DataEx
DataEx
DataEx is the console category for the people who consume what the platform decides. It covers which models serve, which agents act and within what limits, how the model plane is used, which tenant sources CORE reads and what reads them, what CORE may do and who may do it, and the independent verdicts on findings.
The rail order comes from flutter/lib/core/widgets/nav.dart (navGroups): Model cards · Agents · Inference · Connections · Runners · Trust (Harness, Guardrails & autonomy, Policy & ReBAC, Admin, Secrets & PKI) · Model & agent audit · Judgements.
A tour of every DataEx page, with its ?tab= name and the endpoint behind it.
The connection wizard, the registry API and core connection register.
The Runink managed runner, enrolling a self-hosted runner, and the refusal codes.
Model cards, the inference plane and the model router’s admission queue.
Admin allowlists, Harness, guardrails, Secrets & PKI and the Admin page.
The datagov agent’s controls, verdicts and what it never reads.
The judgement contract: one document, two write doors, three outcomes.
DataEx HTTP routes, their auth class, and the gRPC services behind the pages.
Real error strings from the console and the CLI, with cause and fix.
Three rules that hold across DataEx
- Reads never dial. No DataEx page load contacts a tenant source. The one path that dials a registered source is Resolve’s action RPCs (Test, Explore, Access patterns, Map estate). They run in the console process, only on an admin’s action. See Resolve.
- Credentials are write-only. A connection’s credential bundle is stored separately from its record. No read returns it.
- Unread is never empty. When the console cannot read a source it says so in the body (
source:"unavailable",complete:false, anunmeasured[]entry with the reason). It does not report “none”.