AI Creative Studio & Marketing Assets Admin Manual¶
Module: AI Creative Studio Operations & BYOK Administration (M2)¶
Product: ebosAi AMP
Classification: Internal — Confidential
Version: 2.2 (BYOK Multi-Model Integration & Plan Gating)
Last Updated: September 2026
[!TIP] User Manual Reference:
For complete instructions on creative prompt engineering, tone of voice customization, storyboard generation, and marketing copy formats, refer to the AI Creative Studio User Manual (user-manual/AI_Creative_Studio_User_Manual.md).
1. Overview for Administrators¶
The AI Creative Studio at /admin/ai-studio is the company's central AI creative generation engine. As a Company Administrator (admin role) or Manager (manager role), you are responsible for:
1. Configuring Bring-Your-Own-Key (BYOK) Credentials: Connecting tenant-owned LLM API keys (OpenAI, DeepSeek, Anthropic, Gemini, OpenRouter, or custom endpoints).
2. Managing Role-Based Access Control (RBAC): Granting or revoking granular menu permissions for internal staff users.
3. Overseeing Subscription Plan Limits: Monitoring R2 asset quotas and plan tier gating.
4. Publishing to Partner Portal: Governing marketing collateral saved into Cloudflare R2 and published to /partners/assets.
flowchart TD
A["Admin Configures BYOK Keys (/admin/ai-studio)"] --> B["AES-256-GCM Encryption in PostgreSQL (mh2603.tenant_ai_configs)"]
B --> C["RBAC & Plan Gate Validation (require_module('ai-studio'))"]
C --> D["Marketing Team Generates Collateral (User Guide Workflows)"]
D --> E["1-Click Persistence: Cloudflare R2 + mh2603.marketing_assets"]
E --> F["Admin Asset Registry (/admin/assets)"]
F --> G["Published to Partner Portal (/partners/assets)"]
G --> H["Partners Download via 15-Minute Secure Presigned URLs"]
2. Role-Based Access Control (RBAC) & Governance¶
The platform enforces strict role boundaries for the AI Studio:
| Role Code | Access to /admin/ai-studio |
Access to /admin/assets |
Key Management Permission |
|---|---|---|---|
admin (Company Admin) |
Full Access | Full Access | Can connect, update, test, and revoke BYOK provider keys. |
manager (Marketing Manager) |
Full Access | Full Access | Can generate creatives and save to R2; key changes logged to audit. |
accountant (Staff Portal) |
Restricted (403) | Restricted (403) | No access. Staff portal is limited to commission verification. |
user (Partner / Influencer) |
Restricted (403) | Restricted (403) | No access. Partners access finished collateral at /partners/assets. |
Granular Level-1 & Level-2 Menu Permissions¶
Admins can grant or revoke AI Studio access for specific internal users under Internal Users (/admin/users):
- Permission Key: ai-studio (/admin/ai-studio) under the "Marketing & Links" category.
- When toggled off for a user, the AI Studio menu is suppressed from their sidebar, and API requests to /api/v1/admin/assets/ai/* return HTTP 403 Forbidden.
3. Subscription Plan Gating & Quotas¶
Access to the AI Studio is gated at both the frontend routing proxy and backend dependency layer:
| Feature Dimension | Starter (plan_1) |
Professional (plan_2) |
Enterprise (plan_3) |
|---|---|---|---|
Module Entitlement (ai-studio) |
Disabled | Enabled | Enabled |
Sidebar Route (/admin/ai-studio) |
Hidden / Gated | Active | Active |
| Supported Providers | — | OpenAI, DeepSeek, Anthropic, Gemini, OpenRouter | All Providers + Custom LLM Endpoints |
| Max Marketing Assets in R2 | 10 Assets | 100 Assets | Unlimited Assets |
| Backend Dependency Enforcement | HTTP 403 (Upgrade Plan) |
HTTP 200 |
HTTP 200 |
Backend Plan Gate Enforcement:¶
All AI Studio router endpoints in backend/app/api/v1/assets.py enforce:
4. BYOK Security & Key Management¶
4.1 Encryption Architecture¶
- Zero Exposure: Provider API keys are never returned in plaintext in API responses, logs, or frontend state.
- Encryption at Rest: Keys are encrypted using AES-256-GCM using the server's
FIELD_ENCRYPTION_KEYbefore insertion into themh2603.tenant_ai_configstable. - Frontend Display: The API returns only a masked preview string (e.g.,
sk-...9f2c) and a booleanhas_api_key: true.
4.2 Step-by-Step Provider Setup¶
- Log in with
admincredentials and navigate to/admin/ai-studio. - Click Configure Provider & Keys in the upper-right corner.
- Select your organization's AI provider:
- OpenAI: Requires standard
sk-...API key with model permissions (gpt-4o,dall-e-3). - DeepSeek: Cost-effective high-performance reasoning (
deepseek-chat,deepseek-reasoner). - Anthropic: Claude 3.5 Sonnet / Haiku keys.
- Google Gemini: Gemini API key from Google AI Studio.
- OpenRouter: Universal key supporting open-weight models (Llama 3.3, Mistral, Qwen).
- Custom / Self-Hosted: Custom endpoint URL (e.g.,
https://llm.internal.company.com/v1) for private vLLM, Groq, or Ollama deployments. - Click Save Configuration. The backend tests the connection and establishes the active provider.
5. Cloudflare R2 Storage & Asset Distribution¶
When marketing teams click Save to Marketing Assets in the AI Studio:
1. The backend (POST /api/v1/admin/assets/ai/save) generates the production asset file (SVG, PNG, or Markdown).
2. The file is streamed to the tenant's Cloudflare R2 bucket (CLOUDFLARE_R2_BUCKET).
3. An asset record is inserted into mh2603.marketing_assets with category tagging (Images & Banners, Videos & Reels, Social Copy & Scripts).
4. The asset becomes immediately visible in:
- Admin Asset Library (/admin/assets): Admins can monitor download counts, preview files, or delete outdated collateral.
- Partner Self-Service Portal (/partners/assets): Partners can view collateral and generate 15-minute presigned download URLs (GET /api/v1/portal/assets/{id}/download).
6. Administrative API Reference¶
All routes require amp_admin_token authentication with admin or manager role and ai-studio plan entitlement:
| Method | Endpoint | Plan Gate | Description |
|---|---|---|---|
GET |
/api/v1/admin/assets/ai/config |
Pro / Ent | Retrieve tenant BYOK provider, model, and active status. |
POST |
/api/v1/admin/assets/ai/config |
Pro / Ent | Save or update BYOK provider credentials. |
POST |
/api/v1/admin/assets/ai/generate |
Pro / Ent | Generate marketing copy, graphics, or video storyboards. |
POST |
/api/v1/admin/assets/ai/save |
Pro / Ent | Save generated creative into Cloudflare R2 and asset registry. |
GET |
/api/v1/admin/assets |
All Plans | List all marketing assets with category filtering. |
DELETE |
/api/v1/admin/assets/{id} |
All Plans | Soft-delete an asset from the library. |
GET |
/api/v1/admin/assets/{id}/download |
All Plans | Redirect to 15-minute presigned Cloudflare R2 download URL. |