RSOS Developer Console Prototype 3 · Read Only
checking runtime

Control Plane Overview

Authenticated read-only runtime inspection

Runtime

checking

Database

checking

Environment

TEST

Default Policy

DENY

Identity / Session

not authenticated
No session.

Security Boundary

READ ONLY

JWT required
Tenant aware
DENY_BY_DEFAULT
No token persistence
No production mutation

Runtime

Runtime dashboard and trust state

Total Objects

Active Objects

Events

High Risk

Cryptographic Integrity

Authenticate to load runtime.

Dataset State

Authenticate to load runtime.

Tenants

Runtime tenant registry
Tenant Name Type Status Domain
Authenticate to load tenants.

Objects

Tenant-scoped runtime objects
Object ID Runtime Type State Priority Risk Tenant
Authenticate to load objects.

Events

Tenant-scoped runtime audit stream
Time Event Type Object Message
Authenticate to load events.

Evidence

Read-only evidence and evidence-related runtime events

Evidence Events

Decision Evidence

Fact Events

Verification Events

Time Type Object Evidence / Message
Authenticate to load evidence.

Audit & Trace

Audit chain, decision trail and trace-related runtime events

Audit Events

Trace Events

Console Decisions

Audit Reports

Audit Reports

Authenticate to load audit reports.

Latest Audit / Trace Events

Authenticate to load audit and trace events.

Operator & Permission Matrix

Action-class contract · read only · deny by default

Action Classes

5

Default Policy

DENY

JIT Grant Storage

NOT IMPLEMENTED

Self Approval Guard

NOT VERIFIED

Action Class Policy

Class Write Approval Multi-Party Rollback Evidence Max TTL Status
READ NO NO NO NO YES CONTRACT_ENFORCED
LOW_RISK_WRITE YES NO NO NO YES CONTRACT_ENFORCED
GOVERNED_WRITE YES YES NO YES YES 8 hours CONTRACT_ENFORCED
CRITICAL YES YES YES YES YES 2 hours CONTRACT_ENFORCED
RECOVERY YES YES YES YES YES 1 hour CONTRACT_ENFORCED

Current Identity

Authenticate to inspect current operator.

Role / Scope Rules

system_admin
  global scope allowed

runtime_admin
  tenant scope allowed
  global scope not generally allowed

auditor
  READ only

governance
  governance role recognized

unknown role
  BLOCKED

tenant scope without tenant_id
  BLOCKED

JIT / TTL Implementation State

Contract TTL:
  GOVERNED_WRITE = 28800 s
  CRITICAL       = 7200 s
  RECOVERY       = 3600 s

Persistent JIT grant storage:
  NOT_IMPLEMENTED

Approval expiry storage:
  NOT_IMPLEMENTED

Automatic privilege revocation:
  NOT_VERIFIED

Approval / Separation of Duties

Approval contract:
  IMPLEMENTED

Multi-party requirement:
  IMPLEMENTED IN ACTION CONTRACT

Approval persistence:
  TABLE PRESENT

Current approval rows:
  0

Requester / Decider fields:
  PRESENT

Self-approval prohibition:
  NOT VERIFIED

Independent approver identity:
  NOT VERIFIED

Security Interpretation

This view reports only controls that have been technically observed. Missing JIT, expiry, self-approval and independent-approver enforcement remain explicitly unverified and must not be treated as active controls.

Governance

Tenant-scoped governance checks and outcomes · read only

Checks

Approvals

Human Review

Quarantine

Governance Checks

Time Trust Decision Human Approval Reason Checked By
Authenticate to load governance.

Governance Outcomes

Time Status Correct Trust Decision Recorded By
Authenticate to load governance outcomes.

Decision Inspector

Governance and action-class evaluation

Decision / Evidence

No decision evaluated.