Skip to content
Documentation menu
On this page

Operations · 12

Console & operations

The console is where operators control the system: agents, policies, integrations, sessions, evidence, members, and billing. This page walks the workflows an operator owns day to day.

What the console owns#

Everything an agent does is governed by things an operator manages here: which systems are connected and which resources are enrolled, which policies exist and which agent each one is assigned to, which sessions and devices are active and which have been revoked, what the evidence shows, and who on your team can see or change any of it.

Verified behavior

A dashboard element is not a capability claim. This page documents workflows known to work end to end; anything you see in the console marked planned or preview is not documented here until it ships.

See a decision surface live#

Before the console captures below land, there is one decision surface you can inspect today: the authority demonstration on the landing page. Hold the agent and the action constant, change the policy assigned to that agent, and the next decision changes from ALLOW to REJECT with its reason. The decision record for that same event is shown further down the page. It is illustrative rather than live execution, and no account is required.

Open the authority demonstration

Note

Console screenshots on this page ship as specified capture slots until they are taken from the live product. A screenshot is a product claim, and these docs never fabricate UI.

Agents, devices, sessions#

The agents view lists every operator-managed agent identity, the devices (enrolled installations) it runs on, and its live sessions. Revocation is a first-class operation at each level: revoke a session, revoke a device, or disable the agent entirely.

Console

Keydris console Agents view: summary tiles for total, active, without-policy and revoked agents, a filtered agents table, and a detail panel for one agent showing its attached policy, current authority summary, and latest session.
Agents view: identity, devices, sessions, and revocation at each level.

Policy authoring#

Policies are authored on the visual builder: rules for the actions a policy governs, each carrying ALLOW, REJECT, or APPROVAL REQUIRED; conditions that scope them; and the default decision for anything unmatched. Saving produces a new version, and the plain-language summary shows what you actually authored. Preview and lint before relying on a policy. Assignment is central: the agent connects once by Agent ID, and which policy governs it is decided here. Changing or reassigning never touches the agent's setup. (New to the taxonomy? The three decisions are taught in Identity vs authority and the rule semantics in Policies.)

Console

Keydris console policy builder: a Trigger to Node Type path selecting Payment and Action, an Action Control step for integrations, and a Policy Outcome panel whose default decision is Approval, with terminal safeguards and approvers.
Policy Builder: rules, decisions, conditions, default. The plain-language summary is the review surface.

Audit review#

The audit view is the evidence trail: filter by timeframe, agent or principal, action, decision, and outcome; expand any record for its full context; export the selected window for reviews.

Console

Keydris console Evidence view: tabs for all evidence, decisions, policy changes, revocations, system events and live, filters for type, agent and date range, and a table of records with time, type, agent, event, policy and outcome columns.
Evidence view: tamper-evident records of authority decisions and system events, filterable by type, agent, and date, with each record's outcome shown separately.

Roles & members#

Console access is scoped by organization roles with permission-based administrative access: each member sees and changes only what their role permits. Assign roles when inviting members; change them centrally.

Console

Keydris console Roles and permissions view: system role cards for Admin, User, Management and Accounting with their permission counts, and a permissions matrix mapping organization, agent and policy permissions to each role.
Members and roles: permission-scoped administrative access.

Plans & usage#

Note

Plan entitlements can limit members, agents, active KITs, policies, integrations, API keys, KIT issuance volume, and audit retention. The console shows current usage against your plan. Additional KIT issuances are available on Free, Builder, and Pro; commercial changes are currently arranged with Keydris directly. Specific tier prices and limits live on the pricing page and your plan, not in these docs.