Actions and results

What each Platform and Apps button and automatic behaviour does, with worked numbers and what the system refuses.

On this page (24)

Overview

ActionWhenWhat you doWhat happens
Overview tiles match their listsSome packages, releases, runs, alerts and flags existOpen Platform > Overview; note each tile; click each tilePackages awaiting review = Draft + Reviewed packages; Drifted = packages marked drifted; Releases in flight = Draft/Reviewed/Staged/Approved (max 8 listed); Jobs queued = Queued + Waiting to retry runs; Dead letters = Dead runs; Open alerts = Open + Acknowledged; Flags waiting = Proposed flags + active flags with a pending change; Active extensions shown as active/total. Each tile opens the matching list
Last good backup tile colourBackups module has a succeeded backupRead the Last good backup tile; compare with the newest succeeded backup timeShows the age in hours; red when there is none ('never') or it is older than 26 h, green otherwise
Server bannerStaging serverOpen the Overview on https://141-145-152-10.sslip.ioBanner shows the tier label (Staging) and the current environment code if one is marked 'This server'; 'Outgoing mail and webhooks off' shows on a staging/recovery copy unless outbound is allowed; 'Schema is not at this build's head' shows only when the live migration head differs

Packages

ActionWhenWhat you doWhat happens
Sync from this buildOperator rolePackages > Sync from this buildNote 'Registered n, refreshed n, drifted n, unchanged n.'; every modules/*/module.json is a Draft package with source 'Build manifest', licence 'Proprietary (a2NSoft)', its SHA-256 and file count; running it again with no code change gives 'Registered 0, refreshed 0, drifted 0' and all unchanged
Sync never rewrites a reviewed versionA Reviewed or Certified package whose files are later changed on the serverSync from this build after the files changeThe package is NOT updated; it is marked DRIFTED (Digest column shows the warning mark, Overview Drifted tile +1), history shows 'package.drift'; when files return, 'package.drift_cleared'
Register an uploaded packageOperatorRegister a package: Code X_DEMO, Version 1.0.0, Title, 64-hex SHA-256, Licence MIT, Support owner; SaveCreated as Draft, source Uploaded, kind custom, licence review Pending, files 0; history 'package.registered'

Package record

ActionWhenWhat you doWhat happens
Edit only a draftA Draft and a Reviewed packageEdit the draft's dependencies and save; try to edit the Reviewed one (API PUT)Draft saves and revision +1; Reviewed: Edit not offered; API -> 'A reviewed or certified version cannot change. Register a new version.'
Licence reviewApprover role; Draft packageLicence review > Decision Approved > OK; repeat with Rejected and no noteLicence review = Approved; with Rejected the note is required ('This is required.'); on a Certified/Retired version -> 'This version is already certified or retired.'
Review refused until every check passesDraft package with licence Pending and no support ownerOpen Review checks tab; press ReviewTab lists each problem; Review refused with the first: 'Licence review is pending; it must be approved first.' then 'Name the support owner or maintainer.'; a dependency not available -> 'X_DEMO 1.0.0 needs FIN >=9.0, which is not available as a reviewed version.'
Dependency cycle refusedDraft A depends on B; reviewed B depends on AReview ARefused 'Dependency cycle: A -> B -> A.' (arrows shown as the arrow sign); A stays Draft (PLT T001)
Core range checkDraft package with Core versions = 2Review itRefused 'X_DEMO 1.0.0 needs core 2; this build is core 1.0.0.'; with core 1 or >=1.0, <2.0 it passes
Review then certify by another personUser A release manager, user B approver; package with all checks passingA presses Review; A (if also approver) tries Certify; B presses CertifyReview -> Reviewed (reviewed by A); A's Certify refused 'Somebody other than the person who prepared this package version must approve it.'; B's Certify -> Certified, event platform.package_certified.v1
Send back a reviewed versionApprover; Reviewed packageSend back with reasonBack to Draft; reviewer cleared; reason saved; a Draft package cannot be sent back
Retire blocked while in useCertified package in an Approved or Active release; configuration ownerRetireRefused 'Release REL-0001 still runs this version.'; if it is the only reviewed version and another reviewed package depends on it -> '<CODE> <ver> depends on <code> and no other reviewed version would remain.'
Versions and use tabPackage with 2 versions, a dependant and a releaseOpen Versions and useVersions (newest first), Needed by (packages listing this code), Releases carrying it; each row opens its record

Capabilities / Apps

ActionWhenWhat you doWhat happens
App install asks the registryFlag platform.enforce_registry off; package FIN registered but only DraftAs a company admin install or upgrade Finance from the apps screenRefused before anything is written: ''finance' needs package FIN, which has no reviewed or certified version in the package registry.'; with FIN Reviewed it installs (PLT-A1)

Extension record

ActionWhenWhat you doWhat happens
Register an extensionOperatorNew: namespace x_acme, hook partner.after_save, core 1, function custom_modules.acme.hooks:on_save, field 'contacts.partner x_acme_tier'; SaveDraft created; name defaults to x_acme; written for hook v1; Checks tab lists anything missing
Review and activate by someone elseRegistered by A (operator); B release manager; C approverB Review; A tries Activate; C ActivateReview needs no open problems (else first problem shown); A refused 'Somebody other than the person who prepared this extension must approve it.'; C activates only if the function imports, else 'The function cannot be loaded: ...'
Disable and back to draftActive extensionOperator Disable; configuration owner Back to draft; edit; Review againDisabled (data stays readable); Back to draft allows edits; Active -> edit not offered

Release record

ActionWhenWhat you doWhat happens
Create a releaseOperator; an Approved environment STAGING; certified packagesReleases > New: Title, Environment STAGING; Save; Packages tab: Edit, tick 2 packages, Save packagesNumber REL-0001 (next free); state Draft; migration head defaults to this build's heads; the only active policy that fits the tier is attached automatically; Packages tab lists both with Digest matching
Only reviewed/certified versions offeredDraft package existsRelease Packages tab in editDraft/retired versions not listed ('Only reviewed or certified versions can go into a release.')
Attach an SBOMDraft releaseEvidence tab: Take and attach an SBOMSBOM digest, component count and 'no blocking advisory' / 'n blocking' shown; only in Draft (else 'An SBOM is attached while the release is a draft.')
Submit gate: draft -> reviewedDraft release with rollback plan, SBOM (if the policy asks), licences approvedGates tab: read 'Before submit'; press SubmitChecks licence, artifact digests, dependencies, core and vulnerabilities (+ SBOM when the policy lists sbom). All pass -> Reviewed; artifact hash and provenance (commit, clean tree, host, time) written; gates recorded with time
Submit refusalsDraft releaseSubmit with: empty rollback plan; then empty migration head; then a package whose licence is Pending; then no SBOM and a vulnerability gate'Write the rollback plan: forward fix or restore, and how.'; 'Say which migration head the release brings the schema to.'; 'Every package's licence is approved: Licence review open for X_DEMO 1.0.0 (pending)'; 'No unwaived high or critical advisory: No SBOM: nothing to check vulnerabilities against.' - state stays Draft but the failing gates are saved on the Gates tab
Drifted artifact blocks submitA package in the release drifted after it was addedSubmitRefused 'Package artifacts match their recorded digest: X 1.0.0: the files no longer match the reviewed digest.' (PLT T008)
Unwaived high advisory blocks submitSBOM contains a component matched by a high/critical advisorySubmit; then waive the advisory; Submit againFirst: '... 1 unwaived high or critical advisory(ies) in the SBOM.'; after waiver it passes (advisories are re-checked at the gate)
Upgrade rehearsalDraft or Reviewed release; a stored backupEvidence: choose Newest backup; Rehearse the upgrade on a restored copy; then Job runs > Run the scheduler nowA rehearsal drill DRL-xxxxx is queued as a run of platform.upgrade_rehearsal; after it runs it shows Passed with 'Reached' = the release's migration head, or Failed with the reason
Stage gate: reviewed -> stagedReviewed release; release managerStageNeeds a PASSED rehearsal of THIS release in the last 30 days reaching its migration head (+ restore drill / module contracts when the policy lists them). Without -> 'Upgrade rehearsal passed on a copy: No passed upgrade rehearsal for this release in the last 30 days.'; wrong head -> 'Rehearsal DRL-00002 reached <x>, not <y>.'; with policy restore and none -> 'No passed restore drill in the last 30 days.'
Approve with one approverStaged release, policy approvers 1; user C approver who did not create, submit or stage itApprove: QA disposition, tick 'I have read and accept the rollback plan'; OKState Approved; approver C; manifest written (lines, artifact hash, migration head, rollback plan digest, QA, approvers, SBOM, provenance, core 1.0.0) and HMAC signature shown 'valid'; Approvals 1/1
Approve with two approversPolicy approvers = 2; approvers C and DC approves; check state; C approves again; D approvesAfter C: still Staged, Approvals 1/2, history 'release.approval_recorded'; C again -> 'You have already approved this release.'; after D: Approved and signed with approvers [C, D]
Activate gateApproved release; deployment already done on the serverActivateChecks: signature intact, artifact hash unchanged, digests, verified backup inside the environment RPO, inside the maintenance window, live schema = migration head. All pass -> Active, environment's Active release = this one, environment migration head updated, event platform.release_activated.v1
Activate: backup older than the RPOEnvironment RPO 1440 min; newest verified backup finished 1500 min agoActivateRefused 'A verified backup inside the RPO: The newest verified backup is 1500 min old; the RPO is 1440 min.'; with a backup 600 min old: 'Verified backup 600 min old (RPO 1440 min).' passes; no verified backup -> 'No verified backup. Take and verify one first.'
Activate: maintenance window arithmeticEnvironment window Friday 23:00, 120 min, Asia/DubaiTry Activate on Fri 22:50 Dubai, Fri 23:10, Sat 00:30, Sat 01:0522:50 refused 'Outside the maintenance window (Friday 23:00, 120 min, Asia/Dubai).'; 23:10 and Sat 00:30 inside (window opened Fri 23:00 and lasts to Sat 01:00); 01:05 outside. With no start time: 'No maintenance window is set: any time is allowed.'
Activate: schema not migratedRelease migration head differs from the live databaseActivateRefused 'Live schema is at <live>; the release expects <head>. Deploy and migrate first.'
Activation supersedes the previous releaseREL-0001 Active on STAGING; REL-0002 Approved for STAGINGActivate REL-0002REL-0002 Active; REL-0001 becomes Retired with reason 'Superseded by REL-0002.'; environment Active release = REL-0002
Manifest tampered after approvalApproved release whose stored manifest is changed (test DB only)ActivateRefused 'The approved manifest no longer matches its signature. It was changed after approval; reject the release and approve it again.'; changed lines -> 'The release's packages are not the ones that were approved.'
Recover: forward fixActive REL-0002; another release REL-0003 for the same environmentRecover: Outcome Forward fix, fixing release id = REL-0003's internal id, reasonState Recovered, forward fix linked; another environment's release -> 'Name the fixing release for the same environment.'
Recover: restored from backup / failedActive release; a passed restore drillRecover: Restored from backup with the drill id; on another release Recover: Failed - not recoveredRestored: state Recovered with the drill linked (a failed drill -> 'A restore is evidenced by a passed restore of that backup.'); Failed outcome: state Failed. No down-migration is run
Send back to draftReviewed or Staged release; approverSend back with reasonBack to Draft; staged by and approver cleared; any recorded approvals deleted; reason shown in Last reason; history kept
CancelDraft/Reviewed/Staged/Approved release; release managerCancel with reasonCancelled; no further steps offered; an Active release cannot be cancelled ('A active release cannot be canceled.')
RetireActive or Recovered release; configuration ownerRetire with reasonRetired; if it was the environment's active release the environment has no active release
Edit only while draftReviewed releaseTry Edit (API PUT)'Only a draft release changes. Reject it back to draft first.'
Idempotency keyDraft release (API)POST submit with idempotency_key K twice; then K with a different bodySecond call returns the first answer with replayed=true and nothing happens twice; different body -> 409 'That idempotency key was already used for a different request.'

Environment record

ActionWhenWhat you doWhat happens
Create an environmentConfiguration ownerNew: STAGING, Staging, RPO 1440, RTO 240, window Friday 23:00 120 min, secret env:A2N_DB_PASSWORD; SaveState In review; smart 'Window Open/Closed' follows the time; only one environment can be 'This server'
Approve by someone else, then deployCreated by A; B approver; operatorA tries Approve; B Approve with reason; operator Mark deployedA refused 'Somebody other than the person who prepared this environment must approve it.'; B -> Approved and a new row in Approved versions (#1, snapshot tier, RPO, RTO); operator -> Deployed
Change an approved environmentApproved or Deployed environmentTry Edit; press Back to review; Edit RTO; SaveEdit not offered until Back to review ('Send the environment back to review before changing it.'); then saves; history lists before/after
Archive refused while a release is in flightStaged/Approved/Active release on the environmentArchiveRefused 'Release REL-0001 is still in flight here.'; archived environments disappear from the release Environment picker

Scheduled jobs

ActionWhenWhat you doWhat happens
Platform jobs created on first visitFresh workspaceOpen Scheduled jobs7 jobs: platform.metrics_snapshot (every 5 min, Enabled), platform.alert_scan (5 min, Enabled), platform.package_scan (daily 03:00, Enabled), platform.sbom (weekly Sunday 03:30, Tested), platform.prune (daily 04:00, Enabled), platform.restore_drill and platform.upgrade_rehearsal (On demand, Tested, 1 attempt)

Job record

ActionWhenWhat you doWhat happens
Create, test and enable a jobConfiguration owner + operatorNew: code test.heartbeat, Handler Heartbeat, Every N minutes 60; Save; Run now (blank key); Run the scheduler now; EnableCreated Draft; Run now on a Draft runs as a test (trigger 'test'); when it succeeds the job becomes Tested automatically; Enable -> Enabled with Next due set; a Draft job cannot be enabled directly ('A draft job cannot be enabled.')
Interval slot arithmeticEnabled job every 60 minEnable at 10:17 Dubai (06:17 UTC); read Next dueNext due 11:00 Dubai (07:00 UTC): interval slots are counted from 1 Jan 2026 00:00 UTC, so a 60-minute job runs on the UTC hour; run key '2026-10-02T07:00Z'
Daily schedule in Dubai timeDaily job At 02:00, Asia/DubaiEnable on 2 Oct after 02:00 DubaiNext due 3 Oct 02:00 Dubai = 2 Oct 22:00 UTC; run key '2026-10-02T22:00Z'; weekly uses the chosen weekday (Monday 0 ... Sunday 6)
Missed slots after downtime60-minute job; scheduler off for 3 hoursTurn the scheduler back on / Run the scheduler nowOnly the latest due slot is accepted (one run), not three; Next due moves to the next future slot
Same run key is one runEnabled jobRun now with run key 'test-key-1' twiceSecond press returns the same run (created = false); Runs accepted +1 only; the job's Run now is hidden while Paused ('Enable the job first (a draft job runs only as a test).' via API)
Pause and back to draftEnabled jobPause; Back to draft; edit; savePaused clears Next due and is not claimed; Back to draft (configuration owner) allows edits; runs already accepted keep the policy they started with (Policy at acceptance on the run)

Run record

ActionWhenWhat you doWhat happens
Retry with backoff then dead letterJob with Attempts 3, Backoff 60 s whose handler failsRun it; run the scheduler repeatedlyAttempt 1 fails -> Waiting to retry, next retry +60 s; attempt 2 -> +120 s; attempt 3 fails -> Dead letter, event platform.job_failed.v1, error code and redacted message shown; with Backoff 3600 the 4th wait would be 28800 s but is capped at 21600 s (6 h)
Retry a dead letterA Dead runOpen it; Retry (same run key)Back to Queued, attempts 0, same run key; side effects already recorded are not repeated; a Succeeded run shows no Retry ('Only a dead or cancelled run is retried.')
Cancel a runA Queued run and a Running runCancel eachQueued: Cancelled at once with error 'Cancelled on request.'; Running: cancel requested, it stops at its next check and ends Cancelled; a finished run -> 'This run has already finished.'

Job health

ActionWhenWhat you doWhat happens
ReconciliationSeveral runs in different statesOpen Reporting > Job healthFor each job Accepted = Queued + Retrying + Running + Succeeded + Dead + Cancelled and Reconciles = Yes; the line says 'Reconciles'

Restore drills

ActionWhenWhat you doWhat happens
Run a restore drillOperator; a stored backup with fingerprintRun a restore drill: Newest stored backup; OK; Job runs > Run the scheduler now; open the drillDRL-00001 queued then Passed: 'Restored n rows in m tables; every count, file digest and ledger total matches.'; Rows n/n, Stored files match, Ledger totals match; RTO measured; RPO = backup age in minutes; the scratch copy is removed

Drill record

ActionWhenWhat you doWhat happens
Drill against RTO/RPO targetsDrill linked to an environment with RTO 240 min, RPO 1440 min (via rehearsal or API environment_id)Run with a backup 1500 min oldFailed: 'The backup was 1500 min old, beyond the RPO of 1440 min.'; a restore over 14400 s -> 'The restore took <n>s, beyond the RTO of 240 min.'
Old backup without fingerprintA backup taken before fingerprintsRun a drill on itOnly row counts reconciled; message ends 'This backup was taken before file and ledger fingerprints were recorded, so only row counts were reconciled.'; files/ledger show 'not fingerprinted'
Corrupt backup fileA stored backup whose file was changed (test only)Run a drillFailed 'The stored backup is not the file that was written: its checksum differs.'; differences listed where counts differ

Recovery evidence

ActionWhenWhat you doWhat happens
Recovery reportSeveral finished drillsOpen Reporting > Recovery evidenceLine 'n / m drills passed - x with every row count matching - y with file digests matching - z with ledger totals matching'; green 'Reconciles' only when every finished drill passed

Alerts

ActionWhenWhat you doWhat happens
Shipped alert policiesFresh workspaceOpen Alert policies6 active policies: QUEUE-LAG (>900 s, 15 min, critical), P95 (>2000 ms, warning), ERRORS (>5 %, warning), DEAD-JOBS (>0, warning), BACKUP-AGE (>26 h, critical), DRILLS (>0 failed in 30 days, warning, release manager)
Alert opens and auto-resolvesA dead-letter run existsAlerts > Evaluate now; then retry the run until it succeeds; Evaluate nowDEAD-JOBS opens one alert: detail 'Dead-letter jobs is 1.0 (> 0.0) over 60 min.' with up to 5 correlation ids; a second evaluation updates the same alert (no duplicate); when the count is back to 0 the alert becomes Resolved
Queue lag arithmeticOldest queued run waiting 20 minutes (scheduler off)Evaluate nowQUEUE-LAG value 1200 (> 900) opens a Critical alert; lag above a week is reported as 604800
AcknowledgeAn open alert; operatorPress Acknowledge on the rowState Acknowledged; button disappears; still counted in Overview Open alerts until resolved

Alert policy record

ActionWhenWhat you doWhat happens
Create, change and pause a policyConfiguration ownerNew policy; Activate; try Edit while active; Pause (operator); Edit; ActivateEdit refused while active ('Pause the policy before changing it.'); paused policies are not evaluated

Flag record

ActionWhenWhat you doWhat happens
System flagsFresh workspaceOpen Feature flagsplatform.enforce_registry (workspace) and platform.uninstalled_apps_readable (per company) exist as Draft, value false
Propose, approve, versionA config owner, B approverA creates sales.quick_quote (Yes / no); Propose a value true; B ApproveAfter propose: Proposed, Waiting true, In force false; after B: Active, value true, Version 1 row with approved by B; event platform.flag_changed.v1
Change an active flagActive flag value trueA: Propose a change -> false; B: Approve the changeOld value stays in force while waiting; after approval value false, Version 2
Refuse a proposalProposed flagB: Refuse with reasonBack to Draft, pending cleared, reason kept
Effective datesActive flag true with Effective to = 5 minutes from nowWait past the end; reopen'In force' reads false (the default) after the end, with no new approval
Per-company valueActive per-company flagCompanies tab: choose a company, value true, Set for this company; RemoveRow added and that company reads true; Remove deletes it and the company falls back to the flag value
Uninstalled apps readableplatform.uninstalled_apps_readable approved true for one company; an app turned off thereOpen a list of the turned-off app; try to save a recordReads answer; every change refused. Other companies (flag false) are refused everything as before

Bills of materials

ActionWhenWhat you doWhat happens
Take an SBOM and downloadOperatorTake an SBOM now; open it; Download CycloneDXComponents from Python and npm with licences; Licence flags for unknown/copyleft licences; file sbom-<digest12>.cdx.json downloads

Vulnerability advisories

ActionWhenWhat you doWhat happens
Import and waiveRelease manager imports, approver waivesImport the sample record (requests <9.0 high); Waive with reason and end date; Lift waiverCreated 1 (a second import updates it); the SBOM shows a blocking finding; waiver shows 'until <date>'; Lift returns it to blocking

Platform roles

ActionWhenWhat you doWhat happens
Grant and revokeWorkspace ownerGrant a role: test.operator / Operator; RevokeRow Active Yes, Granted by owner; Revoke -> 'Revoked' (row kept); revoking again -> 'That role is already revoked.'

Platform audit trail

ActionWhenWhat you doWhat happens
Every command auditedPerform a release submitOpen Audit trail; filter Record = releaseRow with who, action release.submit and correlation id; the same correlation id is on the response header X-Request-ID

Capabilities

ActionWhenWhat you doWhat happens
Company capability listA member with no platform roleOpen Platform (or Reporting > Capabilities)Note about the console; list of the company's installed apps with reviewed package version and Certified / Reviewed / Not reviewed; server tier and 'Core 1.0.0'; no host names or secrets

Workload

ActionWhenWhat you doWhat happens
Latency measurementsUse the app for a few minutesOperations > Workload; Measure againPer route p50/p95/p99 and 5xx counts; values are for this server process only and reset on restart

Record screens

ActionWhenWhat you doWhat happens
Edit conflict (revision)Same release open in two tabsTab 1 Save; tab 2 Save or SubmitTab 2 refused 'Somebody changed this record since you opened it. Reload and try again.' (409); nothing overwritten