Manage LSBS · 5 min
Servers and access
Understand self-managed and managed servers, server identities, and removal choices.
Choose the management boundary
A self-managed server sends signed monitoring reports while changes stay in local WebAdmin. A managed server additionally enrols a separate outbound control agent for a closed set of typed operations. Neither mode opens a generic inbound agent port.
While managed mode is active, local WebAdmin settings remain readable but API writes return a managed read-only response. This prevents two control planes from changing the same configuration.
Per-server identities
Every server has separate bootstrap, repository, monitoring, and—when selected—managed-control credentials. Each can be revoked for one server without affecting the rest of the account. Private signing keys remain on the server.
People remain on the appliance
The People action opens that server’s own WebAdmin workspace in the signed-in browser. Names, profiles, memberships, and device ownership do not pass through or persist on lsbs.cloud.
Disconnect or uninstall
Disconnect from lsbs.cloud removes the portal relationship and revokes its server credentials. Uninstall LSBS is a separate high-risk, backup-gated plan executed by the server. It removes the platform while preserving configuration and business data rather than purging them.
A root administrator can also run the local managed-agent emergency exit. It erases the managed identity and restores local WebAdmin writes even when the portal cannot be reached.