Platform

One interface. Explicit workflow boundaries.

The web app brings operating surfaces together while keeping investigation, execution, alerts, security, compliance, and access as distinct records.

  • Configured human identity and role checks
  • Per-agent identities and signed workloads
  • Encrypted storage or configured external secret resolution

Operating model

How work moves.

Work does not automatically move through one universal lifecycle. Each surface owns its state, prerequisites, actions, and retained output.

Connect

Expose typed API capabilities

Tested connections make operation discovery, schemas, reads, and eligible actions available to target-aware workflows.

Investigate

Collect bounded evidence

A case uses available read-only tools and retains evidence, method, findings, and notes.

Execute

Use an explicit work path

Managed jobs are scoped, signed, queued, and reported; investigation mutations use governed proposals.

Review

Inspect the owning record

Cases, jobs, alerts, findings, calendar occurrences, and access requests keep distinct histories.

MCP and API reach

Use the underlying API surface as an operating capability.

Spec-backed integrations share a common MCP contract: search operations, retrieve an operation schema, and invoke an eligible capability. This lets one workflow cross the configured identity, cloud, infrastructure, workload, monitoring, security, and repository surfaces it needs instead of stopping at one vendor-specific tool namespace.

Intent

Describe the desired state

Start with the operational outcome, whether it is an existing configuration to capture or a new one to design.

Discover

Search the distributed specifications

Find relevant operations semantically or lexically, then retrieve their exact schemas and safety hints.

Model

Compare current and desired state

Combine live reads, repository content, target relationships, and operator constraints into a concrete design.

Retain

Create code or a governed action

Propose complete repository files, or use a supported proposal, signed playbook, or catalog app runtime.

Existing estate

Convert configuration to IaC

Read current state, inspect any existing repository, author complete desired-state files, and propose the change for review.

New design

Build from schema, not memory

Use the available operation and request shapes to design new configuration, including cross-service identity, cloud, and device-management work.

Governance

Discovery is broad; authority stays narrow

Reads execute only within configured permissions. Writes create a durable proposal where supported or fail closed when no mutation lane exists.

Retention

Keep the result in code

A repository pull request turns the outcome into a diff, review history, and reusable desired state instead of a transient chat or console change.

People

Human identity

Dashboard access uses the configured identity path and role checks. Human sessions stay separate from agent authentication and runtime credentials.

Agents

Per-agent identities

Each agent has its own identity, polls for queue work, verifies signed workloads, and returns logs and status.

Secrets

Your store, not ours

Sensitive values can use encrypted platform storage or a configured external secret connection. Operators select and test the path a workflow uses.

Execution

Queued, not fire-and-forget

Managed playbooks, schedules, and routines dispatch through explicit execution records with target scope, state, timestamps, and returned output.

Appliance model

Bootstrap and manage a known local runtime.

The appliance path bootstraps the base runtime and deployment controller. Optional apps use the same catalogue, configuration, installation, reconciliation, and health model. The same lifecycle can carry additional packaged runtimes for new operational workflows.

Core

Known local runtime

A defined bootstrap path installs the base local runtime and deployment controller.

Baseline

Optional apps

Select, configure, install, reconcile, and inspect the apps required by the environment.

Support

Extensible runtime path

Package additional engines through the same app contract so configuration, deployment jobs, routes, health, and changes stay visible.

Edge model

Controlled exposure

Ingress configuration and synchronization expose the intended routes and current state for review.

Next step

See it on your own stack.

Trace a real workflow across identity, signing, secrets, proposals, queues, agents, and the appliance runtime.