SECURITY OPERATIONSBanyan Control Plane Overview

DAILY SECURITY OPERATIONS

Know who can reach your workspaces.

Banyan Control Plane is the operating desk for workspace access, privileged roles, audit evidence, and access-envelope key posture.

Review workspace access
01AccessReview a workspace and issue delegated envelopes.
02AuthorityProtect and review privileged operator roles.
03EvidenceInspect bounded activity without exposing sensitive request data.

AGENT ONBOARDING

Connect an agent without guessing the security boundary.

Check the real Agent Broker, copy its operator-published HTTP endpoint, and understand which protected actions still require a short-lived BCP access envelope.

HTTPChecking Broker setup… MCPPlanned · not available yet

AT A GLANCE

Control-plane posture

Loading live status…

Control plane

CheckingContacting configured server

API contract

—Reading public profile

Public capabilities

—No profile loaded

Operator actions

ProtectedRequires a trusted operator session

START HERE

Choose the task in front of you

Every control explains its security boundary before it acts.

PRIVILEGED IDENTITIES

Protect operator authority

Grant or revoke control-plane administration only from an authenticated, audited operator session.

AUDIT EVIDENCE

Investigate recent activity

Query up to 50 safe activity records without exposing tokens, request payloads, or client IPs. Export and pruning stay outside this console.

ACCESS ENVELOPE KEYS

Verify trust posture

Inspect published active and retiring public keys before rolling relying parties to a new signing key.

SAFETY BOUNDARY

The console never treats visibility as authorization.

Server-side authentication and authorization decide whether a protected operation may run. This interface makes the boundary visible; it does not bypass it.

How access works

OPERATOR GUIDE

How this console works

Use this overview to understand the system and begin a read-only workspace review. Privileged workflows require an authenticated operator session and remain enforced by the BCP server.

OPERATOR SESSION

Signed in to the Web console

BCP Core still authorizes every workspace and privileged operation.

AUDIT EVIDENCE

Bounded audit ledger

Read-only evidence from BCP Core. Signed-in state does not guarantee administrator authority.

No evidence loaded.

TimeWorkspaceDecisionPrincipal

ACCESS ENVELOPE KEYS

Public verification posture

Published public verification identifiers only. Private keys, file paths and rotation controls never enter this console.

No key posture loaded.

AGENT CONNECTION GUIDE

Connect an agent to BCP

Step 1 of 4

01 · CHECK

Confirm the Agent Broker boundary

BCP Core owns control-plane authority. Agent Broker is the HTTP bridge that accepts Agent service and call operations after BCP has issued exact, short-lived authority.

Checking Agent Broker…Reading bounded liveness and discovery data.