Skip to content

Getting Started

This page walks the Intelligence rail from top to bottom. For each page it gives the ?tab= deep-link name and the CORE data behind it. It then covers the onboarding checklist.

Where the pages come from

Intelligence is a page-for-page Flutter port of the partner product Atlas, pinned to one Atlas commit. The TSX at that commit is the source of truth for layout, sections and copy. Each Dart view names its TSX file and draws an AtlasSourceRef chip, so you can hover to see the source of every screen. The mapping is kept in flutter/lib/features/intelligence/ATLAS_SOURCE.md.

The data is CORE’s, never Atlas’s. Atlas rendered fixed sample numbers. Here every figure comes from a CORE endpoint. If CORE has no source for a section, the section keeps its Atlas layout and draws an absent panel with the reason.

Two things differ from Atlas:

  • Resolve is not an Atlas page. It is ported from FACE’s Reconcile and Data Connectors pages, and it shows a FaceSourceRef chip instead of an AtlasSourceRef chip.
  • Agents left Intelligence on 2026-09-26. It is now DataEx › Agents (see DataEx). ?tab=agents still lands on it.

Deep links

Every page opens with ?tab=<name> on the console URL. Names are case-insensitive. An unknown name falls through to Overview. Several retired names still redirect, for example ?tab=rulesRecon and ?tab=governance → Business Rules, ?tab=compliance → Remediation, and ?tab=maturity and ?tab=governanceRuns → Progress (flutter/lib/core/widgets/nav.dart, retiredTabNames).

The rail, in order

Page (rail label)?tab=What it reads
Capital Governance AnalystanalystDashboardCapexService.GetAnalystDashboard. Also /api/measures, /api/governance-runs, /api/data-governance-findings
CFO CockpitcfoDashboardCapexService.GetCfoDashboard. Also /api/finops (every $ is derived from a CU estimate) and /api/compliance
Director PMOpmoDashboard/api/dashboard instances grouped by initiative as “projects”, /api/measures, /api/finops, CapexService.ListScanRuns
DQ overviewdqOverview/api/data-governance-findings, /api/rules-recon, /api/compliance, /api/connections, /api/governance-runs, Resolve ListSources / GetSourceDescription, CapexService.GetAnalystDashboard for the CapEx DQ score
Capex MonitorcapexMonitorCapexService GetSummary, GetFeeds, GetConfig, ListFindings, GetRuleBook. Writes: StageFeed → PreviewIngest → CommitIngest, ClearFeed, UpdateConfig
Capex LineagecapexLineageCapexService ListFindings, TraceFinding, GetRuleBook
PerspectivesperspectivesNothing. Static governance-framework copy, ported verbatim
Business RulesrulesGovernanceService ListRules, ListRuleChanges. Writes: ProposeRuleChange, DecideRuleChange, SetRuleOwner. Below that, /api/rules-recon
OrchestratororchestratorPlaybookService (list, get, events, dispatchable agents, and the writes). /api/agent-schedules is kept below as the cron truth
Lineagelineage/api/data-lineage plus datagov fail/warn hotspots. Also the “Declared derivations” a Resolve Explore recorded
RemediationremediationGovernanceService ListRemediations, DryRunRemediation, DecideRemediation, ListDecisions. Below that, the platform findings from /api/measures, /api/rules-recon, /api/data-governance-findings, /api/compliance, /api/agents, /api/governance
ProgressprogressCapexService.ListScanRuns, /api/maturity, /api/governance-runs, the governance findings history
Sourcessources/api/connections, /api/connection-types, /api/connectors/status, /api/domains. The “Granted to Atlas” switch calls WorkspaceService.UpdateWorkspace source_ids
ResolveresolveThe shared estate component (runink.ui.estate.v1.EstateService). See Resolve
SettingssettingsWorkspaceService GetWorkspace, ListDqEngines, the onboarding wizard, ResetWorkspace. Read-only: /api/rules-recon, /api/github
Data auditdataAuditResolve’s dialing actions and CapEx pull, with a runner picker. See Data audit & lineage
Deploy lineagedeployLineage/api/lineage. This is the CD pipeline’s lineage, not data lineage

How pages draw what they read

These rules come from ATLAS_SOURCE.md and are enforced in the Dart views:

  • A figure is read only through AtlasFigure.of. An absent Kpi draws its absent_reason and never 0.
  • Provenance decides the sentence. UNAVAILABLE draws the store’s reason (“could not look”). EMPTY draws “no CapEx feed has been uploaded”. An incomplete LIVE read lists what went unmeasured.
  • A TrafficStatus of UNSPECIFIED means not assessed. It is drawn as an absent chip, never green.
  • Write buttons are enabled only after the matching read has answered. The first PermissionDenied is drawn with the console’s reason and disables every write on the page.

Onboarding (Settings)

The workspace records which sources and agents Atlas may use and which data-quality (DQ) engine runs. WorkspaceService.GetWorkspace computes the onboarding checklist against what exists now. A granted source that has since been deleted from the registry shows as missing, not as granted.

Step keyLabelRequired
discover_agentsDiscover agentsNo
grant_sourcesGrant app accessYes
select_engineConnect DQ engineYes
confirmConfirmYes

CompleteOnboarding fails with FAILED_PRECONDITION and lists every unmet step unless both of these hold:

  • at least one granted source exists in CORE’s connection registry, and
  • a connectable DQ engine is selected.

The error reads onboarding cannot be completed; unmet: ….

Only CORE’s own engine, core-capex, is connectable. ListDqEngines also lists Atlas’s four third-party engines as NOT_CONNECTABLE, with the reason and with absent rule counts.

Granting a source never dials it. UpdateWorkspace checks that each source_ids entry exists in CORE’s registry, and that each agent_ids entry is a registered agent. It records permission and nothing more.

A registered agent is metadata only. CORE never calls, polls, authenticates to or sends data to an agent in the enterprise agent registry. The contract has no endpoint, token or credential field. last_seen is always absent, with a reason.

ResetWorkspace (note required) clears only the workspace settings and re-opens onboarding. CapEx feeds, scan history, rule governance, decisions and the agent registry are untouched.

Who may do what

Reads need only a console session. Every write passes the per-method policy table, atlasPolicies. Most writes need an Atlas admin. The allowlist env var for that is CORE_ATLAS_ADMINS. When it is unset, every identity the console admits counts as an Atlas admin. See Rule governance for the four classes.

Next