Getting Started
This page walks the DataEx rail from top to bottom. For each page it gives the label, the ?tab= name for a deep link (/?tab=<name>), and the endpoints the page reads. Labels come from flutter/lib/l10n/app_en.arb, order from navGroups in flutter/lib/core/widgets/nav.dart, and endpoints from each screen’s source.
| Rail label | ?tab= | What it reads |
|---|---|---|
| Model cards | modelCards | GET /api/models |
| Agents | agents | GET /api/agents, GET /api/swarm, GET /api/agent-config, GET /api/access, GET /api/guardrails |
| Inference | inference | GET /api/models, plus GET /api/agents for its inference.router block |
| Connections | connections | the shared ConnectionsService (gRPC-web) |
| Runners | runners | the shared RunnersService (gRPC-web) |
| Trust › Harness | harness | GET /api/harness |
| Trust › Guardrails & autonomy | guardrails | GET /api/guardrails |
| Trust › Policy & ReBAC | policy | GET /api/access |
| Trust › Admin | admin | the shared AccessService (gRPC-web). Drawn only for an admin of the chosen instance |
| Trust › Secrets & PKI | secrets | GET /api/security |
| Model & agent audit | modelAgentAudit | /api/models, /api/agent-config, /api/guardrails, /api/harness, /api/judgement, /api/judgements |
| Judgements | judgements | GET /api/judgement, GET /api/judgements |
Old links still land. ?tab=security goes to Secrets & PKI, and ?tab=measures goes to Harness (retiredTabNames in nav.dart).
Model cards
One row per serving tier. Each row joins three sources (models.go): the reviewed card in modelcards.json, what the tier is actually running, and the core-inference-bench ConfigMap when a measurement can be attributed to that tier. A tier is healthy only when it is deployed, is ready, has not just been OOM-killed, and runs the model its card names. More in Models & inference.
Agents
The console’s agent roster (GET /api/agents) is seventeen entries: the thirteen grpc/agents/ binaries plus users, resolver, forger and the core session CLI. Each card carries the agent’s purpose, trigger, delivery (workflow, cli or cronjob), model tier and the gate that arms it. The page also shows each app agent’s live health (/api/swarm), its ini settings and OpenBias rules (/api/agent-config, read from each repo’s HEAD), who may arm agents (/api/access) and the hard guardrails (/api/guardrails). The fleet itself is documented under DevEx › Agent fleet.
Inference
The model router and per-tier usage and quotas. Admission, queue depth and token quotas are not exported by anything today. models.go lists them as unmeasured[] entries that name what would have to exist. See Models & inference.
Connections
This page is where tenant data-source connections are created, edited, tested and rotated. It is the shared org-runink/ui datasources wizard, mounted by datasources_ui.go. Credentials are write-only, and Test is Resolve’s Test run on the connection’s bound runner. See Connections.
Runners
The data-access runners: the built-in Runink managed runner (console) and any self-hosted runners CORE connects out to. These are not CI runners. See Data-access runners.
Trust
- Harness: the console’s own findings (from
/api/measuresand/api/compliance), each with only the actions CORE can really take. An admin’s POST to/api/harness/{id}/actruns one. - Guardrails & autonomy: an autonomy level of
off,hitlorautofor each action class. The default ishitl, and in this buildautois recorded but never executed. - Policy & ReBAC: which allowlists are set, how large each is, and your own membership. ReBAC is reported as not wired: the library exists, and no route checks a relation.
- Admin: the members and seats of the instance chosen on the landing page.
- Secrets & PKI: the shared mesh CA as distributed to each namespace, with its subject, SHA-256 fingerprint and validity window.
See Trust & access.
Model & agent audit
An assessment page, not the audit log. It reaches one verdict over the six reads listed above: model health against each card, OpenBias coverage per app agent, the autonomy guardrails, the Harness’s open findings and the independent judgements. Its actions go through the paths that already exist. A Harness action stays on Trust › Harness, and the judge agent is started through an existing playbook (PlaybookService.RunNow).
Judgements
The docket of findings that external assessment platforms have submitted, and CORE’s own verdicts on them. See Judgements.
Where to go next
- Register a source on Connections.
- Explore it on Intelligence › Resolve, so that the datagov agent can assess data quality and PII exposure.
- Read the result in Data governance.