Event-Driven Notification Platform · View 22 of 26 · 5 · Operations
Administration and Operations Surface
What an operator can do, who may do it, and which actions are dangerous enough to gate.
Copy
PNG
PDF
⋯
Editable source
SVG
draw.io
All views
Read — any operator with tenant scope
Read — any operator with tenant scope
Inspect
Inspect
Event browser
by id · type · window
Event browser...
Notification history
per recipient timeline
Notification history...
Failure explorer
error class · provider
Failure explorer...
System health
lag · DLQ · SLO
System health...
Configure — tenant administrator, reviewed change
Configure — tenant administrator, reviewed change
Business configuration
Business configuration
Rule management
CEL editor · dry run
Rule management...
Template management
draft · publish · roll back
Template management...
Preference defaults
Preference defaults
Platform configuration
Platform configuration
Provider management
rank · credentials · TPS
Provider management...
Retry policy
attempts · backoff · budget
Retry policy...
Feature flags
Unleash · per tenant
Feature flags...
Tenant quotas
Tenant quotas
Dangerous — step-up authentication, four-eyes, always audited
Dangerous — step-up authentication, four-eyes, always audited
Recovery actions
Recovery actions
Event replay
range capped · second approver
Event replay...
DLQ redrive
batch limited
DLQ redrive...
PII erasure
irreversible
PII erasure...
Tenant pause
stops all sends
Tenant pause...
Admin API
everything the console does
Admin API...
Keycloak
roles · step-up MFA
Keycloak...
Audit Log
WORM · 7 y
Audit Log...
roles
roles
who · range · count
who · range · count
subject · scope
subject · scope
diff
diff
Administration and Operations Surface
Administration and Operations Surface
Application we own
Application we own
Security / platform
Security / platform
Interface / broker
Interface / broker
Risk / gap
Risk / gap
synchronous
synchronous
event / async
event / async
The console is a client of the Admin API and has no privileged path of its own. The red row is the reason this view exists: replay at scale can duplicate millions of notifications, so it is gated, capped and audited rather than merely permitted.
The console is a client of the Admin API and has no privileged path of its own. The red row is the reason this view exists: replay at scale can duplicate millions of notifications, so it is gated, capped and audited rather than merely permitted.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
Decisions
The console is a client of the Admin API and has no privileged path of its own, so every capability is scriptable and testable
Read, configure and dangerous are three separate authorisation tiers, not one admin role
Every dangerous action requires step-up authentication, a second approver and writes an audit record before it runs
Why replay is treated as dangerous
A careless range can re-decide millions of events and, if deduplication is degraded, re-send them
Capped by event count and time range, requires a second approver, and dry-run reports the affected count before execution
The same treatment applies to DLQ redrive, PII erasure and tenant pause
Deliberate omissions
The console's screen designs and information architecture, which are a product deliverable
Break-glass access, which follows the enterprise privileged-access standard rather than a platform-specific one
◀ Observability and Operations
All views
The Operator Loop ▶