
new incident — the logs, the service states, what changed — and writes **the cause**
and **what to do**. She only reads. If she found a fix the server can take back — a
restart, a deploy, a setting — the incident gets a **Run the fix** button, which shows
exactly what will run; pressing it is your approval. The fix runs in the background:
the incident says it is running, then shows what it answered, and it cannot be started
twice at once. A fix that deletes, restores or restarts the whole server is written
into the steps instead: ask Tia for it, and approve it on its card.

A critical incident is alerted at once, and its analysis follows as a second message.
A warning's alert waits for the analysis — five minutes at most — so it arrives with
the cause. It goes out without one when monitoring's daily budget or analysis count is
used up, or when a panel restart cut the analysis short: an alert can be late, never
lost.

**Let Tia fix an incident on her own** goes one step further: for each incident
Tia may run **one** change that can be taken back (a restart, say), never the same
one twice in six hours. Whether the problem is gone is decided by the checks, not by
Tia.

**The AI for monitoring** (on the same tab) can use another provider or a cheaper
model than Tia, with its own daily token budget.

### Alerts and the daily report

With **Alert me about new incidents** on, a new warning or critical incident is sent
to the alert email and to your **alert channels**. The **Alerts** card on the
Monitoring tab shows both: the address the email goes to (or **Set up the alert
email**, which opens **Settings → Alerts**), and each channel — **Add a channel** for
**Telegram** (a bot token from @BotFather and the chat id), **Slack** or **Discord**
(an incoming webhook), or any **webhook** that takes JSON. **Send a test** checks one.
Channels can also carry the daily report and approval requests from MCP clients. When
neither is set up, the card says plainly that nobody would be told about a problem.

**What was sent** lists the latest alerts and what each destination answered — sent,
refused with the destination's own error, or not set up — so a channel that stopped
working shows up here before you miss an alert.

A failed job is not emailed twice: the panel already emails a job the moment it fails,
with its last log lines, so monitoring sends it to your channels only. When Tia
analysed it, the cause and what to do are new, and that email does go out.

At most **six** monitoring emails an hour: an outage that opens many incidents is one
inbox, not dozens. Your channels still get every alert, and **AI → Monitoring** lists
every incident.

Alerts are plain text and never contain a link into the panel — the panel's address
is a credential.

**Send a daily report at** mails a short summary of the last 24 hours: incidents,
jobs, backups and resources. **Make a report now** writes one on demand, for the page —
it is emailed and sent to your channels only when the daily report is on.

---

## Connect your own agent

**AI → Connect.** SixPanel is also an **MCP server**, so an AI agent on your own
computer can manage the server with the same tools as Tia.

Pick your client — **Claude Code**, **Claude Desktop**, **Cursor**, **VS Code**,
**Windsurf**, **Hermes Agent** or **Other** — and how it connects. The tab then shows the
exact line or file to paste, and where it goes for that client (`claude mcp add …` for
Claude Code, the JSON for Claude Desktop, Cursor, VS Code and Windsurf, the YAML for
Hermes Agent), each with a copy button.

### Over SSH

Works with every client that can start a command, and needs no token. `<server-ip>` is
the server's own IP address — not the panel's domain, which Cloudflare fronts and which
carries no SSH:

```
ssh root@<server-ip> sixpanel mcp
```

For Claude Code: `claude mcp add sixpanel -- ssh root@<server-ip> sixpanel mcp`. On
servers that do not let root log in — stock AWS and Google Cloud Ubuntu images — the
line is `ssh ubuntu@<server-ip> sudo -n sixpanel mcp`; the Connect tab shows the one that
works on your server, with the lines for Claude Desktop, Cursor, VS Code, Windsurf and
Hermes Agent. Over SSH you are root already, so changes run without the panel asking; a root
command still needs root commands switched on and your password in the panel.

### Over HTTPS with a token

For clients that connect to an address. This needs the panel on its own domain
(**Security → Access**, see
**[Give the panel your own domain](https://test-allsweb.allsweb.net/sixpanel/docs/security#6-give-the-panel-your-own-domain)**) —
MCP clients refuse the certificate the panel has on its bare IP address. The address
is `https://<panel domain>/mcp`.

The token is made right there, for the client you picked:

- **Name** — filled in with the client's name;
- **Expires after** — 30 days, **90 days** (the default), 1 year or never;
- **Permission** — **look only** (the default), *look + changes that can be undone*,
  or *everything Tia can*;
- **Dangerous actions** (only for *everything*) — wait for your approval in the panel
  (the client waits too; you are alerted on your channels), or let the client's own
  confirmation count;
- **Projects** — the whole server, or only the projects you tick.

**Create the token**: a look-only token is made at once; one that can change anything
needs your admin password. The token is shown **once**, together with the ready
settings for your client with the token already in them — copy them now; the panel
keeps only a fingerprint. **Make another token** starts again. The **Tokens** table
shows what each can do, when it expires, when it was last used and from where;
**Revoke** stops every client using it at once.

A wrong, missing or revoked token gets the same bare "not found" as any other address,
so the endpoint tells a stranger nothing.

---

## Privacy

What Tia sends to your provider: your messages, the tools' answers, and a
short description of the server (its projects, the page you are on, open incidents,
her notes). Before anything leaves the server, passwords, keys and tokens are masked —
the panel's entry code, API keys of every common shape, `.env` secrets, database and
SMTP passwords — in files she reads as well: a site's `.env` or `wp-config.php` reaches
the provider with those values as `****`. Her read-only commands cannot open a `.env`,
a private key or the panel's own data at all.

Conversations are stored on the server (the newest 50) and can be deleted on the
**Tia** tab.

---

## If something goes wrong

| What you see | Why, and what to do |
|---|---|
| "Set up Tia first" | No provider yet: pick a card right there, paste the key, **Save and check**. |
| **Save and check** says the key, address or model is wrong | Nothing was saved. Do what the message ends with — usually paste the key again, or choose another model from the list. |
| A provider shows "the key works, the model did not answer" | The provider is out of credit, rate-limiting or down. Top up or wait, then press **Check** on its row. |
| "Monitoring is switched on, but its checks are not running" | Restart the panel: `sudo sixpanel panel restart`. |
| "Nobody would be told about a problem" | Set up the alert email (**Settings → Alerts**) or add a channel on **AI → Monitoring**. |
| "today's AI budget … is used up" | It resets at midnight, or raise it: Tia's on **AI → Settings**, monitoring's under **AI → Monitoring → The AI for monitoring**. |
| An approval card expired | Nobody answered for 30 minutes (10 for MCP clients). Ask again. |
| "root commands are switched off" | Turn them on under **AI → Settings** if you want it — each command still asks. |
| An MCP client gets "not found" | The token is wrong, expired or revoked, or the address is not the panel's domain. |
| An MCP client says the certificate is not trusted | Set up the panel's own domain, or use SSH. |
| An incident has no **Run the fix** button | The fix Tia found cannot be taken back (a restore, a reboot …) or needs a value she could not show you. Ask Tia: she asks you on a card. |
| Fewer alert emails than incidents | More than six in the hour. The channels have every one, and **AI → Monitoring** lists them all. |
