SECURITY OPERATIONSBanyan Control Plane Overview

DAILY SECURITY OPERATIONS

Know who can reach your workspaces.

Banyan Control Plane is the operating desk for workspace access, privileged roles, audit evidence, and access-envelope key posture.

Review workspace access
01AccessReview a workspace and issue delegated envelopes.
02AuthorityProtect and review privileged operator roles.
03EvidenceInspect bounded activity without exposing sensitive request data.

AGENT ONBOARDING

Connect an agent without guessing the security boundary.

Connect directly to the BCP Agent Gateway over MCP or ActNode Protocol. A local Broker is optional and only needed for local Agent governance.

GATEWAYChecking Agent Gateway… MCPChecking Agent Gateway… ACTNODEChecking Agent Gateway…

AT A GLANCE

Control-plane posture

Loading live status…

Control plane

CheckingContacting configured server

API contract

—Reading public profile

Public capabilities

—No profile loaded

Operator actions

ProtectedRequires a trusted operator session

START HERE

Choose the task in front of you

Every control explains its security boundary before it acts.

PRIVILEGED IDENTITIES

Protect operator authority

Grant or revoke control-plane administration only from an authenticated, audited operator session.

AUDIT EVIDENCE

Investigate recent activity

Review up to 50 safe activity records or download up to 200 validated records from an explicit UTC window. Pruning stays outside this console.

ACCESS ENVELOPE KEYS

Verify trust posture

Inspect published active and retiring public keys before rolling relying parties to a new signing key.

SAFETY BOUNDARY

The console never treats visibility as authorization.

Server-side authentication and authorization decide whether a protected operation may run. This interface makes the boundary visible; it does not bypass it.

How access works

OPERATOR GUIDE

How this console works

Use this overview to understand the system and begin a read-only workspace review. Privileged workflows require an authenticated operator session and remain enforced by the BCP server.

OPERATOR SESSION

Signed in to the Web console

BCP Core still authorizes every workspace and privileged operation.

AUDIT EVIDENCE

Bounded audit ledger

Read-only evidence from BCP Core. Signed-in state does not guarantee administrator authority.

No evidence loaded.

TimeWorkspaceDecisionPrincipal

DOWNLOAD EVIDENCE

Export a selected UTC window

Choose both UTC boundaries. BCP validates the complete response before your browser receives a file; failed exports are never downloaded or retried automatically.

Times are interpreted as UTC. The file contains at most 200 safe records and never includes tokens or request payloads.

Select a start and end to prepare a download.

ACCESS ENVELOPE KEYS

Public verification posture

Published public verification identifiers only. Private keys, file paths and rotation controls never enter this console.

No key posture loaded.

AGENT CONNECTION GUIDE

Connect an agent to BCP

Step 1 of 4

01 · CHECK

Confirm the BCP Agent Gateway

BCP owns the remote protocol endpoint and control-plane authority. Agents may connect directly; installing a local Broker is optional and reserved for observing or operating local Agent processes.

Checking Agent Gateway…Reading bounded liveness and discovery data.