Getting Started
This page walks the Intelligence rail from top to bottom. For each page it gives the ?tab= deep-link name and the CORE data behind it. It then covers the onboarding checklist.
Where the pages come from
Intelligence is a page-for-page Flutter port of the partner product Atlas, pinned to one Atlas commit. The TSX at that commit is the source of truth for layout, sections and copy. Each Dart view names its TSX file and draws an AtlasSourceRef chip, so you can hover to see the source of every screen. The mapping is kept in flutter/lib/features/intelligence/ATLAS_SOURCE.md.
The data is CORE’s, never Atlas’s. Atlas rendered fixed sample numbers. Here every figure comes from a CORE endpoint. If CORE has no source for a section, the section keeps its Atlas layout and draws an absent panel with the reason.
Two things differ from Atlas:
- Resolve is not an Atlas page. It is ported from FACE’s Reconcile and Data Connectors pages, and it shows a
FaceSourceRefchip instead of anAtlasSourceRefchip. - Agents left Intelligence on 2026-09-26. It is now DataEx › Agents (see DataEx).
?tab=agentsstill lands on it.
Deep links
Every page opens with ?tab=<name> on the console URL. Names are case-insensitive. An unknown name falls through to Overview. Several retired names still redirect, for example ?tab=rulesRecon and ?tab=governance → Business Rules, ?tab=compliance → Remediation, and ?tab=maturity and ?tab=governanceRuns → Progress (flutter/lib/core/widgets/nav.dart, retiredTabNames).
The rail, in order
| Page (rail label) | ?tab= | What it reads |
|---|---|---|
| Capital Governance Analyst | analystDashboard | CapexService.GetAnalystDashboard. Also /api/measures, /api/governance-runs, /api/data-governance-findings |
| CFO Cockpit | cfoDashboard | CapexService.GetCfoDashboard. Also /api/finops (every $ is derived from a CU estimate) and /api/compliance |
| Director PMO | pmoDashboard | /api/dashboard instances grouped by initiative as “projects”, /api/measures, /api/finops, CapexService.ListScanRuns |
| DQ overview | dqOverview | /api/data-governance-findings, /api/rules-recon, /api/compliance, /api/connections, /api/governance-runs, Resolve ListSources / GetSourceDescription, CapexService.GetAnalystDashboard for the CapEx DQ score |
| Capex Monitor | capexMonitor | CapexService GetSummary, GetFeeds, GetConfig, ListFindings, GetRuleBook. Writes: StageFeed → PreviewIngest → CommitIngest, ClearFeed, UpdateConfig |
| Capex Lineage | capexLineage | CapexService ListFindings, TraceFinding, GetRuleBook |
| Perspectives | perspectives | Nothing. Static governance-framework copy, ported verbatim |
| Business Rules | rules | GovernanceService ListRules, ListRuleChanges. Writes: ProposeRuleChange, DecideRuleChange, SetRuleOwner. Below that, /api/rules-recon |
| Orchestrator | orchestrator | PlaybookService (list, get, events, dispatchable agents, and the writes). /api/agent-schedules is kept below as the cron truth |
| Lineage | lineage | /api/data-lineage plus datagov fail/warn hotspots. Also the “Declared derivations” a Resolve Explore recorded |
| Remediation | remediation | GovernanceService ListRemediations, DryRunRemediation, DecideRemediation, ListDecisions. Below that, the platform findings from /api/measures, /api/rules-recon, /api/data-governance-findings, /api/compliance, /api/agents, /api/governance |
| Progress | progress | CapexService.ListScanRuns, /api/maturity, /api/governance-runs, the governance findings history |
| Sources | sources | /api/connections, /api/connection-types, /api/connectors/status, /api/domains. The “Granted to Atlas” switch calls WorkspaceService.UpdateWorkspace source_ids |
| Resolve | resolve | The shared estate component (runink.ui.estate.v1.EstateService). See Resolve |
| Settings | settings | WorkspaceService GetWorkspace, ListDqEngines, the onboarding wizard, ResetWorkspace. Read-only: /api/rules-recon, /api/github |
| Data audit | dataAudit | Resolve’s dialing actions and CapEx pull, with a runner picker. See Data audit & lineage |
| Deploy lineage | deployLineage | /api/lineage. This is the CD pipeline’s lineage, not data lineage |
How pages draw what they read
These rules come from ATLAS_SOURCE.md and are enforced in the Dart views:
- A figure is read only through
AtlasFigure.of. An absentKpidraws itsabsent_reasonand never 0. - Provenance decides the sentence.
UNAVAILABLEdraws the store’s reason (“could not look”).EMPTYdraws “no CapEx feed has been uploaded”. An incompleteLIVEread lists what went unmeasured. - A
TrafficStatusofUNSPECIFIEDmeans not assessed. It is drawn as an absent chip, never green. - Write buttons are enabled only after the matching read has answered. The first
PermissionDeniedis drawn with the console’s reason and disables every write on the page.
Onboarding (Settings)
The workspace records which sources and agents Atlas may use and which data-quality (DQ) engine runs. WorkspaceService.GetWorkspace computes the onboarding checklist against what exists now. A granted source that has since been deleted from the registry shows as missing, not as granted.
| Step key | Label | Required |
|---|---|---|
discover_agents | Discover agents | No |
grant_sources | Grant app access | Yes |
select_engine | Connect DQ engine | Yes |
confirm | Confirm | Yes |
CompleteOnboarding fails with FAILED_PRECONDITION and lists every unmet step unless both of these hold:
- at least one granted source exists in CORE’s connection registry, and
- a connectable DQ engine is selected.
The error reads onboarding cannot be completed; unmet: ….
Only CORE’s own engine, core-capex, is connectable. ListDqEngines also lists Atlas’s four third-party engines as NOT_CONNECTABLE, with the reason and with absent rule counts.
Granting a source never dials it. UpdateWorkspace checks that each source_ids entry exists in CORE’s registry, and that each agent_ids entry is a registered agent. It records permission and nothing more.
A registered agent is metadata only. CORE never calls, polls, authenticates to or sends data to an agent in the enterprise agent registry. The contract has no endpoint, token or credential field. last_seen is always absent, with a reason.
ResetWorkspace (note required) clears only the workspace settings and re-opens onboarding. CapEx feeds, scan history, rule governance, decisions and the agent registry are untouched.
Who may do what
Reads need only a console session. Every write passes the per-method policy table, atlasPolicies. Most writes need an Atlas admin. The allowlist env var for that is CORE_ATLAS_ADMINS. When it is unset, every identity the console admits counts as an Atlas admin. See Rule governance for the four classes.
Next
- Load data: CapEx feeds & findings
- Map your sources: Resolve
- Automate a response: Playbooks