Skip to content
Warplock

Seven workflows. Same words as the help page.

These are the task guides the control plane ships in its own Help area, in the same order. Each names who runs it, what to do, and what you should see afterwards.

01 · All roles

Sign in and choose the Active Client Context

Make sure every action happens inside the intended Client workspace.

Opens
  • /dashboard Dashboard
Do this
  1. 1Sign in with email and password; complete MFA setup or the MFA challenge.
  2. 2Check the Dashboard status chip for the Active Client Context.
  3. 3Change context before creating anything for a different Client.
Expected result
  • Navigation shows only what your role or membership allows.
  • Client-scoped records land under the visible context.
02 · Partner Admin, Client Admin, Client Developer

Configure the runtime surface

Create the SQL Connection, DAB Instance and Exposed Entities that define what an MCP client may see.

Opens
  • /sql-connections SQL connections
  • /dab-instances DAB instances
  • /exposed-entities Exposed entities
Do this
  1. 1Create the SQL Connection; test it and refresh schema metadata.
  2. 2Create the DAB Instance that uses it. DEV, STAGING and PROD environments are created with it.
  3. 3Create Exposed Entities for deliberate tables, views or procedures; cached metadata prefills columns and keys.
  4. 4Add entity and column descriptions so generated MCP Resources make sense to the model.
  5. 5Review SQL Capability status before preparing a Draft Change.
Expected result
  • Only selected entities exist in the runtime surface.
  • Descriptions and capability status are visible before Promotion.
03 · Partner Admin, Client Admin, Client Developer (authoring), Client Admin (promotion)

Preview, approve and promote a Draft Change

Move deliberate configuration into an environment through preview, validation, approval and Promotion.

Opens
  • /draft-changes Draft changes
  • /deployment-map Deployment map
  • /operational-events Operational events
Do this
  1. 1Create a Draft Change for the DAB Instance.
  2. 2Preview the generated DAB config and redacted runtime plan.
  3. 3Resolve failed SQL Capability validation.
  4. 4Record or wait for approvals where Policy Governance requires them.
  5. 5Promote to DEV, STAGING or PROD.
Expected result
  • An immutable Effective Config Version exists for the environment.
  • A Deployment Job is queued; runtime effect is visible once it applies.
04 · Partner Admin, Partner Operator, Partner Viewer

Configure runtime host execution

Separate where a runtime is placed from the credential that lets the worker act there.

Opens
  • /docker-hosts Runtime hosts
  • /dab-instances DAB instances
  • /mcp-gateways MCP gateways
Do this
  1. 1Register the host; confirm role eligibility, address and readiness notes.
  2. 2Expose it only to the Clients and environments that may place runtimes there.
  3. 3Choose Apply or Plan-only for the host.
  4. 4As Partner Admin, set the remote workspace root and add the Host Execution Credential.
  5. 5As Partner Operator, assign exposed hosts to DAB Instance environments or MCP Gateways.
Expected result
  • Placement records show where runtimes belong.
  • Lifecycle jobs apply only when worker, host and credential all agree; otherwise Plan-only evidence is recorded.
05 · All roles; changes by Partner Admin, Client Admin, Client Developer

Operate MCP Gateways, tokens and runtimes

Connect MCP clients through scoped tokens without exposing secrets beyond the intended boundary.

Opens
  • /mcp-gateways MCP gateways
  • /mcp-tokens MCP tokens
  • /registered-runtimes Registered runtimes
  • /client-setup Client setup
Do this
  1. 1Create or inspect the MCP Gateway for the Client, instance or environment.
  2. 2Issue an MCP Access Token scoped to one instance environment; narrow it to named tools if needed.
  3. 3Use Client Setup to copy endpoint details, snippets, an M365 App Package or a DCR onboarding URL.
  4. 4Register off-host runtimes only when they run outside the central control plane.
  5. 5Rotate or revoke when access changes.
Expected result
  • MCP clients call the Gateway route with a scoped token.
  • Restricted tokens see only their allowed tools and resources.
  • Runtime state and Gateway health are visible in the Web UI.
06 · All roles; payload viewing by permission

Understand Query Audit, retention and notifications

Inspect traffic, retained payloads and events without treating audit data as configuration.

Opens
  • /query-audits Query audits
  • /client-audit-settings Client audit settings
  • /audit-delivery-settings Audit delivery
  • /notifications Notifications
Do this
  1. 1Open Query Audits for recent traffic metadata.
  2. 2View or export retained payloads only when policy and your Payload Viewer permission allow it.
  3. 3Adjust Client audit settings when retention or Partner Payload Access must change.
  4. 4Use Audit Delivery and Notifications to understand delivery behaviour around events.
Expected result
  • Metadata is available per retention policy.
  • Payload content is metadata-only, redacted, retained or unavailable, as policy says.
  • Notifications reflect significant control-plane and runtime activity.
07 · All roles

Troubleshoot from visible state

Narrow a fault to access, configuration, Promotion, Gateway routing, runtime health or infrastructure before escalating.

Opens
  • /deployment-map Deployment map
  • /dab-instances DAB instances
  • /operational-events Operational events
Do this
  1. 1Check Active Client Context and role before assuming a route is broken.
  2. 2Use Deployment Map and DAB Instance detail for runtime state, health probes and Gateway URL.
  3. 3Use Draft Changes to see whether a config is pending rather than promoted.
  4. 4Use Operational Events to find failures, retries and credential rotations.
  5. 5Escalate to the sovereign cloud team only when DNS, TLS, firewall, hosts or backups are implicated.
Expected result
  • The Web UI narrows the fault to one layer.
  • Client-visible troubleshooting never needs operator secrets or runbook commands.

Who can do which of these?

Six roles, one matrix.

Roles and permissions

Run the first one with us.

A Client workspace, one SQL Connection, one Draft Change to PROD.

Talk to a partner in your area