Platform Console

Sign inSign up

Marvia-15

One platform, one workspace, two runtime modes.

The console runs atop the kernel as a privileged workspace. It reuses the shell, the widget framework, the runtimes and every registry — administration adds permissions, never a second architecture.

Consoles

20

Platform roles

10

Permissions

38

Super admin grants

38

Single platform

The console is a privileged workspace on the same kernel, with zero duplicated architecture.

Dual modes

Workspace mode and platform mode change navigation and permissions, nothing else.

RBAC everywhere

Ten platform roles, uniform permission checks across every console.

Registry-driven

Consoles consume existing registries; the console adds no parallel system.

Runtime modes

Mode switching alters navigation and permissions, nothing else

Platform mode is offered only to users holding at least one platform role, and every action inside it is audited.

workspace

Workspace mode

Audience
Every member of a workspace, including platform staff acting as a user.
Navigation
Core kernel navigation plus extension links.
Permissions
Workspace RBAC only; platform permissions are inert.
platform

Platform mode

Audience
Administrators and operators of the Marvia platform.
Navigation
Console sections, resolved from the console registry and filtered by role.
Permissions
Platform RBAC, evaluated on every request and every render.
  • Mode switching changes navigation and permissions; it never changes the shell.
  • Platform mode requires at least one platform role; otherwise the switch is not offered.
  • Every platform-mode action is written to the audit centre with the acting role.
  • There is no admin-only component: consoles are built from the same registries as the product.

Platform navigation

Twenty consoles, derived from the registry

A section the operator cannot read is absent, not disabled. Groups collapse when empty.

Operations

Dashboard

platform.dashboard.read
OverviewPlatform healthRecent activityAnnouncements

Queues

platform.queue.read
Queue statusRetriesDead lettersThroughput

Jobs

platform.job.read
Scheduled tasksAutomationExecution logs

System health

platform.health.read
WorkersDatabasesQueuesStorageAPIErrors

Tenancy

User management

platform.user.read
UsersRolesPermissionsAuthenticationSessions

Workspace management

platform.workspace.read
OwnersMembersProjectsCreditsExtensionsHealth

Project management

platform.project.read
WebsitesSnapshotsReportsKnowledgeActivity

Ecosystem

Marketplace

platform.marketplace.read
ExtensionsPublishersReviewsModerationRevenue

Extensions

platform.extension.read
Installed versionsHealthErrorsUpdates

Connectors

platform.connector.read
ProvidersSync statusHealthLogsCredentials

Knowledge

platform.knowledge.read
ObjectsGraphCollectionsTagsAI references

Content

platform.content.read
BlogsDocsAcademyPoliciesMediaLocalization

Commerce

Credits

platform.credits.read
WalletsTransactionsPackagesConsumptionAdjustments

Billing

platform.billing.read
PlansSubscriptionsInvoicesTaxesRefunds

Platform

Feature flags

platform.flag.read
RolloutTargetingBeta cohortsExperiments

Announcements

platform.announcement.read
NoticesProduct updatesSecurity alertsWorkspace notices

Support

platform.support.read
TicketsFeedbackBug reportsLive chat (future)

Audit centre

platform.audit.read
User actionsPaymentsExtensionsPermissions

Analytics

platform.analytics.read
User retentionWorkspace growthCreditsRevenueAdoption

Developer tools

platform.devtools.read
Registry explorersValidatorsManifest viewerSDK playground (future)

RBAC

Ten roles resolving to granular platform permissions

Roles are additive, checked server-side, and only a super admin may grant them.

super-admin

38 permissions

platform.dashboard.readplatform.user.readplatform.user.manageplatform.user.suspend

platform-admin

36 permissions

platform.dashboard.readplatform.user.readplatform.user.manageplatform.user.suspend

marketplace-admin

6 permissions

platform.dashboard.readplatform.marketplace.readplatform.marketplace.moderateplatform.marketplace.publish

content-admin

7 permissions

platform.dashboard.readplatform.content.readplatform.content.manageplatform.knowledge.read

support-admin

7 permissions

platform.dashboard.readplatform.support.readplatform.support.manageplatform.user.read

billing-admin

6 permissions

platform.dashboard.readplatform.billing.readplatform.billing.manageplatform.credits.read

developer-admin

12 permissions

platform.dashboard.readplatform.devtools.readplatform.extension.readplatform.connector.read

moderator

5 permissions

platform.dashboard.readplatform.marketplace.readplatform.marketplace.moderateplatform.content.read

auditor

21 permissions

platform.dashboard.readplatform.user.readplatform.workspace.readplatform.project.read

read-only

20 permissions

platform.dashboard.readplatform.user.readplatform.workspace.readplatform.project.read
  • Roles are additive; a user's effective permissions are the union of their roles.
  • Permissions are checked server-side on every operation, not only in navigation.
  • Auditor may read everything and export logs, but may mutate nothing.
  • Only super-admin may grant or revoke platform roles.

Search, dock and commands

One query, one context panel, one command system

Unified search fans out across every scope the operator may read; the dock reports context; commands are registered in the kernel palette.

Search scopes

usersworkspacesprojectsextensionsconnectorsknowledgereportscontentcreditspaymentslogs
  • One query fans out to every scope the operator may read; forbidden scopes are never queried.
  • Providers are asynchronous and independent; a slow provider never blocks the ranked list.
  • Results carry their scope so the operator always knows which console they will land in.

Context dock

Current section and entity
The console in view plus the selected user, workspace, project or extension.
Recent activity
The last events for the selected entity, read from the history service.
Quick actions
Permission-filtered commands for the selected entity.
Related resources
Owner, workspace, projects, connectors and extensions linked to the entity.
Health status
Live health of the entity and of the subsystems it depends on.

Global commands

  • Create workspaceplatform.workspace.manage
  • Suspend userdestructiveplatform.user.suspend
  • Publish extensionplatform.marketplace.publish
  • Approve marketplace listingplatform.marketplace.moderate
  • Refresh connectorplatform.connector.manage
  • Run queueplatform.queue.manage
  • Create announcementplatform.announcement.manage
  • Adjust creditsdestructiveplatform.credits.adjust
  • Toggle feature flagplatform.flag.manage

Widgets

Every console is widget-driven

Widgets declare their permission and their refresh interval; the page decides nothing.

Users

metric

platform.user.read

refresh 300s

Credit consumption

chart

platform.credits.read

refresh 300s

Revenue

metric

platform.billing.read

refresh 900s

Marketplace moderation queue

table

platform.marketplace.moderate

refresh 60s

System health

status

platform.health.read

refresh 30s

Queue depth

chart

platform.queue.read

refresh 30s

Recent jobs

table

platform.job.read

refresh 60s

Reports generated

metric

platform.project.read

refresh 600s

Learning adoption

chart

platform.content.read

refresh 900s

Extension errors

list

platform.extension.read

refresh 60s

Connector sync status

status

platform.connector.read

refresh 60s

AI usage (future)

metric

platform.analytics.read

refresh 900s

  • Consoles are composed from widgets registered in the dashboard widget registry.
  • A widget the operator cannot read is never resolved, never fetched and never rendered.
  • Refresh intervals are declared by the widget, not chosen by the page.

Audit centre

Append-only, hash-chained, retained per category

Every platform-mode mutation writes a record before the operation is acknowledged.

Categories and retention

user.action
730 days
permission.change
2555 days
workspace.change
730 days
payment
2555 days
credit.adjustment
2555 days
extension.lifecycle
730 days
connector.credential
2555 days
content.change
365 days
flag.change
365 days
system.operation
365 days
  • Audit records are append-only and hash-chained; an edited row breaks the chain.
  • Every platform-mode mutation writes a record before the operation is acknowledged.
  • Records are exportable by auditors in CSV and JSON for compliance review.
  • Retention is per category and enforced by a scheduled job, never by hand.

Audit record

{
  "id": "aud_01J9K",
  "category": "credit.adjustment",
  "action": "credits.adjust",
  "actor_id": "usr_admin_04",
  "actor_roles": ["billing-admin"],
  "target_type": "workspace",
  "target_id": "wsp_2f18",
  "at": "2026-08-05T02:00:00.000Z",
  "previous_hash": "3f6c…a91b",
  "hash": "9d02…44e7",
  "meta": { "amount": 2500, "reason": "Support goodwill credit" }
}

System health

Declared thresholds, never hard-coded latency

An unreachable probe reports unknown, never healthy. Transitions raise platform events.

healthydegradedfailingunknown

Snapshot worker

worker

every 30s · degraded ≥ 2000ms · failing ≥ 10000ms

Connector worker

worker

every 30s · degraded ≥ 2000ms · failing ≥ 10000ms

Queue worker

worker

every 30s · degraded ≥ 2000ms · failing ≥ 10000ms

Cron worker

worker

every 60s · degraded ≥ 3000ms · failing ≥ 15000ms

Primary database

database

every 15s · degraded ≥ 300ms · failing ≥ 2000ms

Queue backlog

queue

every 30s · degraded ≥ 1000ms · failing ≥ 5000ms

Object storage

storage

every 60s · degraded ≥ 1000ms · failing ≥ 5000ms

Edge API

api

every 15s · degraded ≥ 500ms · failing ≥ 3000ms

Integration

Consumes registries, reuses runtimes, duplicates nothing

The console is composed from what already exists in the kernel.

Registries consumed

Widget registry
Every console surface is composed of registered widgets.
Sidebar registry
Platform navigation is a permission-filtered projection.
Command registry
Global platform commands live beside product commands.
Capability registry
Console features discover extensions by capability.
Content registry
Announcements, docs and policies reuse the content engine.
Report registry
Operational reports use the universal report structure.
Connector registry
Connector console reads provider manifests and health.
Extension registry
Extension console reads owner-attributed artifacts.

Runtimes reused

AppShell
Sidebar, header, palette, prompt bar and overlays are unchanged.
Workspace runtime
Tenancy consoles operate through workspace context.
Project runtime
Project console reads websites, snapshots and reports.
Content engine
Content console edits the same documents users read.
Report engine
Analytics and operational reporting.
Snapshot engine
Project inspection and knowledge graph review.
Universal Website Object
The only website contract the console reads.

AI, performance and compliance

Permission-bound assistance and declared non-functional requirements

Assistants see exactly what the operator sees; performance and compliance rules are part of the contract.

AI assistants (future)

  • Summarize platform health into a daily operator briefing.
  • Recommend actions for degraded workspaces and stale connectors.
  • Detect anomalies in credit consumption and revenue.
  • Prioritize the marketplace moderation queue.
  • Suggest performance and cost optimizations.
  • Generate operational reports from findings.
  • Assistants are permission-bound: they see exactly what the operator may see.
  • AI output is advisory; no assistant executes a destructive command unattended.

Performance and accessibility

  • Lazy-load every console; the platform bundle never ships all twenty at once.
  • Virtualize tables and paginate by cursor — offset pagination is forbidden at platform scale.
  • Load incrementally: skeletons first, data as it lands, no blocking spinners.
  • Memoize derived projections such as navigation and permission sets.
  • Keyboard-first: every console action is reachable without a pointer.
  • ARIA-compliant tables, dialogs and status regions.
  • Reduced motion is respected in every transition.
  • Semantic HTML and screen-reader labels on all status indicators.

Non-functional requirements

Security
RBAC enforced server-side, immutable audit logs, no admin-only components.
Scalability
Registry-driven surfaces, lazy loading and incremental updates.
Compliance
Per-category retention, export capability and immutable storage.
Performance
SLAs on critical operations — user suspension under two seconds — verified by synthetic load tests.
Multi-tenancy
Workspace-level quotas, resource isolation and tenant-specific overrides.