Skip to content
User Guide

Resource → Summary

The default tab for resources that support snapshots. Graphical-only resources open on Notes. They and Generic SSH do not expose Summary or Facts; Generic SSH opens on Actions where permitted. Summary shows the latest saved verification check alongside a snapshot-based overview: key identification fields, a map pin, tags, and health metrics.

Available tabs and actions depend on your permissions at this resource’s location. Reading a resource does not automatically allow editing, connecting, transferring files or using Quick Assist.

Connections

Use the Connect button beside the resource in the location tree to open a session in its own pin. Session options appear when required. Access depends on execute permission at the resource’s location.

Use the connection pins to switch between sessions. Shells share a default limit of three per user/resource; graphical modes share a fixed limit of one. Disconnect or close a connection pin to free its slot. Closing one pin leaves sibling connections running.

The connection title shows the resource name followed by (ID: <session_id>). Disconnect, AI assistance (when available), and Invite appear on the right of the title bar, followed by the pin button.

What you see

  • Verification row — compact chevron badges for reachability, signature, authentication, and identity, with the last checked date at the end. This row appears only on Summary.
  • Resource Info card — identification fields extracted from the snapshot (vendor, model, serial, version, hostname, OS, etc., depending on the resource type).
  • Map card — a map centered on the location’s coordinates. If no coordinates are configured, the map still renders, zoomed out to a world view.
  • Tags card — the tags assigned to this resource, as removable chips, plus an Add tag menu to assign more. (Shown when you can read tags; adding and removing require write access to resources.)
  • Health Status grid — one card per enabled metric. The badge next to the Health Status heading summarizes the worst metric state: green (healthy), orange (degraded), red (critical).

Below the metrics, permitted evidence appears in three cards: Compliance spans the full width; Alerts and Syslog share the next row and stack on smaller screens. Their existing filters and investigation controls remain available, even when no snapshot has been collected yet.

The resource tab order is Summary → Actions → Configure → Notes → Facts → Files → History. Only supported and permitted tabs appear. Compliance, Alerts, and Syslog appear within Summary.

Metric cards are tinted by status:

StatusCard tint
Healthygreen
Warning / Degradedorange
Criticalred
Not collectedgrey (“No data in snapshot”)

Each card renders a visualization suitable for the metric type:

  • Gauge — a dial showing the current value against a maximum.
  • Count — a large number.
  • Boolean — a Yes/No indicator with human-readable labels.
  • Distribution — a donut chart summarizing proportions.
  • Breakdown — a horizontal bar chart of top items.

Every populated card also carries a small View metric history chart button that opens the metric’s history over time.

Verification status

The row reads in this order: Reachability → Signature → Authentication → Identity, showing only checks the resource type supports. Unsupported and inapplicable stages are hidden; supported checks that have not run remain visible. These outcomes use the same vocabulary as the browse tree’s icons and verification filter, and the add/edit resource checks.

StageOutcomes and meaning
ReachabilityReachable means the worker reached the resource. Unreachable means the connection failed. It does not establish whether credentials or identity are correct.
SignatureValid signature means the applicable server key or certificate verification passed. Invalid signature means that verification failed. For SSH, this includes comparison with the saved host key.
AuthenticationAuthentication passed means the resource accepted the credential. Authentication failed means authentication did not succeed.
IdentityIdentity match means the observed external identity matches the stored value. Identity mismatch means it differs. Identity detected is the initial observation during onboarding. Identity check failed means the identity could not be verified; it does not establish a mismatch.

Identity compares the resource’s external identifier, such as a serial number or account identifier where supported. It does not compare the friendly resource name, and a successful login alone does not prove an identity match.

Green indicates a passed stage; red indicates failure. Warning states use orange, and neutral states use grey. Hover or focus a badge for a concise explanation. A badge opens additional details only when there is more information to show, such as expected and observed values.

Grey and incomplete stages

  • Not checked means the check did not establish an outcome for that stage. An earlier failure may have prevented it from running.
  • Signature not configured means optional server verification is disabled, for example SSH with Strict Host Key Verification turned off.
  • Signature configuration required means verification is required but a usable saved key is missing. Review the observed key in onboarding or in a fresh edit check.
  • Not applicable means the stage does not apply to that resource or connection method; it is omitted from the row and tree icons.

An existing resource with no stored identity shows Identity not checked, even if a new identity was observed. A fresh edit check can offer Accept new identity to establish the comparison value.

The stages adapt to the resource. AWS and Azure checks use the verification built into their cloud clients; successful authenticated remote checks can establish Valid signature without a separate host-key setting. A network connection alone, including an open RDP or VNC port, does not prove signature, authentication, or identity success.

Check failed summarizes a failure; read the individual stages to see what succeeded and where to act. Check incomplete means some stages were not checked. Check completed does not mean that every optional verification setting is enabled.

Check freshness and recovery

The row describes the latest saved check, independently of the selected historical snapshot. Changing the Snapshot Selector changes snapshot data, not this row. A check records what was observed at its timestamp; it is not continuous monitoring of the connection.

When settings have changed since the saved check, the row shows Settings changed — re-check required. Open Edit → Verify to check the current configuration. An unreachable resource needs its address, network path, and worker reachability checked; an authentication failure needs the selected credential reviewed. For a signature or identity mismatch, inspect the expected and observed values before accepting an intentional change. Follow Re-check or change connection settings.

What you can do

  • Click a metric card that is backed by a command to run the underlying command live against the resource — the view switches to the Actions tab with the command’s output. (Cards tied to a command show a pointer cursor on hover.)
  • Use the Snapshot Selector in the header to pick a previous snapshot and view its data. Going back in time changes every tab that depends on snapshot data.
  • Click the collect button on the Snapshot Selector (tooltip: Collect new snapshot) to trigger a fresh collection right now.
  • Click Quick Assist in the header to ask the AI for a summary of the resource’s current state in plain language.

The Snapshot Selector’s outline and text reflect the selected snapshot’s collection result: green for success and red for failure, regardless of age. While a collection is running, the control blinks orange.

Collection can take several minutes on larger resources. The browser waits for the collection’s execution deadline and reports completion or failure when the result arrives. Check the collection status before treating displayed values as current.

When there is no data

If the resource has never had a snapshot taken — or every metric is disabled — a yellow banner reads:

No snapshot data available. Run a snapshot collection first.

Trigger a snapshot with the collect button on the Snapshot Selector in the page header, or wait for a scheduled collection that covers this resource.

Permissions

  • Read: app.resources.read.
  • Run a live command from a metric tile: the permission matching the command’s mode — app.resources.read for the built-in read-only commands the tiles use. The command opens in the Actions tab.
  • Trigger a snapshot from the Snapshot Selector: app.resources.execute, scoped to the resource’s location.
  • Tags card: app.resources.read to see assigned tags; app.resources.write to add or remove tags. Both follow your allowed locations; tag administration permissions are not needed.

Compliance, Alerts, and Syslog cards require both the appropriate permission and the licensed capability (fact policies, IDS, and Collector respectively).