Every feature, in the product's own words.
Grouped the way the control plane groups them. Each name below is the name you will meet in the UI, the documentation and the audit trail.
Runtime surface
Decide what exists. Only entities an operator deliberately exposes become MCP tools.
SQL Connections
Client-owned targets with credentials stored as AES-256-GCM envelopes under a per-Client data key. Lists show metadata, never secrets.
DAB Instances
One runtime identity per SQL Connection, each owning DEV, STAGING and PROD Deployment Environments.
Exposed Entities
Tables, views and stored procedures made available on purpose, with stable client-facing names and plain-text descriptions.
Column Exposure
Choose the columns each entity returns; describe them for the model.
Column Redaction
Mask or transform selected column values before they leave the Gateway and before payloads are retained.
TFN Redaction
Pattern rule that replaces Australian Tax File Numbers in any output, per instance or per entity.
Row Filter Presets
Staged DAB database policies that narrow reads after promotion.
Procedure Contracts
Declared inputs, outputs and side-effect classification for procedure-backed entities.
SQL Capability checks
Expected database permissions validated before a change can be promoted.
Schema Drift
Detected differences between the SQL object and the entity built on it, advisory until a staged change is promoted.
Schema analysis
Schema refresh captures primary keys and unique indexes; an optional mcp.ViewCatalog view supplies descriptions, grain notes and key hints to prefill model-friendly metadata.
Exposed Entity Templates
Non-secret export and import of entity configuration between runtimes, with explicit binding on import.
Change control
No runtime-affecting DAB configuration reaches an environment without preview, validation, approval and an immutable version.
Draft Changes
Every runtime-affecting configuration change is a change-set that has not yet touched an environment. Descriptions, token restrictions and rate-limit policies are audited edits outside this flow.
Preview
Generated DAB config and a redacted runtime plan, before anything runs.
Policy Governance
Client-owned approval authority over sensitive policy, with Partner emergency paths recorded separately.
Promotion
Move a Draft Change into DEV, STAGING or PROD. Optimistic: blocked if the environment moved underneath you.
Effective Config Versions
Immutable, checksummed snapshots per environment. Rollback is a new Draft Change from an old snapshot, through the same gates.
Deployment Jobs
Queued worker work that renders, validates and applies the promoted version.
Advanced overrides
Guarded JSON for DAB runtime settings, with secret values held as encrypted references, never raw.
Gateway and access
Who may call, from where, how often, and which tools they can see.
MCP Gateways
Managed ingress scoped to a Client, a DAB Instance or a single environment, each with an opaque /mcp/:id route.
MCP Access Tokens
Bearer credentials stored as one-way hashes. Shown once. Scoped to one instance in one environment with a default 720-hour expiry.
Restrict, rotate, revoke
Narrow a token to named tools, rotate with an overlap window, or revoke immediately. Every action needs an audit reason.
Discovery filtering
tools/list, resources/list and resources/read are filtered to the token's scope before they leave the Gateway.
Gateway-owned MCP Resources
List, search and read helpers that let Copilot-style clients discover entities as resource links.
Source Allowlist Policy
Per-Gateway inbound network policy, enforced in-process and exported for the firewall.
Rate limits
Postgres-backed policy, Redis-backed counters, at Client, instance, environment, token and entity scope.
Registered Runtimes
DAB or Gateway runtimes run outside the control plane, enrolled with revocable tokens and reporting heartbeats.
Public ingress metadata
Hostname, upstream and route snapshot for each Gateway, feeding the load balancer and WAF configuration.
Microsoft 365 and Copilot
Hand a Gateway route to a Microsoft 365 tenant without embedding a secret in the package.
M365 App Package
Unified manifest 1.29 with one agent connector entry pointing at the Gateway route. Never contains a stored token secret.
OAuth clients
Client-scoped OAuth with PKCE and rotating refresh tokens. A replayed refresh token revokes the whole family.
Dynamic Client Registration
RFC 7591 onboarding for Copilot Studio from a token-scoped URL, public or confidential clients.
Copilot Studio compatibility
Well-known schema endpoint and rewritten initialize and tools/list responses, including event-stream transports.
Service-tag allowlists
Render Microsoft service tags into firewall-ready CIDRs for the WAF.
Query Audit and retention
Every authenticated call is a record. What the record contains is a policy you set, down to a single entity.
Query Audit
Metadata for every authenticated MCP call, including policy rejections: route, token, tool, status, timing, source. Requests with a missing, expired or revoked token are refused before a record is written. Payload only when policy says so.
Payload Policy
Metadata-only or retained, with separate retention days, cascaded from Client to environment, instance, connection and entity.
Zero Data Retention
Query and response content is not stored after the request is handled. Operational metadata still is.
Payload Viewer
A permission, not a role. Retained content is visible only to users who hold it, and every view is an event.
Partner Payload Access
A Client setting that decides whether your integration partner can see retained content at all.
Audit Delivery Policy
Decide whether traffic continues when audit cannot be delivered, per Gateway and per environment.
Export
Scoped CSV of metadata, individual payload export, and bulk export as worker jobs with IDs-only event metadata.
Retention cleanup
Worker jobs expire payload and metadata rows on schedule, with manual run-now for Partner Admins.
Operations
Placement and execution authority are separate. The worker applies only where both agree.
Runtime host inventory
Partner-managed hosts for containerized DAB and Gateway workloads, with role eligibility, readiness and per-Client exposure. Registering a host grants nothing by itself.
Host Execution Credentials
Encrypted SSH authority, separate from placement, never shown back in plaintext.
Plan-only or Apply
Lifecycle jobs downgrade to Plan-only when the worker is frozen, the host says so, or no credential is active.
Worker jobs
Retries with exponential backoff, per-runtime lock keys, stale lock recovery.
Runtime lifecycle
Audited start, stop and restart for DAB runtimes and Gateway services from the control plane.
Operational Events
Durable records of everything significant, streamed live to the UI.
Notification Endpoints
Email or HMAC-signed webhooks per Client, with retry and final failure state.
Outbound Target Policies
Two policies. Webhook callbacks may only reach the public internet, never private, loopback or metadata addresses. Infrastructure probes may reach private DAB and SQL hosts but still refuse loopback, link-local and reserved targets.
Lifecycle Controls
Archive, deactivate and reset actions that preserve history and require a reason.
Blank-Slate Reset
Operator-approved return to a new-Client baseline that keeps hosts, partner access and proxy anchors.
Identity and roles
Built-in accounts with the boring, verifiable defaults.
Argon2id passwords
With throttled login and MFA attempts by account hash over a rolling window.
TOTP MFA
Required for integration partner users before any workspace action; replayed counters rejected.
Session versioning
Role, membership, password, MFA and payload-permission changes invalidate older sessions on next read.
Partner roles
Partner Admin, Partner Operator, Partner Viewer: platform control, infrastructure operation, or read-only inspection.
Client roles
Client Admin manages the Client's users, runtime configuration, tokens and promotions. Client Developer authors configuration and tokens but cannot manage users or promote. Client Viewer inspects without changing.
Active Client Context
Every scoped action happens inside one visible Client workspace.
Missing a pane you need?
Tell your partner what your assistants need to read and what they must never see.