Documentation · The Lagstyr handbook
Sources, structure and the operations index
Two of the registers an administrator visits most are read-only in the console, by design. This chapter says what they show, what they do not let you do, and where the writes live.
Sources
Sources is the health of your installation’s connections to the systems it reads from and acts into. Its first sentence sets the frame: Registered source rows are the authoritative posture (identity and reliability). Intent and receipt counts are operational ledgers, and this table is a rebuildable projection derived from them at read time — nothing here is a second store.
For each owning system it shows the registered sources, the outbound intents, the effect receipts by state, the oldest unresolved read-back deadline and the open reconciliations. One figure is called out in bold because the receipt counts cannot show it: Sent, no receipt, an effect that was performed and for which the governed ledger has no row. It counts only effects whose kind records a governed receipt, which the database decides when the effect is claimed; kinds that record none by design are not counted. It is absent rather than failed, and it is the one to chase.
Nothing on this page can be changed from the console. The only control is a filter by owning system. Registering a source, admitting an external event namespace, mapping its kinds to business fact roles and giving a connector its least-authority machine role are governed acts made through the kernel’s API by the person who operates your installation, and a registered source is not a commissioned one: your installation still supplies the source meanings, the connector, the credentials, the support owner and the test evidence.
Integrations
Integrations is where an installed integration is watched and contained. For what this installation can connect to at all, what every finding means and what happens when a provider changes its API, read What this installation connects to; this section is the console pages. You reach it from the operations index, from the Integrations needing attention → link below the Sources tables, or from an integration key on the Sources page. Its lead says what it shows: Every installed integration and what currently pages about it. A covered condition is answered by a dated remediation case or an active quarantine; nothing covers an overdue remediation. It lists each integration with its status, active release, readiness and conditions, then the live breaks in built-in adapters. If the kernel’s attention read fails, the page still renders and says Nothing below is known — it is not clear.
Three conditions page. Release blocked means the integration cannot take new work: its release, executor, credential, pack or signing key is no longer usable, or the system paused it. Capture refusing means records are being refused under the integration’s signed declaration. Remediation overdue means an open remediation case has passed its due date.
An integration’s own page shows its summary, its conditions and what covers each, the active release and release history, capture progress, breaks, remediation cases, specification candidates, lifecycle events and, once retired, its retirement snapshot. A break’s page shows each refused record as a drift capsule in metadata only: the refusal, the expected shape, the record’s digest and how long it is kept. The record itself is never shown, and it is erased when retention ends.
Specification candidates lists what the kernel compiled from a provider specification somebody uploaded: its status, how many decisions are still open, and how far it has drifted from the release that is active now. A candidate’s own page shows that drift, each open decision, the bounded provider text behind it, anything the compiler refused, and every revision with the person who applied it. The provider text is quoted under a heading that says it came from the provider: read it as evidence about the interface and never as an instruction. A candidate is never authority. It becomes a release only by answering its open decisions in one governed proposal and then publishing the signed result, so no field acquires a meaning nobody approved.
The acts on these pages divide into the immediate and the governed, and What this installation connects to enumerates both sets in full. What is worth knowing while reading the page itself: Pause this integration admits no new capture, claims or effects and keeps every release; Close this break records that the resource is no longer broken, and is refused while the break’s source is quarantined; Withdraw candidate stops work on an unpublished candidate and keeps it, with your reason, as evidence. Each re-authenticates you and records you as the actor. Resuming a paused integration is a governed publish rather than an act here. A governed form ends in Submit for approval and needs a second approver: opening a remediation case from a condition, with an owner and a due date; resolving a case with evidence; quarantining a break’s source and lifting that quarantine; and retiring the integration, which the kernel refuses while a break is live. An open, in-date case or an active quarantine covers a blocked or refusing condition, so it stops paging. A pause by a person shows as a warning. Breaks in built-in adapters take no remediation case: each is owned by its incident, and a quarantine is the containment.
An integration whose active release connects through OAuth also shows a Provider connection section: the connection’s status and findings, the provider account, OAuth client, granted scopes, when it connected and by whom, the last token refresh and credential generation, plus any approved connection and the latest consent attempt. The refresh token is never shown. With no approved connection the section offers Propose a provider connection, a governed form naming the OAuth client and a reference to its secret, never the secret itself; a second operator approves it. Once approved, Begin consent re-authenticates you and shows a page naming the provider host and the exact scopes before a Continue to link takes you there. The attempt lasts ten minutes and must finish in the same browser. After you consent, the provider returns you to a Consent received page; the connection appears on the integration page once the token broker has exchanged the code. Disconnect now is immediate containment like a pause: it re-authenticates you, asks for a reason and cuts the connector’s provider access at once. Reconnecting needs a new approved proposal.
Access structure
Access structure shows the roles that carry access meaning, the positions and what each entitles, and the segregation-of-duties rules. Access holders, one person’s access, and the joiner, mover and leaver cases are read the same way. The pages tell you what an empty register means: No access roles are declared. Until one is, no role kind carries access meaning, and Nobody holds governed access yet. Declare access roles and positions first.
That last sentence is an instruction to act somewhere else. The console has no form to declare a role, define a position, set its entitlements, declare a separation rule, or open, enact or cancel an access case. Those are governed writes through the kernel’s API, each requiring an officer’s approval, and no approval route for them is seeded: routes are your installation’s own data. The one write the access pages carry is the administrator two-person review, described in Access, people and language.
The operations index
The page reached from the navigation as Operations index is titled Launch operations, and its lead is the sentence this whole part rests on: Configure and operate launch capabilities through governed kernel surfaces. Authoritative records are shown apart from operational counters and rebuildable projections, and every change below is a proposal the kernel validates and routes for approval — the console holds no authority of its own.
It is nine tiles and a search. The tiles are doors to pages this book has already covered: sources and integrations; integration attention; action classes; AI systems and workflows; external effects; policy exceptions; needs attention, which is the landing page under another name; cash and commitments; and operating outcomes. The search finds documents in your installation’s corpus by text and changes nothing; if the search itself fails, the page still renders and says the search was unavailable.
What the administrator cannot do from here
Install, upgrade, back up or restore the installation; arm emergency access; supply an identity provider, a model endpoint, a connector credential or an alert destination. None of those is a console act. They are the host operator’s work and your organisation’s decisions, using the installation tooling described in the engineering and DevSecOps chapters. Start with integrations for source commissioning and security for identity and credential boundaries.