The control plane your admin sees, previewed honestly.
You do not have to take our word for anything: every claim on this estate is independently verifiable, and the harness that proves it ships with the product.
Everything on this page is a design preview on SYNTHETIC values from the Tenant-One profile; the working administration surfaces ship inside the product and are open in the static review estate today. In production these panes reflect the tenant live integrations, all read-only, with per-tenant residency and anchored lineage.
Integrations
Read-only, with conformance reported honestly
Every connection is read-only and carries its conformance scorecard as checks passed over checks total; an adapter is never shown as certified until it fully conforms, and scaffolds report not-ready until validated on a live tenant. On the SYNTHETIC preview: an ERP at full conformance, procurement at full conformance, a warehouse system and a visibility feed mid-validation, a planning system early, and a CRM planned at zero until wired. Counts on this estate derive from the canonical ladder, never typed.
Bring your own AI
The intelligence layer is a capability you choose, not a vendor you inherit
Register the providers and models your enterprise has already approved. Each one carries a passport stating its owner, purpose, risk tier, data clearance, permitted domains and tools, cost ceiling, residency, autonomy limit, and evaluation on record; an incomplete passport is rejected with its missing fields rather than defaulted into the routable set. Your policy states which providers are allowed, the highest data class that may leave the tenant, the autonomy ceiling, the cost ceiling, the residency requirement, and whether an evaluation is required, and absent fields resolve to the strictest reading rather than the most permissive. The control plane then routes each task to the best permitted capability and names the rule that refused any other. Your own hosted model is a first-class entry on that registry, never a special case. The autonomy ceiling does not move: no write path exists in this product, so the highest grant any policy can receive is preparing an action for a human, and a policy asking for more is refused by name under decision D-R62. Calibration, stated plainly: no credential is bound in this build, so every route resolves its execution to the deterministic engines and records the provider it would have selected as intent rather than as a call. The plane cannot claim a model ran, and the rule pack that proves it turns red if that stops being true.
Identity and access
Enterprise SSO, provisioning, and least privilege
SSO over SAML 2.0 and OIDC with the major identity providers; SCIM 2.0 provisioning with deprovisioning on identity-provider removal; sessions bounded by idle lifetime. Roles are read-scoped by function, operations, procurement, finance, executive view, with administration separated, and the entitlement model is the same one the isolation suites prove on every sealed run. There is no write-back toggle to govern, because no write path exists in the product; approvals live in AssetShop own ledger, per decision D-R62, and the source transaction is never touched.
Audit log
Append-only, anchored, walkable
Every access is recorded with a SHA-256-anchored, tamper-evident entry: reads, conformance checks, configuration confirmations, approval entries in the platform ledger. Anchors on this preview are SYNTHETIC. The log is append-only and the product cannot alter source transactions, which makes the log evidence rather than narrative.
Residency and governance
Per-tenant region and keys, retention under your control
Region is a tenant property and holds across every domain added; changing region in production is a governed migration, never a silent move. Keys are managed per tenant. Retention is customer-defined; deletion on exit completes within thirty days with backups within sixty; data-subject requests turn around within thirty days; sub-processors publish with thirty-day notice, and none is active pre-deployment.
Observability, without theater
The instrument, not a percentage
No availability percentage prints here or anywhere on this estate, because a percentage without production history is theater; the reliability page carries the measurement instrument, the failure modes published first, and the per-engagement availability commitments in the MSA. Error monitoring, log aggregation, external probes, and paging wire at deploy, and each provider publishes on the sub-processor page the day it activates.