Hub: everything on this hub, set by hub admins in Hub settings.
Team: each team, set by its admins in Team settings.
Account: each person, for themselves, on the Account page.
Satellite: each registered phone or Pi, either stored on the hub (its page under Satellites) or kept on the satellite itself (the phone's Settings screen, the Pi's .env).
This page lists every setting and permission with the levels where it exists: where to change something, who may do what, and how a value set at one level meets the others.
Default: what a level gets when it sets nothing itself, named after where it comes from: "Hub default (Off)", "Team default (On)".
Override: a lower level setting its own value instead of the default. The level above can allow it or not: "Teams may override", "Satellites may override".
Locked: a level above does not allow overriding. The setting shows its value, greyed, with "Locked by the hub" or "Locked by the team".
Hub admin: the hub-wide role (is_platform_admin in the code, where the hub level is still called platform).
Device: only the computer or phone someone signs in from, as in the two-factor "remembered devices". A recording phone or Pi is a satellite.
Satellite settings the hub sends (audio filter, upload queue, heartbeat, pre-upload drops): the satellite's own value when it overrides, otherwise the team's, otherwise the built-in default. A satellite's page shows, next to each setting, the default it would get.
On-satellite inferencehub 0.64: hub, then team, then satellite. Each level sets a value and says whether the level below may override it; a level that does not allow it wins over everything below. A change refused for that reason answers 403 LOCKED_BY_PLATFORM or LOCKED_BY_TEAM (the API codes keep the code names).
Hub switches over team options: a team can open itself to newcomers only while allow_public_teams is on, and publish a public page only while allow_public_pages is on.
Account over team: a person's bird-name languages win over the team language wherever that person reads names (web pages, PDF and CSV exports, shared links). Alerts and scheduled exports use the team language.
Legend: ✓ = the setting exists at that level. In the Satellite column, "hub" = stored on the hub for each satellite, "local" = kept on the satellite itself.
Phone (Settings screen): keep the screen on, record when the app opens, vibrate on detection, GPS on or off and its interval, manual position, name. The phone also remembers whether it was recording, so that an update resumes it.
Raspberry Pi (.env, OTAVI_SAT_*): capture mode and audio input, sample rate and chunk length, GPS mode and fixed position, whether the YAMNet gate runs, telemetry interval, data folder, log level. The Pi also holds starting values (inference mode, minimum confidence, range filter, recording profile, YAMNet threshold) that the hub replaces on its first configuration push.
Roles inside a team, lowest first: viewer, member, admin, owner. A hub admin counts as at least admin in every team. The registrant of a satellite is the person who registered it.
"Manage a satellite" means: a hub admin, an admin of the satellite's team, or its registrant while the team's policy is "members". A satellite's own key may act on that satellite only: rename it, rotate its key, edit its settings.