Manage → Browse
The main workspace for inventorying resources. The page is a two-pane layout: a hierarchical tree on the left lists the locations and resources you can access; the right pane shows the detail of whichever item you select.
Tabs and actions follow your permissions at the selected location. A parent location may be visible so you can reach an allowed branch without giving you permission to change the parent. When an administrator changes your access, reload the page to see the updated controls.
What you can do
- Browse the location tree and expand branches to find resources.
- Filter the tree by scope (everything, locations only, or resources only), verification outcome, health status, resource type, and tags.
- Search the tree by name.
- Create, edit, move, and delete locations and resources.
- Import resources in bulk from a CSV file.
- Open an interactive session on a resource with one click.
- Onboard new resources through a guided modal.
- Reach the workspace catalogs (Credentials, Tags, Metrics, Snaps, Facts, Commands) through the Configuration entry at the bottom of the tree.
The tree
Each tree node shows:
- An icon indicating the kind (folder for locations, type-specific icon for resources).
- The name, optionally followed by a secondary label (for example, an IP address).
- A location pin icon when a location has map coordinates configured.
- A resource count badge on locations that contain resources.
- Verification icons showing the checks supported by the resource type: reachability, signature, authentication, and identity. Hover over an icon for its meaning.
- A health icon for types that support health collection, whose tooltip shows the resource’s health, such as Health: Ok.
- A Connect button (terminal icon) on resources that support interactive sessions.
- A ⋮ (menu) button with contextual actions.
Click the row body to select the node; its detail opens in the right pane. Click the > chevron on a location to expand or collapse it.
Graphical-only types show reachability only. Generic SSH also shows signature and authentication. Database and Kubernetes checks do not currently report signature verification. Unsupported stages are hidden and do not match verification filters; supported checks that have not run or whose verification setting is disabled remain visible.
When you narrow the tree pane, the status icons hide together to leave more room for resource names. The same verification outcomes remain available on the resource’s Summary tab.
Below the tree, after a separator, a Configuration entry opens the workspace catalogs — Service account credentials, Tags, Metrics, Snaps, Facts, and Commands — in the right pane. It appears if you hold at least one of the corresponding permissions.
Filtering and searching
Above the tree, a toolbar offers:
| Control | What it does |
|---|---|
| Search | Type to filter by name or secondary label. |
| Scope filter | Show Everything, Locations Only, or Resources Only. Locations Only preserves the location hierarchy and hides resources, separators, and labels. |
| Verification filter | Show resources with a particular outcome, such as Unreachable, Invalid signature, Authentication failed, or Identity mismatch. Neutral outcomes such as Signature not configured are also available. |
| Health filter | Show only resources in a given health state (Critical, Degraded, Healthy…). |
| Type filter | Show only a specific resource type (Linux, Cisco IOS, AWS Account…). |
| Tags filter | Show only resources carrying all of the selected tags (visible with app.resources.read). |
Active verification, health, type, and tag filters appear as removable chips below the toolbar, together with a count of matching resources and a Clear filters shortcut. Verification outcomes have the same meaning as the stages on the Summary tab. A reachable resource can still have a signature, authentication, or identity problem.
Common tasks
Create a location
- On any location in the tree (including a top-level one), click the ⋮ menu and pick Add Child Location.
- Fill the form (name, description, map coordinates) and click Save.
Create a resource
- Pick a location in the tree and choose ⋮ → Add Resource. The Resource Path sets the location and name; leave the name blank to use the discovered name.
- Choose the connection method. Keep Resource type on Detect automatically, or select the expected type. Enter the destination and select or create a compatible credential. Advanced settings contains additional connection options, Automatic collection, and Allow personal SSH keys for native SSH automation for supported shell resources.
- Click Verify. Review the reachability, signature, authentication, type, and identity results beside the form. Only checks supported by the connection method appear.
- Resolve failed checks and verify again. Review an observed SSH signature against a trusted source before proceeding.
- Click Create resource within the displayed 60-second verification window. If it expires, or you change the connection settings or location, verify again. Renaming does not reset the window.
- Choose Open resource or Done after creation.
For SSH, automatic detection identifies supported systems, including Palo Alto Panorama as a separate type from a Palo Alto firewall. If the connection succeeds but no specific type can be identified, the fallback is Generic SSH. A failed connection or authentication does not qualify for this fallback.
Selecting a specific type requires it to match; a mismatch fails onboarding instead of silently choosing another type. Select Generic SSH explicitly when you only need a generic SSH resource. SSH automatic detection runs during onboarding; later checks, sessions, and snapshots use the saved type.
On a first SSH check, Signature configuration required means there is no saved host key yet. Review the observed fingerprint against a trusted source before creating the resource. Identity detected establishes the initial identity; later checks compare against this stored value.
When your license’s resource capacity is reached, Add Resource stays visible but is disabled with a lock icon whose tooltip explains why.
Bulk-import resources from CSV
- Click the ⋮ menu on a top-level location and pick CSV Import.
- Choose Resources as the import type. Use Download Template and Field Reference to get the format, installed type identifiers, connection fields, and available location and credential names.
- Upload the completed file (up to 5 MiB and 1,000 data rows). Use UTF-8 encoding. Review validation errors; Errors only and Download Errors help you correct the file. You can continue with valid rows while invalid rows are skipped.
- Run the resource checks and review the results. Only successfully checked rows can be selected for import. Retry failed checks after correcting their cause, or import the successful rows separately.
- Review the import report to see which resources were created and which rows still need attention.
| Resource column | Value |
|---|---|
name | Resource name. |
engine_id | Connection method identifier from Field Reference, such as ssh. |
expected_type_id | Optional installed resource type identifier. Blank enables automatic detection; a supplied type must match. For Panorama over SSH, use panorama_ssh. |
connector_data | A JSON object containing the connection settings required by the selected method. Follow the template’s CSV quoting for JSON values. |
location | An existing location name or path from Field Reference. |
credential | An existing compatible credential name from Field Reference. |
sshgw_allow_personal_key | Optional; true or false (default false). Turns on Allow personal SSH keys for native SSH automation for the created resource. Only available for resource types with a shell session mode; a row set to true whose detected type has none is reported at the check step and is not imported. |
resource_type is accepted as an alias for expected_type_id; if both are filled, they must agree. The same SSH detection, Generic SSH fallback, and saved host-key behavior apply to manual and CSV onboarding.
Validation and import use the locations where your app.resources.write permission applies. A location outside that scope is reported as unavailable, just like a location that does not exist.
Organize a branch
- Add separator / label: ⋮ menu on a location → Add separator / label inserts a visual divider or free-text label among its children.
- Sort A–Z: ⋮ menu on a location → Sort A–Z alphabetizes its children.
Edit, move, or delete a node
- Edit: ⋮ menu → Edit opens the form for that location or resource.
- Move: ⋮ menu → Move lets you reassign the node under a different location.
- Delete: ⋮ menu → Delete asks for confirmation. Deletion is permanent.
Re-check or change a resource’s connection settings
- Open the resource’s ⋮ → Edit and adjust its settings or credential. Resource Path controls its location and name; Advanced settings contains additional connection and collection options.
- Click Verify. Results appear beside the form. Stop verification cancels an unwanted check.
- Review any failure. For an intentional SSH host-key change, compare the saved and observed signatures with a trusted source before selecting Accept new signature. For an intentional resource replacement or missing identity, review the observed identifier before selecting Accept new identity.
- Click Save changes within the displayed 60-second verification window. Saving uses the reviewed result without contacting the resource again.
Saving requires a successful verification or explicit acceptance of an offered signature or identity change. Other failures still need to be resolved. Changing connection settings, credentials, or location invalidates the result and clears pending acceptance choices; verify again. Renaming does not reset the window.
Accepting an SSH key saves the observed fingerprint but does not establish that unperformed checks passed. Verify again after saving to check the resource against that key. Accepting a new identity changes the stored comparison value; ordinary checks and snapshots do not replace it automatically.
See Verification status for the meaning of failures and unchecked stages, and SSH host key verification for restoring strict verification.
Connect to a resource
Click the terminal icon on a resource row. Choose the connection options if prompted; the interactive session opens in its own pin. See Resource → SSH / Console.
The button reflects live session state — green when a session on that resource is already established, blue while one is connecting, and neutral otherwise.
License banners
A dismissible banner appears at the top of the page in two situations:
- Resource capacity reached or exceeded: “Resources capacity reached (used used of licensed licensed)” — the word becomes exceeded once you are over the limit. No new resources can be added until you are back under the limit; existing ones keep working, and deleting is never blocked.
- A license is expiring or has expired: the banner names how urgent it is.
See Settings → System → Licensing to install or renew license keys.
Permissions
- Read:
app.resources.read. - Create / edit / move / delete locations:
app.resources.write. - Create / edit / move / delete resources:
app.resources.write. - Re-check a resource from its edit form:
app.resources.execute. - Open interactive sessions:
app.resources.execute.