See what needs attention, open the exact call, and act. Console reads Gateway records directly.
Interactive operator preview
Start with what needs an owner.
Example tenant data. This preview reads no production system and changes nothing.
Operator queue
Attention
Conditions that need a person, ordered by impact.
research-agentinv_01J8…F73CRevenuesupport-resolution12 invocationsPlatformcontract-reviewChanged 38m agoLegal opsSystem of record
Agent catalog
Identity, protocol, upstream, protection, pricing, and operating state together.
agt_research_01Keep history intact, stop new routed work, and confirm the authoritative state after the action.
Evidence explorer
Invocations
Filter the work that reached the upstream and open the exact record.
inv_01J8…F73Cresearch-agentstream · TTFT 842msCompletedFailedinv_01J8…08D1support-resolutionMCP · tools/callCompletedNot pricedinv_01J8…9A20contract-reviewtransaction · 202CompletedSettledPolicy denials and unpaid 402 challenges stop before an invocation record exists. This view does not call them invocations.
Commercial state
Settlement evidence
Know whether authorization was verified, funds settled, and the upstream was allowed to run.
settlement_failed · facilitator_timeoutThe operator loop
Find the problem. Open the record. Act.
Missing data is shown as missing, never as zero.
- 01Own
Know each agent, upstream, status, owner, pricing rule, and credential reference.
CATALOG - 02Inspect
Filter invocations by agent, result, mode, time, error, and settlement state.
INVOCATIONS - 03Act
Suspend or resume an agent and work the conditions surfaced by the attention queue.
CONTROL - 04Confirm
Read the authoritative tenant state again. Missing data shows as missing, not as zero.
EVIDENCE
Connected views
Seven views. One source.
Each view reads the Gateway API and shows only what it can produce.
Every agent, in full.
See catalog status, suspension, protocol, upstream, rate boundary, credential reference, pricing, tags, and per-agent traffic. Register, suspend, or resume an agent from the same view.
GET · POST · PATCHFind the exact invocation.
Filter server-side by result, mode, agent, time, error class, and settlement state, with the policy decision shown per row. Page through results or look up an invocation ID directly.
/v1/invocationsAn attention queue.
Rules flag suspended or pending agents, elevated failures, settlement failures, priced agents without settlement, and credentials no agent references.
6 NAMED RULESThe tenant at a glance.
Overview and analytics report live tenant state. Metrics Gateway cannot compute are left out, not estimated.
OVERVIEW · ANALYTICSInspect credentials, policies, and activity.
Read-only views over stored credentials, the policies applied to them, and recent agent activity scoped to what the summary endpoint can produce.
READ-ONLYPayments and settlement.
Read the settlement state behind priced agents and the payment posture of the tenant, without acting on it from the browser.
READ-ONLYKeep Gateway tokens out of the browser.
The same-origin BFF holds the Gateway bearer server-side. The browser gets an opaque, secure session and sends Console requests to its own origin.
OIDC · BFFHow it reports
If Gateway cannot confirm it, Console does not show it.
Console never invents a total.
Denied and unpaid calls are not invocations.
Policy denials and 402 challenges stop before an invocation row exists. The explorer shows traffic allowed to proceed, not every attempt.
Missing data shows as missing, not as zero.
A failed analytics read is unavailable. It does not become zero calls, zero errors, or an empty queue that looks healthy.
Some views are still being connected.
Overview, analytics, credentials, and policy are being connected to the Gateway API. Until each one lands, its preview is not presented as live.
What it operates
Console runs on top of Gateway.
Gateway enforces and records. Console is where people operate it. Portals and Rooms join Console as they ship.