Tenants
Every customer is an isolated tenant. Lifecycle governs access — suspending a tenant immediately cuts off its modules.
host tessila-01 · env dev
All tenants
REQ-111 · lifecycle| Tenant | Plan | State | Modules | Lifecycle |
|---|
Module & feature entitlement
REQ-110 · click a chip to toggle| Tenant | Core modules | Features | State |
|---|
Devices
§6 Connect · a device is provisioned here, and nowhere elseCredential for this device — shown once
Copy this into the device now. The platform stores only a hash of it, so nobody
— including a platform administrator — can read it back. Closing this box is
the last time it exists.
Describe what this device measures
1 · Measurements
2 · Alarms
When will this cross its limit?
close
| Device | Profile | Last seen | State | Credential |
|---|
Awaiting a human
AII-011 · nothing here has happened
A forecast that books an engineer is a model spending somebody’s money. Everything
the platform predicts arrives here instead, doing nothing, until a named person
accepts or declines it — and the platform refuses to record a decision with
nobody attached to it. Accepting does not schedule the work; it records that
a person agreed the window is right, which is what a maintenance system is then
handed.
| Recommendation | Confidence | Source | Raised | Decision |
|---|
Rules
§7 Flow · a rule is data, not code| Rule | Watches | Condition | Severity | State |
|---|
Open alarms
§8 Pulse · state, not events
Read-only here, deliberately. Acknowledging an alarm records who took
responsibility for it, so it belongs to the operator on duty in that city's own
console — not to a platform administrator looking in from outside. Nothing on this
screen clears an alarm either: an alarm ends when its condition ends.
| Alarm | Device | Severity | Open for | Owner |
|---|
Providers, in the order they are tried
ADR-007 §2 · failover on refusal, never on silence| Order | Provider | Gateway | Credential |
|---|
Tenants pinned to a carrier
ADR-007 §2.2 · one provider to the front, not a reordering
A pin moves one provider to the front for that tenant. Everything after it keeps
the order above, so a pinned carrier having a bad night still leaves somewhere to go.
Use it where a customer’s traffic must go via a particular carrier — a local
A2P rule, a regulator, a contract — and not as a preference.
| Tenant | First provider |
|---|
Notification groups
ADR-006 §1.3 · a roster, not a field on thirty rules| Group | Reaches | Routing | Limits |
|---|
AI token usage
AII-013 · input vs output
Input · prompt
Output · completion
| Feature | Input | Output | Total | Calls |
|---|
Video storage charge
ADR-002 §4 · per camera / month
The terms in force for each tenant, and what a month costs at the cameras they actually run — not the
cameras their plan allows. Indicative: the invoice is computed from metered usage, and repricing appends a
new record rather than editing this one, so an invoice raised last month can still be explained.
| Tenant | Per camera / month | Retention included | Extra day | In force since | Indicative / month |
|---|
Usage against plan quota
REQ-112 · AII-013| Tenant | Plan | Devices | Messages | AI tokens | Cameras |
|---|
Model availability
AII-012 · sovereign deliveryPer-tenant Intelligence posture
AII-011 · 013
Entitlement decides who may use the copilot; the proposal queue is where its output waits for a named
human. Both are shown here because “the AI proposed something and nobody looked” is the failure
this platform is meant to make visible.
| Tenant | Intelligence | Predictive | AI tokens used | Proposals awaiting a human |
|---|
Accounts
REQ-115 · 116Password — shown once
Give this to them now. The platform stores only a hash of it, so nobody — including
you — can read it back, and they should change it after signing in. If it is lost the
account needs a new one.
A lockout backs off geometrically — five wrong attempts, then a minute, doubling with each
further miss. The attempts left under each name are what one more guess costs before that
starts. Unlocking clears the counter with the lock, because leaving it set means the next single
mistake re-locks instantly and the unlock looks like it failed.
Disabling revokes every session that account currently holds; it does not change the
password, so enabling it again lets the same person straight back in.
| User | Scope | Roles | State | Last sign-in | Actions |
|---|
Recent sign-in events
why a login failed
bad-password means the password was genuinely wrong.
locked means it never got that far — and the person trying could not
tell the difference from the error they saw.
| When | User | Event | Reason | From |
|---|