connectingNew policy

Application documentation

Using the governance platform

Practical guidance for the workflows available in the current local demonstration.

Start here

The portal reads tenant-scoped business records from the control plane. When a workflow is not implemented, its action is disabled or documented as preview-only. Use the section guides below for what works today and what remains intentionally limited.

Application section

Overview

Open section

Confirm connectivity and review the live tenant snapshot.

  1. Confirm the control-plane indicator is connected.
  2. Change the time range to update telemetry.
  3. Use Reset demo data only when you intend to remove demo-time mutations.
Current boundaryRuntime toggles are presentation controls until gateway lifecycle APIs are implemented.
Application section

MCP Catalog

Open section

Review MCP servers, tools, risk, and default access.

  1. Select a server to inspect its tools and scopes.
  2. Choose Register server to create a tenant-scoped pending entry.
  3. Use policies to govern tools exposed by approved servers.
Current boundaryAutomatic discovery and catalog approval are not yet implemented.
Application section

Policies

Open section

Create, activate, and simulate deny-by-default authorization rules.

  1. Create a draft with server, effect, priority, principal, and tool patterns.
  2. Open the persisted draft and activate it.
  3. Simulate a matching call and confirm the selected policy and outcome.
Current boundaryEditing, rollback, staged rollout, archive, and signed bundle delivery remain future work.
Application section

Sandboxes

Open section

Inspect boundaries and collect evidence from a real Docker agent.

  1. Open Air-gapped agent.
  2. Run the isolation test.
  3. Review identity, storage, privilege, workspace, and public-network checks.
Current boundaryThe demo runner is long-running and executes a fixed probe; per-run workload containers are next.
Application section

Agents

Open section

Review endpoint identity, status, bundle version, and posture.

  1. Compare online, offline, stale-policy, and revoked examples.
  2. Open an agent for its stable ID and last-seen details.
Current boundaryProduction enrollment, rotating credentials, posture ingestion, and revocation are not implemented.
Application section

Approvals

Open section

Persist a human decision for approval-required tool calls.

  1. Open a pending request.
  2. Approve or deny it.
  3. Refresh and confirm the reviewer and status persist.
Current boundaryA decision does not yet resume or terminate a waiting gateway call.
Application section

Audit events

Open section

Investigate decisions using outcomes, policies, and correlation IDs.

  1. Filter the current event window by outcome.
  2. Open a detail route to inspect decision context.
  3. Export the loaded tenant-scoped window as JSON.
Current boundaryProduction ingestion, retention enforcement, and SIEM delivery remain future work.
Application section

Administration

Open section

Preview organization, identity, credential, retention, and integration surfaces.

  1. Use Settings and organization routes to review planned enterprise capabilities.
  2. Treat displayed administration records as scenario-owned documentation.
Current boundaryAdministration mutation remains disabled until authenticated OIDC/RBAC and persistence contracts land.