Sign in
This console shows nothing until you are signed in — not the queue, not identity administration, and not the dashboard.
This console shows nothing until you are signed in — not the queue, not identity administration, and not the dashboard.
Loading the queue…
| Received | Imported | Channel | Path | From | Subject | State | Age |
|---|
How your correspondence is flowing, stage by stage. Each
card shows the worst state of its parts and then lists them, so the colour
is never the whole story. Checked every 15 seconds — last at
—.
Left to right is outside to inside. Platform services sit
underneath because every plane depends on them. Probed live through the
gateway every 15s — last at —.
Loads .eml files through the same admission pipeline
as any other message (ING-FIL-001). Use it to bring existing
correspondence in — an archive, a client's forwarded mail — rather than to relay
something that has just arrived. For that, use
Compose.
This decides whether the platform may ever answer it, so it is asked before the files rather than after.
There is no option here for live mail, and
that is deliberate. An imported message is admitted with a non-live origin
(ING-FIL-003) and the run token minted for it carries no capability
to send (ING-FIL-004) — so importing a customer's old question
cannot result in them being emailed about it weeks later. The service refuses
origin=live outright; this list is not what enforces it.
No files chosen.
| File | Outcome | Subject | Why |
|---|
This enters the same admission pipeline as a message that
arrived by mail or came in on a file import (ING-SUB-001). Nothing
downstream can tell it apart, and nothing here is trusted more than a message
relayed by a tenant's own backend.
Submitted on behalf of your signed-in
tenant. There is no tenant field here and typing one would have no effect:
the tenant comes from your session token (ING-SUB-003).
Submitting…
What this tenant's intake accepts. Enforced by
ingestion-svc before a request is buffered or parsed
(ING-LIM-002), and owned here as configuration
(CFG-COV-016) so a change is versioned, revertible and audited.
A tenant may set a limit below the platform ceiling and
never above it (ING-LIM-003). A value of zero is refused: stopping
intake is a tenant lifecycle action, not a limit.
Intake limits could not be read.
| Limit | In force | Platform ceiling | Source |
|---|
Not reported by this deployment.
CON-ADM-014 requires the intake-path and publication flags shown
here, and ingestion-svc exposes no endpoint that carries them. This
panel shows nothing rather than an all-clear it cannot support: an operator
looking at a stalled queue would otherwise read "no problems" from a page that
never asked.
Of the five intake paths, two accept anything today — file import and the submission endpoint behind Compose. Publication to the event bus is not wired, so nothing downstream is notified of an admitted message.
| Started | State | Message | Thread | Definition | Spent |
|---|
Who this tenant corresponds with — accounts and prospects, and the
people, systems and agents acting for them. An index, not a customer store
(PTY-MOD-007a): identity and the association graph only. Orders,
invoices and prices stay in the tenant's own system, reached live through
external_ref.
Loading parties…
| Name | Kind | Relationship | External ref | Since |
|---|
A party added here is created confirmed: you asserted it, so it does not appear in the unconfirmed queue above. Parties may also reach this list by other routes — this console is told what exists, not how it got here.
Tenants are platform-plane (CON-IDN-002). Everything inside a tenant is tenant-plane. There is no identity directory — members are added by exact issuer and subject, because a searchable one would disclose which addresses exist in other tenants (CON-IDN-004).
| Name | Status |
|---|
One action, not four — IDN-TEN-005 makes the
tenant, its default workspace, the first membership and the first admin role
atomic.
| Identity | Status | Roles |
|---|
Adding a member grants no role — membership and role assignment are separate acts with different blast radii (CON-IDN-005). Disable suspends and is reversible; Remove from tenant cascades (CON-IDN-007).
A revision is immutable and publication is a separate act
(CFG-VER-001, CFG-VER-005). Saving changes nothing
until a configuration set is published, and every row below says which state
it is in.
Loading configuration…
| Domain | Effective value | Came from | Revision |
|---|
"Came from" is provenance (CFG-RES-002) —
which scope in the chain supplied the value. It is how you answer why a
workspace behaves differently from its tenant.
| Name | Domain | Scope |
|---|
The configuration vocabulary could not be read from config-svc, so there is nothing to choose from and this form is disabled. It is disabled rather than left enabled-but-broken, because a button that does nothing when pressed is worse than one that says why.
The domain list comes from config-svc's published
registry, so it is exactly what this deployment accepts
(CON-CFG-001) rather than a copy that drifts.
| Revision | State | Comment | Author | Created |
|---|
| Version | State | Comment | Actor | Published |
|---|
A set is the unit of publication and spans objects
(CFG-VER-006). Rollback produces a new published set
(CFG-VER-007), and superseded sets are hidden here, never
deleted — they are what a rollback restores, and what says which
configuration produced a past response (CFG-VER-003,
CFG-RES-004).
Consumption for this tenant. Broa's internal provider cost
and margin are not shown here and are not sent to this page
(CON-MTR-003).
Loading usage…
A budget does not stop
correspondence. If quota state is unavailable the platform keeps
processing messages (MTR-QTA-004) — a budget is a spend
control, not a kill switch, and treating it as one is how a tenant's
customers get ignored.
Budgets are not persisted yet: quota configuration
(MTR-QTA-002) has no store behind it, so this control
demonstrates the consequence text and saves nothing.
The published metering vocabulary
(MTR-COV-023): what can be measured, in what unit, and which
dimensions every event must carry. A meter absent from this list cannot be
recorded.
| Meter | Unit | Aggregation | Components | Required dimensions |
|---|
Every decision and action, including reads
(AUD-COV-001, AUD-COV-002). Reading this page is
itself an audited access.
What this platform can record, and which types are
critical — AUD-CAP-004 forbids the action from completing
until a critical event is durably persisted.
Loading audit records…
| Correlation |
|---|