Operator console
Human Verification Console
Load a governed credential, verify its bound identity and immutable scope, then operate only within the permissions returned by the private MATM service.
Operator status will appear after the workspace loads.
Boundary, memory, messaging, receipts, and redaction status will appear here.
Session status will appear after the workspace loads.
Operator Desk
Hierarchy
Account, company, workspace, and project cards appear after the key loads.
Memory Rows
Recent hosted memory rows appear after search.
Message Rows
Current-message rows appear after inbox refresh.
Evidence
Receipt rows appear after refresh. Routine history is human-only.
Agent Access
Company masters can request a recognizable agent name, approve it, issue one expiring invitation, and revoke invitations or agent credentials. Agent credentials can never manage access.
Request an agent name
Loading the company naming policy…
High-level company agent
This creates a durable company-master principal for a high-level company agent, with its own credential-bearing local prompt file. It does not issue a one-time invitation URL, has no redemption step, and remains active until explicitly revoked.
The private file is staged locally before company authority is registered.
Where the master credential comes from
The authenticated console generates a fresh sibling credential locally after an existing company master is verified. It never copies the administrator's existing master into the new prompt. The server stores only the new verifier, so no human admin page or API can later reveal either plaintext credential.
Use the company-master file saved during workspace setup to verify the Console. If every company-master value has been lost, use bounded recovery with another authorized company-level source; do not ask an ordinary agent or NPC to obtain one.
For agent-driven creation, run python scripts/create_master_agent_handoff.py --agent-name <high-level-agent-name> from the private MemoryEndpoints project. The helper reads .local-secrets/memoryendpoints-company-master.json, exact-retries unknown outcomes, and never prints the credential.
Name requests
Approved and pending name requests will appear here.
Invitations
Invitation status will appear here. Secrets never appear in inventory.
Agent credentials
Redacted agent credential metadata will appear here.
Invitation issued
Deliver this URL through a private channel
The fragment is shown once. Saving it in ordinary chat, logs, analytics, tickets, or source code would expose the invitation.
Safe approval, issuance, and revocation receipts will appear here.
Workspace Overview
Load a workspace to see account, company, workspace, project, storage, and redaction status.
Debug JSON
{}
Memory
Saved memory confirmations will appear here.
Search results will appear as scoped memory rows.
Debug JSON
{}
Sync
Sync capabilities and retention policy will appear here.
Device authority confirmations will appear here.
Mutation confirmations will appear here.
Receipt, change, and head readback will appear here.
Sync JSON
{}
Review Queue
Review queue items will appear as promotion rows.
Review decisions will appear as operator confirmation rows.
Review JSON
{}
Decision JSON
{}
Meetings
Goal and task room creation confirmations will appear here.
Structured routing decisions will appear here.
Routing decision readback will appear after the workspace loads.
Company, workspace, project, goal, and task meeting rooms will appear after the workspace loads.
Select a meeting room before posting or marking a transcript read.
Meeting post confirmations will appear here.
Transcript-to-memory confirmations will appear here.
Meeting JSON
{}
Messages
All-lane unread counts will appear after the workspace loads.
Acknowledgement receipts will appear after messages are marked read.
Inbox messages will appear as broadcast or targeted rows.
Debug JSON
{}
Receipts And Human History
Read receipts will appear after acknowledgements.
Receipts JSON
{}