Seven workflows. Same words as the help page.
These are the task guides the control plane ships in its own Help area, in the same order. Each names who runs it, what to do, and what you should see afterwards.
Sign in and choose the Active Client Context
Make sure every action happens inside the intended Client workspace.
- /dashboard Dashboard
- 1Sign in with email and password; complete MFA setup or the MFA challenge.
- 2Check the Dashboard status chip for the Active Client Context.
- 3Change context before creating anything for a different Client.
- Navigation shows only what your role or membership allows.
- Client-scoped records land under the visible context.
Configure the runtime surface
Create the SQL Connection, DAB Instance and Exposed Entities that define what an MCP client may see.
- /sql-connections SQL connections
- /dab-instances DAB instances
- /exposed-entities Exposed entities
- 1Create the SQL Connection; test it and refresh schema metadata.
- 2Create the DAB Instance that uses it. DEV, STAGING and PROD environments are created with it.
- 3Create Exposed Entities for deliberate tables, views or procedures; cached metadata prefills columns and keys.
- 4Add entity and column descriptions so generated MCP Resources make sense to the model.
- 5Review SQL Capability status before preparing a Draft Change.
- Only selected entities exist in the runtime surface.
- Descriptions and capability status are visible before Promotion.
Preview, approve and promote a Draft Change
Move deliberate configuration into an environment through preview, validation, approval and Promotion.
- /draft-changes Draft changes
- /deployment-map Deployment map
- /operational-events Operational events
- 1Create a Draft Change for the DAB Instance.
- 2Preview the generated DAB config and redacted runtime plan.
- 3Resolve failed SQL Capability validation.
- 4Record or wait for approvals where Policy Governance requires them.
- 5Promote to DEV, STAGING or PROD.
- An immutable Effective Config Version exists for the environment.
- A Deployment Job is queued; runtime effect is visible once it applies.
Configure runtime host execution
Separate where a runtime is placed from the credential that lets the worker act there.
- /docker-hosts Runtime hosts
- /dab-instances DAB instances
- /mcp-gateways MCP gateways
- 1Register the host; confirm role eligibility, address and readiness notes.
- 2Expose it only to the Clients and environments that may place runtimes there.
- 3Choose Apply or Plan-only for the host.
- 4As Partner Admin, set the remote workspace root and add the Host Execution Credential.
- 5As Partner Operator, assign exposed hosts to DAB Instance environments or MCP Gateways.
- Placement records show where runtimes belong.
- Lifecycle jobs apply only when worker, host and credential all agree; otherwise Plan-only evidence is recorded.
Operate MCP Gateways, tokens and runtimes
Connect MCP clients through scoped tokens without exposing secrets beyond the intended boundary.
- /mcp-gateways MCP gateways
- /mcp-tokens MCP tokens
- /registered-runtimes Registered runtimes
- /client-setup Client setup
- 1Create or inspect the MCP Gateway for the Client, instance or environment.
- 2Issue an MCP Access Token scoped to one instance environment; narrow it to named tools if needed.
- 3Use Client Setup to copy endpoint details, snippets, an M365 App Package or a DCR onboarding URL.
- 4Register off-host runtimes only when they run outside the central control plane.
- 5Rotate or revoke when access changes.
- MCP clients call the Gateway route with a scoped token.
- Restricted tokens see only their allowed tools and resources.
- Runtime state and Gateway health are visible in the Web UI.
Understand Query Audit, retention and notifications
Inspect traffic, retained payloads and events without treating audit data as configuration.
- /query-audits Query audits
- /client-audit-settings Client audit settings
- /audit-delivery-settings Audit delivery
- /notifications Notifications
- 1Open Query Audits for recent traffic metadata.
- 2View or export retained payloads only when policy and your Payload Viewer permission allow it.
- 3Adjust Client audit settings when retention or Partner Payload Access must change.
- 4Use Audit Delivery and Notifications to understand delivery behaviour around events.
- Metadata is available per retention policy.
- Payload content is metadata-only, redacted, retained or unavailable, as policy says.
- Notifications reflect significant control-plane and runtime activity.
Troubleshoot from visible state
Narrow a fault to access, configuration, Promotion, Gateway routing, runtime health or infrastructure before escalating.
- /deployment-map Deployment map
- /dab-instances DAB instances
- /operational-events Operational events
- 1Check Active Client Context and role before assuming a route is broken.
- 2Use Deployment Map and DAB Instance detail for runtime state, health probes and Gateway URL.
- 3Use Draft Changes to see whether a config is pending rather than promoted.
- 4Use Operational Events to find failures, retries and credential rotations.
- 5Escalate to the sovereign cloud team only when DNS, TLS, firewall, hosts or backups are implicated.
- The Web UI narrows the fault to one layer.
- Client-visible troubleshooting never needs operator secrets or runbook commands.
Run the first one with us.
A Client workspace, one SQL Connection, one Draft Change to PROD.