Confirm scope
Use exact devices, fresh inventory, collected resources, and the intended execution path. Read the full preview.
Automation Platform
This guide is available from the authenticated platform workspace.
Return to sign inOperator edition · English
A practical guide to observing the network, planning safe changes, approving work, executing through governed workers, and reviewing evidence.
Core operating model
Planning and approval do not change a device. Device access begins only when the required gates pass and a worker claims authorized work.
Use exact devices, fresh inventory, collected resources, and the intended execution path. Read the full preview.
Do not repeat a request while it is queued or running. Open its detail view and follow the evidence.
Check configuration presence and operational state separately. Create a governed withdrawal when the resource is no longer needed.
If a run shows unknown_outcome, do not retry. The platform keeps the device write lock. A Platform Administrator must verify the device out of band and record the result.
Global controls
The top bar and left status card show the platform state that applies to every page.
Press /, then search by network element, management IP, device, serial number, software version, or job. Use arrow keys and Enter to open a result; Esc closes the list.
READ-ONLY means device I/O is globally off. DEVICE I/O ON means access may proceed only if every other gate also passes.
A green dot means all required runtime services are available. A red mark needs attention. Click the badge for service, heartbeat, queue, and Start or Restart controls.
PG OK confirms the database health check. Treat PG DOWN as a platform incident. Do not start new work.
Theme preference is saved in this browser. Open the account menu or Users & Access to review your profile, group, effective permissions, password controls, and sign out.
Navigation, management panels, and operation buttons appear only when your effective permissions allow them. Users & Access stays available for your own account. A hidden control is not a platform failure; check your assigned group or overrides.
Before Start or Restart, inspect its queue depth and purpose. When Device I/O is on, an available worker may immediately claim already-authorized items.
Overview
Use the topology for network context, link evidence, traffic context, and fast access to a device inspector.
The node ring shows role; the center shows reachability. Link color shows operational state and line style shows confidence.
Drag nodes to reposition them and scroll to zoom. Use Reset Layout to return to the computed placement.
Show device name, system IPv4, or system IPv6. Keep labels limited when the view is dense.
Select a node to open Inventory, Configuration, Readiness, Attributes, Allowlist, and Auto-Init details.
Run allowed read operations, open traffic evidence, or use the permission-gated link handle to begin a LAG plan between two devices.
Overview
Use the Dashboard as the platform summary, not as proof that one device is ready.
credentials.manage; otherwise your access levelNetwork
This page owns the platform identity, reachability, readiness, trust, and management lifecycle of each network element.
Add the approved inventory list. Check hostname, management IP, expected network OS, role, and tags before import.
Use Nokia SR OS Auto-Init only for the supported Nokia lifecycle. Use Adopt existing management for an already-configured Cisco IOS XR device.
Independently verify the presented SSH algorithm and SHA-256 host key. Never reuse trust from another address or accept a changed identity from the UI alone.
For Nokia, provide the approved bootstrap credential and reason. For Cisco IOS XR, choose a compatible stored read profile or enter a one-time login, add the reason, then select Adopt & Discover.
Open the Discovery Job. Cisco adoption must end as MANAGED · READ ONLY; Nokia must complete its supported management verification before normal Sync and automation.
Review Inventory, Configuration, Readiness evidence, Attributes, Allowlist, and lifecycle controls before planning a change.
Do not confirm a changed hostname or host key from the UI alone. Verify through an independent source such as console, VM identity, serial, or approved device records.
Cisco IOS XR adoption sends only the fixed read-only discovery command set. It does not run Nokia Day-0, enter configuration mode, provide Cisco writes, or claim full readiness.
Re-enroll rechecks the host key, rotates managed CLI, NETCONF, and SNMPv3 credentials, rebinds profiles, and restores automation only after live verification.
Network
Review facts collected by discovery: hardware identity, software, capabilities, configuration mode, ports, cards, routing, and services.
Operations
Start with the desired network outcome. The platform builds typed, immutable per-target plans and shows exact configuration, checks, rollback, and hashes before execution.
Select the exact domain or service.
Use collected, available resources.
Check every target payload, rollback, verification, and hash.
Direct, approval, or MOP only when policy offers it.
Track all targets until verified or stopped.
Select every participating NE, a collected port or LAG and VLAN for each endpoint, then set the common EVPN values. VPRN routing is configured per endpoint. Review each Nokia YANG payload in the matching endpoint card.
A successful creation record remains immutable. When the resource is no longer needed, open it and create a governed withdrawal. Remove dependent routing before its parent service, or use the reverse MOP offered by a completed blueprint.
Direct mode may skip Change Request approval or MOP orchestration, but it still requires authentication, permission, Device I/O, allowlist, host-key pin, write credentials, validation, write lock, and audit evidence.
A verified service or routing object proves the expected configuration is present. Check service, interface, adjacency, session, and traffic state separately when operational readiness matters.
Operations
Review durable discovery execution history, active work, target scope, and append-only evidence.
If the detail says authorization is missing or expired, start a new authorized operation from the correct page. Do not start extra workers as a workaround.
Assurance
Review the latest per-device decision from the onboarding readiness rule engine. This is evidence coverage, not generic continuous monitoring.
Assurance
Preserve normalized, checksummed configuration evidence and trace how each snapshot is used by governed workflows.
A failed capture does not overwrite the last known-good snapshot. Always compare timestamps before using an older row as current evidence.
Operations
Run an operator-triggered, bounded-concurrency collection of readiness, inventory, and configuration across authorized NEs.
The page records manual fleet runs. It does not claim that an unattended scheduler is configured.
Assurance
Export portable fleet readiness evidence for review, handoff, or an approved maintenance record.
Check reachability, onboarding, readiness time, snapshot, and access gates.
HTML is the readable report; CSV supports analysis; JSON preserves structured data.
Open the downloaded file and confirm its generation time and expected device scope.
Operations
Create verified local packages and use the governed candidate-based restore path. A restore does not directly overwrite config.cfg or require a reboot.
Select devices, choose New schedule from selection, then set Daily, Every N days, or Weekly, the local time, IANA timezone, source, and enabled or paused state. Editing or deleting a schedule never deletes its existing packages or audit history.
Check the device, backup source, artifact checksum, preflight baseline, complete diff, and mode. If the baseline changes after preflight, execution must stop. Never approve an unexplained diff.
A startup SCP package reflects the saved BOF file. Unsaved running changes are not included.
Changes
Use a Change Request for controlled configuration with pre-check evidence, an exact dry-run diff, approval, separate execution, post-check, and rollback evidence.
Select an approved template, target NE, and valid parameters. Review the frozen intent.
The platform captures fresh configuration, checks access and drift, and records current values for rollback.
Review the private-candidate diff. The candidate is discarded. An empty diff completes as a verified no-op.
The approver reviews the exact hash and diff. Approval issues a one-use authorization with a limited lifetime.
The executor must differ from the approver. The worker reacquires evidence, matches the approved diff, commits, and runs post-check.
Confirm verified or rolled back. Use a typed withdrawal for a standing resource. Resolve uncertain outcomes only with external evidence.
If parameters, device baseline, or the live candidate diff changes, the approved authorization cannot be reused. Build and approve a new plan.
Changes
Templates are vendor-scoped, versioned definitions that turn typed parameters into reviewed configuration and rollback plans.
A direct saved-template link and a renderer identifier are different provenance. Review both totals. The server blocks deletion when a governed reference still depends on the record.
A rendered preview does not connect to a device or push configuration. Secrets remain placeholders and must never be embedded in a template.
Operations
Use a Method of Procedure for a dependency-aware 1–N runbook with frozen plans, ordered execution, verification, stop conditions, and an independent reverse workflow.
Choose a preset or arrange LAG, interface, IGP, BGP, VPRN, and other native components.
Complete every component. Later steps may use projected results from earlier steps for planning only.
Compile every child, then review target payloads, checks, rollback, dependencies, and immutable hashes.
Set title and Minor, Major, or Critical tier. Critical work requires a maintenance window.
ai.configure.mop.plan permits draft use with the minimal enabled-Provider list. Only ai.configure exposes Provider URLs, model and key controls. API keys go directly to the encrypted broker and are never shown again.
AI cannot approve, execute, change hashes, weaken gates, or replace operator review. Never send device passwords, private configuration, customer data, or other secrets in a prompt.
ARCHIVE N MOP RUNS for a selection or CLEAR TERMINAL MOP HISTORY for all terminal history.It hides terminal runs from the operational list but retains steps, approvals, child evidence, report hashes, and the append-only Audit Log. It does not delete or withdraw device configuration.
A failed child stops later components. The platform does not blindly undo previously verified components. Use the explicit, newly planned reverse workflow when it is safe and approved.
Governance
Use the append-only audit log to reconstruct who did what, when, to which resource, and with what outcome.
Governance
Platform Administrators control device I/O, collection cadence, credential references, trust pins, relocation, and host-native services here.
Keep off during setup, migration, testing, or an unresolved incident. Enabling it does not bypass any per-device gate.
Set the polling behavior appropriate for platform capacity and evidence needs.
Enroll a profile name, username, password, and purpose. Secrets go to the host-local broker and are never shown again.
Record only independently verified SSH SHA-256 fingerprints. Revoke trust when device identity is uncertain.
Open WORKERS, inspect heartbeat and queue state, then start in dependency order beginning with Credential Broker.
Use only during a planned rebuild. Full estate retirement requires Device I/O off, settled work, and the exact confirmation phrase.
Do not replace a shared profile, reset the broker, retire inventory, or renew a host key to clear an unrelated error. Identify the exact failed gate first.
Governance
Every signed-in user can manage their own account. Four duty groups define the normal workflow. A Platform Administrator may edit non-admin group defaults and add or deny fixed delegatable permissions for one user.
| Group | Primary use | Typical actions |
|---|---|---|
| Read-only | Observe platform and network evidence | Dashboard, topology, inventory, jobs, reports |
| Planner | Create governed work | Inventory operations, changes, Services, MOP plans |
| Reviewer & executor | Review and release work | Approve, reject, execute, rollback, audit read |
| Platform administrator | Platform ownership and break-glass controls | Users, governance, lifecycle, restore, workers, unrestricted terminal |
platform.read; it is mandatory.ai.configure as sensitive and default-off. It may be granted to a group or one user when required.terminal.admin here. Administrator SSH is available only as a special per-user permission.terminal.admin only for a named user who needs audited Administrator SSH. It can never be a group default.Even when one group has both review and execution permissions, the same signed-in person cannot approve and execute the same governed scope.
The permission only reveals the governed terminal control. Exact target trust, allowlist, host key, device AAA, credential profile, Device I/O, and terminal authorization still apply.
Governance
Use this page to understand delivery status and planned capabilities. It is a product status view, not an operational control.
The application capability has current repository tests or witnessed evidence. Deployment-specific SSO, TLS, HA, DR, secrets, or scale gates may still remain.
A real slice exists, but vendor breadth, live canaries, scheduling, or environment closure is still open. Read the stated boundary before use.
The capability is not an available control. Do not infer an API, worker, schedule, or device action from a roadmap row.
A roadmap item may be planned, partial, or complete. For an operational decision, rely on current UI controls, current evidence, and the active design contract.
Reference
Start with the failed gate. Avoid broad restarts or repeated submissions.
Open the account menu and check group and effective permissions. Sign in again if access was recently changed because permission updates revoke existing sessions.
MOP planning permission allows use of enabled Providers but does not reveal their configuration. Check whether your effective permissions include ai.configure. It is default-off outside Platform Administrator.
Click WORKERS. Check the exact service, heartbeat, installation state, and queue depth. Start or restart only the failed fixed service and only after checking pending authorized work.
Reachability is only one signal. Check active lifecycle state, Device I/O, allowlist expiry, SSH host-key match, credential profile, readiness, and operation permission.
Open the Network Element, select Cisco IOS XR · adopt existing management, independently verify the exact host key, choose a compatible read credential or enter a one-time login, add the reason, and use Adopt & Discover. Do not run Nokia Auto-Init.
Open the per-NE detail. Identify whether Readiness, Configuration, or Discovery lacks evidence. Fix that exact dependency, then run the per-device Sync.
Collect fresh evidence, review what changed, and build a new plan. Never reuse an old approval or weaken the stale-evidence gate.
Check authorization expiry, worker health, queue order, target write locks, and active unknown outcomes. Do not submit duplicates.
Stop all writes to the target. Do not retry, roll back blindly, or release the lock. A Platform Administrator must verify the live device through an approved out-of-band path and record verified or rolled back with evidence.
A Platform Administrator may have soft-archived terminal history. Check the append-only Audit Log and retained execution evidence. Archiving the list row does not withdraw device configuration.
Your platform session is missing, expired, or was revoked. Return to the platform, sign in, complete any required password change, then open Tutorial again.
Reference
Use state text and evidence, not color alone.
| Status | Meaning | Operator response |
|---|---|---|
| READY / VERIFIED | Required checks or expected configuration evidence passed. | Check freshness and operational state before the next dependent action. |
| QUEUED / RUNNING | Work is waiting or being processed. | Open the detail view. Do not submit a duplicate. |
| INCOMPLETE / PARTIAL | Some work completed, but required evidence or targets are unresolved. | Review per-step or per-target results. |
| STALE | The evidence is older than the accepted collection window. | Refresh or recollect before using it for a plan. |
| FAILED / DOWN | A deterministic error or unavailable dependency stopped work. | Record the error code, fix the exact cause, then create a fresh attempt. |
| UNKNOWN OUTCOME | A connection was lost where commit state may be uncertain. | Stop, preserve the lock, and perform approved manual verification. |
| UNENROLLED | The record is historical and excluded from platform automation. | Use controlled Re-enroll; do not renew trust directly. |
| NOT ONBOARDED | The imported NE has no completed platform trust and read-management path. | Choose the correct network OS and use its supported initialization or adoption flow. |
| MANAGED · READ ONLY | Cisco IOS XR fixed-command discovery passed with exact identity and authorization. | Use collected evidence only. Do not assume write, Day-0, or full readiness support. |
| READ-ONLY | Global real-device I/O is disabled. | Planning and review may continue. Device collection or writes cannot. |
Try a page name, workflow state, or action such as “backup”, “approve”, or “host key”.