What you can do today¶
Self-serve capability is gated by what the Operator Console and admin APIs actually expose. Verified against running code (2026-07-18).
Self-serve today (Bucket A)¶
Documented in full under Operator Console:
| Task | Console page |
|---|---|
| View connector status; trigger ingestion | Data & Knowledge |
| Enable / disable agent channels | Identity & Access |
| Create / revoke API keys; set quotas; view usage | API Access |
| Activate a model; set per-workload routing | Models |
| View + export audit trail; agent journal; set budgets | Governance |
| View deployment status + install plan | Deployment |
| View settings | Settings |
Not self-serve in the console yet¶
| Area | Status |
|---|---|
| SSO / IdP federation (Azure AD, Google Workspace, Okta) | Must be done in Keycloak; console wizard is a connectivity pre-check only. Docs for this path are coming soon — blocked on Keycloak hardening. |
| First-time connector credentials / OAuth app registration | Requires Residion engineering. See What still needs Residion. |
| Vertical pack activation (BFSI, Healthcare, etc.) | Arranged with Residion. Not a technical self-serve control. |
Do not treat missing screens as a documentation gap — several capabilities simply are not customer-operated yet.