Skip to content

Console reference — every screen and the permission it needs

This page is the map of the console. It lists every route the application mounts — not a selection, not the ones somebody remembered to write up — with the permission a principal needs to enter it and where to read more.

It is generated. The roster comes from web/src/features/route-census.json, the append-only census that registry.route-conservation.test.ts pins against the built router, so a screen cannot be added, moved or lost without this page changing with it. Each screen’s name and one-line description are the console’s own strings, taken from the same translation catalog the sidebar renders, so what you read here is what you see in the product.

  • Screen — the name the sidebar and the command palette use.
  • Path — the URL under your deployment’s console origin. It is a published contract: a bookmark, a runbook deep link and a docs cross-reference are all this string.
  • Requires — the RBAC permission. any signed-in user means the route is open to every authenticated principal; no sign-in means it is served before there is a session at all.
  • Reference — the page the console’s own help link opens for that screen.

The five headings below are the console’s hubs, in the order the sidebar renders them.

The console publishes 59 routes. Every one of them is in the tables below, with the permission it requires and the reference page its in-product help link opens.

ScreenPathWhat it isRequiresReference
Overview/Estate overview and health at a glanceany signed-in userdocs home
Claude Code/agentopsCreate, attach to and govern Claude Code sessions — no SSHsessions:run:readhow-to/run-claude-code-with-olivares
Backups/backupsTrigger, schedule, download and restore backups, with a second confirmation on the destructive path.system:adminhow-to/backup-and-restore
Health & SLA/healthAgent and MCP uptime and SLAshealth:status:readreference/modules/xxii-health
Kill switch/killswitchEmergency stop, dual-control recovery and guardian containmentgovernance:killswitch:readhow-to/cookbook/kill-switch-drill
Logs/logsThe live engine log stream, filtered by level and module, with search and pause.system:adminhow-to/troubleshooting
Observability/observabilityIngestion health by standard and trace drill-downhealth:status:readreference/modules/observability
Sandbox/sandboxIsolated agent testing and replaysandbox:run:readreference/modules/xvii-sandbox
Sessions/sessionsLive agent operation and timelinessessions:live:readreference/modules/ii-sessions
Tenants/tenantsWithdraw or restore a tenant’s servicesystem:adminhow-to/troubleshooting
Voice/voiceVoice and realtime sessionsvoice:session:readreference/modules/xvi-voice
Work/workThe durable cross-session backlog: items, dependencies, acceptance and decisionssessions:work:readreference/modules/ii-sessions
Workspace/workspaceAgents, sessions, resources and activity scoped to one workspacetenant:readreference/modules/xx-multi-tenancy
Workspace templates/workspace-templatesReusable session configuration snapshots: hooks, settings, connectors and policies.sessions:template:readreference/modules/ii-sessions
ScreenPathWhat it isRequiresReference
Alerting/alertingRoute findings to destinations and inspect deliveriesnotify:route:readreference/modules/xv-notify
Automations/automationsAll three automation rails and their trigger catalogorchestration:schedule:readreference/modules/iv-orchestration
Webhooks & events/eventingOutbound webhook subscriptions, their delivery log and the dead-letter queue.eventing:subscription:readreference/modules/eventing
Orchestration/orchestrationAgent-to-agent coordination and schedulesorchestration:graph:readreference/modules/iv-orchestration
ScreenPathWhat it isRequiresReference
API Playground/api-playgroundInteractively explore and test the control-plane APItenant:adminreference/modules/xix-api-manage-as-code
MCP & skills/capabilitiesGovern MCP servers, skills and toolscapabilities:catalog:readreference/modules/v-capabilities
Catalog/catalogCurated, approved agents and capabilitiescatalog:entry:readreference/modules/xiv-catalog
Protocol bindings/communications/protocol-bindingsCompose and reconcile governed A2A and MCP bindingssessions:protocol-binding:readreference/modules/ii-sessions
Deployment/deployProvision and wire agents to infrastructuredeploy:deployment:readreference/modules/vii-deploy
Inventory/inventoryDiscover and catalog every agent, MCP and modelinventory:catalog:readreference/modules/i-inventory
Knowledge/knowledgeKnowledge bases, RAG and data lineageknowledge:kb:readreference/modules/viii-knowledge
Model Operations/model-operationsOwned models, admission and deploymentsmodels:registry:readreference/modules/xxiii-model-operations
Models/modelsModels, routing and provider keysmodels:catalog:readreference/modules/x-models
Setup wizard/onboardingStep-by-step deployment configurationsystem:adminstart/quickstart
Platforms/platformsDeploy surfaces, compliance matrix and per-platform model lifecyclemodels:platforms:readreference/modules/x-models
ScreenPathWhat it isRequiresReference
Access map/access-mapWhat each agent reads and writes (R/RW)accessmap:graph:readreference/modules/iii-access-map
AgentCore export/agentcore-exportPlan and apply the Cedar policy export to AWS AgentCore, and review what would change before it does.governance:agentcore-export:adminreference/modules/vi-governance
Claude Code governance/claude-policyManaged policy, hooks, MCP, sandbox and policy-as-codegovernance:claude-policy:readhow-to/connectors/claude-code-hooks-pep
Control console/consoleOnboard users, connect SSO/IdP, and shape workspaces and agent-groups.tenant:adminreference/modules/xx-multi-tenancy
Identity & NHI/identitySSO, SCIM, the NHI roster and the WIF graphgovernance:identity:readreference/modules/vi-governance
Inference proxy/inference-proxyProxy gates, egress DLP rules and device approvalsinferenceproxy:config:readreference/modules/inferenceproxy
Permissions/permissionsIdentity, roles and approvalsgovernance:identity:readreference/modules/vi-governance
Rate limits/rate-limitsAnthropic rate-limit inventory (read-only)models:ratelimits:readreference/modules/x-models
Data residency/residencyPin each org to a region, or leave it unpinnedsystem:adminreference/modules/xiii-compliance
Routine policies/routine-policiesCadence floors, concurrency caps, approval requirements and cron allowlists for Claude Code routines.governance:routine:readreference/modules/vi-governance
ScreenPathWhat it isRequiresReference
Claude Code Adoption/adoptionProductivity, acceptance & model mixadoption:metrics:readreference/modules/claudeadoption
Agent Artifacts/agent-artifactsSkills, MCP extensions and instruction files — registry, posture and supply-chain BOMmodels:registry:readreference/modules/xxiii-model-operations
Supply chain/attestationRelease attestation — SLSA, SBOM, VEX and Scorecardobservability:attestation:readhow-to/verify-a-release
Audit ledger/auditTamper-evident evidence ledgeraudit:readreference/modules/ix-security
Compliance/complianceFrameworks, controls and evidencecompliance:framework:readreference/modules/xiii-compliance
Dashboards/dashboardsExecutive KPIs and reportingany signed-in userreference/modules/xxi-executive-dashboards
Evals/evalsQuality, evals and regressionevals:run:readreference/modules/xii-evals
Cost & FinOps/finopsToken cost, budgets and spendfinops:spend:readreference/modules/xi-finops
Posture export/posture-exportExport ground-truth posture for a control towerposture:export:readreference/modules/posture-export
Recordings/recordingsPrivileged session recording and replayrecording:session:adminreference/modules/recording
Red-teaming/red-teamAdversarial testing of your agentsredteam:target:readreference/modules/xviii-redteam
Reports/reportingGenerate and download governance reportsreporting:report:readreference/modules/reporting
Security/securityGuardrails, forensics and anomaliessecurity:finding:readreference/modules/ix-security
Session viewer/session-viewer/$id (deep link only)The full timeline of one recorded session, reached from a row in Recordings rather than from the sidebar.recording:session:adminreference/modules/recording
Team costs/team-costsSpend attributed by team, expandable into the per-project and per-model breakdown.finops:spend:readreference/modules/xi-finops

These are mounted outside the feature registry. The ones marked no sign-in are served before there is a session — they are the only console routes that are.

ScreenPathWhat it isRequiresReference
Accept an invitation/accept-inviteWhere an emailed invitation link lands: the invitee sets a password and joins the workspace, with no prior session.no sign-in
Sign in/loginThe credential and token sign-in page for an already provisioned account.no sign-in
Settings/settingsWorkspace and account settingsany signed-in user
First-run setup/setupThe one-time page that turns a fresh deployment into a usable one: it consumes the setup token and creates the first owner account.no sign-in
Public status/status-pageComponent health for people who are not signed in, refreshed on its own while the page is open.no sign-in

It is a map, not a manual. It says which screens exist, where they live and who may open them; it does not walk you through a task. For those, start at Paths by role or the how-to guides.

Screens whose backend is deny-closed until an operator provisions it appear here like any other — the route exists and the permission is real. Which module actuates and which is gated is recorded in the modules overview, and the honesty and limits page states the general rule.