The second half of #234. =[registration] notify_admin= queues a notice to every instance admin when an account becomes active: an invite redeemed, or an open-mode signup that verified its address. Off by default; config load refuses it without =[mail] smtp_host=.
The unverified row an open signup creates is deliberately not reported. Anyone can post the signup form, so mailing on that would aim a flood at the admins; verification proves a mailbox. Recipients are the verified primary addresses of active admins with activity mail on, the same rule every other notice follows. The notice is enqueued, not sent inline, so a dead SMTP host lands in the admin page's Mail table rather than failing the registration that caused it.
The first half of the issue, =admin user list= on the web, is not in this branch. It needs =SSHOnly= dropped from the admin account commands, which also exposes them to full-scope API tokens. That is a decision about the threat model rather than a refactor, so it is written up as a comment on the issue instead of made here.