Turning a feature off refuses it at the API and removes it from this console. It is not a display setting.
What this tenant can run in , and which version is live.
A run holds one credential exclusively — most payer portals allow a single active session, so a second run waits rather than sharing.
The platform stores a reference, never the value. What you type here goes to the secrets driver and is not readable back — not by this page, not by the API, not by anyone.
Everything outside this platform an automation reaches — an API, a bucket, a payer portal login. Configured once here, then named by an automation, which never learns the credentials.
Secret fields go straight to the secrets driver; the platform keeps a reference. They cannot be read back — not by this page, not by the API.
Moves one version from staging into production. Checks run now and are kept with the record; a second person must approve.
Every tag with the digest it currently points at. The copy button copies the digest, never the tag — two builds can share a name and nothing else.
One image, many runnable configurations. Each states the account it logs in as and the digest it is pinned to.
Runs fire automatically. The preview shows the next five real timestamps,
because nobody reads 30 9 * * 1-5 and pictures a Tuesday morning.
What this automation’s containers may call back into the platform. Everything else is refused at the hooks API, whatever the code inside tries.
The configuration, defaults and credential this automation’s runs are started with. Values that are secret are masked here and resolved only inside the container — this console never sees them.
Applied to every run container. Not configurable — these are the conditions the rest of the isolation depends on.
What fired, and why. The values are the ones at evaluation time — five failures an hour ago are invisible to a query run tomorrow.
First match wins. A narrow rule above a broad one answers first; reorder with the arrows and the order is what a run will use.
Turns what a captured run saw into rules. Identifiers are replaced with synthetic values on import — captured bodies are never stored as they were seen.
Nothing here is available in production, and that is deliberate: a mock answering in production would fake a payer response — a run reporting an eligibility result nobody’s portal ever gave.
A production run that any rule would touch fails outright, naming the rule, rather than quietly proceeding against either the mock or the real portal. Switch to staging to configure rules.
Every delivery is signed and retried. The secret reference is written here and never read back — not by this console, not by the API.
What was sent, what came back, and when. This is the answer to “we never received it”.
Whether each one is still consuming, and what it routes to. Lag is what the gateway last measured — a consumer that stopped being assigned anything reports a lag that stops moving rather than an error.
A subscription consumes one topic from one Pegasus cluster in . It is created disabled and stays that way until it has a routing rule — consuming with no rule answers every request as unroutable, which sends a failure to a requester whose request was fine.
Messages is what the topic holds. Lag is what we have not handled. They are not the same number: a subscription that starts at the latest offset never sees what came before it, so a topic can hold twelve messages with the consumer entirely caught up.
What arrived, and what became of it. Unroutable is the one state nothing else on this platform reports: a request consumed with no matching rule starts no run, so there is nothing in Runs to look at and no error anywhere but here.
What we answered, and why one did not go. A response refused by the contract fails with its whole cause in one field and nowhere else — the run succeeded and the portal was touched, so nothing else records why the requester heard nothing.
The bundle floats: the gateway downloads and imports a wheel from the topic and calls the topic owner’s transformer. That is the design — the topic’s ACL is the trust boundary, and floating is what lets a schema change self-heal instead of breaking us. Floating is the choice; this list is the control.
First match wins. Order is the whole of the conflict resolution: there is no scoring and no most-specific-wins, because a rule set you can read top to bottom is one whose behaviour you can predict. The topic says which action; the match says which portal.
Turning a feature off refuses it at the API and removes it from this console, for only. It is not a display setting.
Shown once. Only the hash is stored, so it cannot be shown again.
Who can enter this tenant. A change takes effect on the person’s next request — nothing caches it, so a revoke is immediate rather than eventually.
A group is a set of people with a role per environment and a tag selector. Someone reaches an object when its tags intersect that selector; rights are the union across every group they are in.
An invitation carries the offer; accepting is what creates the membership. Nothing here grants anything until the person accepts.
The shared vocabulary groups select on. A rename never drops access — everything references a tag by id — but it does change what people read, so it says what it will affect first.
Each row states where its value came from and whether the running process picks a change up. Restart required is a property of the setting, not a warning about this form.
Creating a tenant does not make you a member of it. Creating a customer and being able to read that customer’s runs are different acts.
Straight from /health, one row per component, refreshed on the
same poll as everything else. Unconfigured is not failure — it means
the component has no driver wired yet, which is a fact about this deployment rather than an
outage.
A loop that stopped ticking looks exactly like a quiet queue — nothing broken, nothing running, nothing saying so. The age is what tells them apart.