Real product surfaces
Explore the surfaces that connect the work.
These are surfaces from the operator console, not concept art. Inspect how the board, vault, lease, session, patch wave and export contribute to one operation, so the work, oversight and resulting evidence can be read together.
Why the set matters more than any one screen
Six surfaces write to it. Three read from it.
A screenshot tour is usually a feature list with pictures. The thing worth checking here is the direction of the arrows: whether each module keeps its own log, or whether they all contribute fields to a single object that can be exported as one thing.
How to read the frames
The colours mean the same thing on every screen.
One key, applied everywhere in the product and everywhere on this site. Learn it once and the screenshots below stop being decoration.
The work
Where operations are run, watched, and taken over.
These three are the day-to-day surfaces. A technician spends their time here; everything else is consulted rather than worked in.

Delivery board
Look at what an operation card carries before anyone touches it: who asked, which machine, which procedure, and how much of the lease is left. That is the whole decision, on one card.
Delivery Board →
Patch waves
Look at what stands between one wave and the next. Patching here is a sequence of gates rather than a schedule, and a gate is a place where something has to be true before more machines are touched.
Patch Management →
Devices & discovery
Look at the split between machines with an agent and machines that were only discovered. That boundary is a real constraint on what can be done, not a smaller feature set, and we draw it explicitly.
Devices & Discovery →The board is the surface that decides how many workstreams one technician can hold, so it is the one to be sceptical about in a demo. Ask to be shown an operation stopping safely and handing back to a person — that path is more informative than a clean run, and it is the one commanded autonomy is built around.
The privilege
Where rights are borrowed, and where they end.
These three exist so that the answer to "what account did that run as" is never a shrug. Each of them writes a field into the operation record rather than keeping a log of its own.

Credential vault
Look at the distinction between a record and its value. The record is what an operation refers to; the value is resolved elsewhere and never reaches the model. Rotation is a property of records we have been asked to manage.
Credential Vault →
Just-in-time elevation
Look at the expiry beside every grant. A lease is scoped to one operation on one target and ends on its clock, which is a different promise from ending when the work does.
Just-in-Time Elevation →
Governed sessions
Look at the operation a session is attached to. Remote access is launched by policy against a specific piece of work — it is not a separate tool opened alongside it.
Governed Sessions →Two honest edges here. Session evidence is deliberately narrow today: we describe governed launch, authorization and the operation record, and we do not claim full multi-surface session replay. And a credential record is a password-safe entry a human may also use — managed means we own its rotation, and only after a deliberate designation, not by default.
The evidence
Where it turns into something you can send.
The last three surfaces are the commercial ones. Everything upstream exists so that these can be handed to somebody outside your team without a covering explanation.

Outcome receipt & chain
Look at the confirmation line and the fingerprint under it. One says the target machine answered; the other is what makes editing the record afterwards visible to anyone who checks.
Outcome Receipts →
Reporting & exports
Look at what an export is scoped to — one client, one period — and that it goes out as PDF, JSON or CSV with the proof attached. Exports are included in the published package scope.
Reporting & Exports →
Roles & multi-tenancy
Look at how scope is expressed. It is identity crossed with customer, not a single flat role list, and an operator can hold more than one live context at a time.
Roles & Multi-Tenancy →Screens are the weakest form of proof
Have us drive them instead.
A screenshot proves an interface exists. Fifteen minutes on a live system proves the record does — a real ticket resolved end to end, the record opened, the rollback executed, and your hardest audit question answered on the call.