What the fleet is connected to
Each app is a separate connector with its own endpoint, protocol era and credential. Tools are only served once an app is enabled and its current tool set has been approved.
| App | Tools | Auth | Catalog age | State |
|---|
Who is wearing what, right now
Only redeemed claims appear. A binding is permission to claim, not a claim — a mis-wear should be visible here in seconds rather than found in a post that already went out.
| Agent | App | Acting as | Pass | Since | Expires |
|---|
Add or edit a connector
Adding an app is a data change, not a deploy. A new connector arrives disabled and unapproved — test it, enable it to start collection, then approve its tools to put them on the fleet surface.
run_playbook polls for 60s, so its connector is set to 90s — a shorter timeout cuts the call off mid-run and the model retries a job that is still going.
Configured connectors
Click a row to load it into the form above.
| App | Endpoint | Era / session | Auth | Timeout | Enabled |
|---|
Tool sets, grouped by application
Every tool the Launchpad serves, under the app that owns it — never one flat list. Tool changes never take capability away: a new or changed tool is served immediately and flagged new for you to look at, and a tool removed upstream costs nothing else. The only thing that pulls a tool off the surface is blocking it here.
What the scopes mean
Scope decides caching, not just permission.
| Scope | Served? | Behaviour |
|---|---|---|
| read | yes | Never cached. Anything returning a clock, a poll, or memory must be here — a cached answer would be wrong by the time it is read. |
| post | yes | Deduplicated for 5 minutes on caller + worn identity + arguments, so a connector that wrongly reports failure cannot double-charge a credit-debiting call. |
| admin | no | Withheld from every surface until per-tenant isolation lands. |
| new | yes | Shipped since you last reviewed this app. Served anyway — a gateway that withholds capability every time an app ships is the instability it was built to remove. |
| blocked | no | The one thing that removes a collected tool. Explicit, per tool, reversible. |
Provision an agent
Creates a fleet agent, mints its key, and binds its app identity in one step — so every agent gets its own identity. Agents sharing one fleet agent is the shape that lets a session collision swap identities silently.
1:1 coverage
Progress toward one agent, one key, one identity. Multiple live keys on a single fleet agent means several agents may be sharing an identity.
| Agent | Keys | Identities | Assessment |
|---|
Bind an identity to an agent
This grants permission to ask. The app still decides at claim time, and the agent still redeems its own claim key — the Launchpad holds none.
vk_ value is a credential and belongs only in the agent's own hands — this form refuses it.Roster
Revoking takes the shoes off immediately — it does not wait for a token to expire.
| Agent | Status | May claim |
|---|
Every wear, every refusal
Refusals matter more than successes: a run of them is either a misconfigured agent or someone probing the allow-list. Claim keys are never recorded here.
| When | Agent | App | Identity | Outcome | Reason |
|---|
Collector
pg_cron reports success when a request is queued, not when it succeeds — net.http_post is asynchronous. These figures come from the catalog itself, so a dead collector cannot look healthy.
| App | Catalog age | Budget | Tools | Alarm | Last error |
|---|
Invariants
Run against the deployed functions and the collected rows, not a mock — a test that imports the rule it is testing proves only that the rule equals itself.