Skip to content
Warplock

Where exposure is decided.

The control plane is the signed-in Warplock application. Your integration partner and your own admins, developers and viewers use it to decide which entities exist, promote configuration through DEV, STAGING and PROD, issue and revoke access, and read what happened. It runs in Warplock's sovereign cloud and never touches your database directly; the runtimes it configures do.

What it is made of
  • Web UI for integration partner and Client workflows
  • Worker for deployment, lifecycle, audit and notification jobs
  • Postgres as the source of truth for every record
  • Redis for job delivery, audit buffering, live events and rate limits

The MCP Gateway and DAB runtimes are configured from here but run as separate services on the pipeline.

The change spine.

Runtime-affecting configuration only ever moves one way. Every step leaves a record; none can be skipped; nothing is hard-deleted.

01

Draft Change

A change-set that has not touched any environment. Entities, columns, policies, deployment settings.

02

Preview

The generated DAB config and a redacted runtime plan, rendered before anything runs.

03

Validate

SQL Capability checks against the SQL Connection; contradictory deployment settings rejected.

04

Approve

Where Policy Governance requires it, a Client-held approval is recorded before Promotion.

05

Promote

Into DEV, STAGING or PROD. Blocked if the environment moved underneath the preview.

06

Effective Config Version

An immutable, checksummed snapshot that is now the environment's truth.

07

Deployment Job

The worker renders, validates and applies it, or records a Plan-only result if the host is frozen.

Rollback

A rollback is a new Draft Change created from an older Effective Config Version. It goes through the same preview, validation and Promotion, so a rollback is never a shortcut around the gates.

Outside the spine

Display names, descriptions, token restrictions and rate-limit policies are audited direct edits with a required reason. They never change what DAB executes.

Operational truth, close to the action.

Every list shows the IDs, environment scope, version, health timestamp and Gateway route an operator needs before changing anything. Dense tables, not dashboards. Non-colour status labels throughout.

DAB Instance Orders service dab_4f2a…
Illustrative · synthetic data
EnvironmentEffective Config VersionRuntimeGateway routeHealth
DEVecv_8c1f…Running/mcp/gw_3k9d…Healthy · 12s ago
STAGINGecv_8c1f…Running/mcp/gw_3k9d…Healthy · 9s ago
PRODecv_51a0…Running/mcp/gw_p7x2…Healthy · 14s ago

Row actions: start, stop, restart, create rollback draft, edit TFN redaction, edit payload policy. Each requires an audit reason and writes an Operational Event.

Every area of the Web UI.

Navigation only shows what your role or Client Membership allows. These are the areas, what they hold, and who sees them.

Workspace

Dashboard

/dashboard

Active Client Context, role, and what needs attention.

Everyone

Clients

/clients

Client workspaces, memberships, display names, audit settings, archive.

Integration partner

Help

/help

Task-oriented guidance generated from the same source as the documentation.

Everyone

Release notes

/release-notes

What changed in the App Release you are using.

Everyone

Runtime surface

SQL connections

/sql-connections

Encrypted targets, test, schema refresh, payload policy, archive.

Integration partner, Client Admin, Client Developer

DAB instances

/dab-instances

Instances, DEV/STAGING/PROD detail, start/stop/restart, rollback drafts, TFN redaction.

Integration partner, Client Admin, Client Developer

Exposed entities

/exposed-entities

Tables, views, procedures; columns, descriptions, redaction, write governance, templates.

Integration partner, Client Admin, Client Developer

Change

Draft changes

/draft-changes

Author, preview, validate, approve and promote.

Integration partner, Client Admin, Client Developer

Deployment map

/deployment-map

What is deployed where: versions, runtime state, health, Gateway URLs.

Everyone

Policy governance

/policy-governance

Inventory of Client-held approval authority; expire, deactivate, reset.

Partner Admin

Access

MCP gateways

/mcp-gateways

Scoped Gateways, route snapshots, defaults, public ingress, source allowlists, service lifecycle.

Integration partner, Client Admin, Client Developer

MCP tokens

/mcp-tokens

Issue, restrict, rotate, revoke. Secrets shown once.

Integration partner, Client Admin, Client Developer

Registered runtimes

/registered-runtimes

Off-host DAB or Gateway runtimes: enrollment, bundles, heartbeat, lifecycle requests.

Integration partner, Client Admin, Client Developer

Client setup

/client-setup

Endpoint URLs, client config snippets, M365 App Packages, OAuth clients, DCR onboarding URLs.

Everyone

Gateway rate limits

/gateway-rate-limits

Policy overrides per Client, instance, environment, token or entity.

Partner Admin

Audit

Query audits

/query-audits

Traffic metadata, guarded payload view and export, bulk export jobs.

Everyone, payload by permission

Client audit settings

/client-audit-settings

Payload policy, retention days, Zero Data Retention, Partner Payload Access.

Partner Admin, Client Admin

Audit delivery

/audit-delivery-settings

Fail-open or fail-closed when audit cannot be delivered, per environment.

Partner Admin

Operational events

/operational-events

Durable record of every significant action, streamed live.

Everyone

Notifications

/notifications

Email and signed-webhook endpoints with event and environment filters.

Integration partner, Client Admin

Operations

Runtime hosts

/docker-hosts

Inventory of hosts for containerized DAB and Gateway workloads: role eligibility, Client exposure, lifecycle mode, execution credentials.

Integration partner

Nothing is hard-deleted.

Lifecycle Controls keep history, audit and dependencies intact. Three kinds of change, each with its own gate.

  1. Direct edit

    Display names and labels. Requires write permission and a reason; writes an Operational Event.

  2. Draft Change

    Anything DAB executes: entities, columns, policies, deployment settings, SQL Connection swaps.

  3. Archive · revoke · disable

    The destructive controls. Blocked while dependencies remain: running environments, active tokens, open drafts, placements.

Archived SQL Connections keep their non-secret history and lose their encrypted credential. Archived Clients keep every record for audit. A Blank-Slate Reset returns an environment to a new-Client baseline only after explicit operator approval.

See it with your own entities.

Your partner will set up a Client workspace and walk one Draft Change from preview to PROD with you.

Talk to a partner in your area