# The Console

> What the Console controls, who can open each page, and how it works with your agent and the proof pages.

Canonical page: https://anectico.com/docs/manage/console/


The Console is the web app for your Anectico workspace. Your own AI agent does the product work
(it searches, measures, investigates and sets things up) through MCP and the CLI. You use the
Console for three jobs:

- **Control.** You decide who and what has access: agents, keys, people, projects, connections,
  privacy, safety, published links, billing and the audit log.
- **Onboarding.** You connect your first agent and check your first application.
- **Viewing.** You open a [proof page](/docs/agents/proof-pages) that your agent gave you as a link,
  and check its claim.

The Console has no lists, builders or editors for your product data. There is no issue list, no
dashboard editor and no chart builder. To ask a question about your product, ask your agent. See
[Quickstart](/docs/start/quickstart).

## The ten menu pages

The menu has ten pages. It shows only the pages you are allowed to open. If your role cannot open a
page, the page is not in your menu. Each card on a page checks your permission again, so typing an
address does not get you past it. A role and its scopes are listed in
[Permission scopes](/docs/reference/permissions).

| Menu page | Address | You can open it with |
| --- | --- | --- |
| Home | `/` | Any signed-in account |
| Agents and keys | `/agents` | `oauth:connections` or `api_key:read` |
| People | `/people` | `members:read` |
| Projects | `/projects` | Any signed-in account |
| Connections and notifications | `/connections` | `connections:read` or `channels:read` |
| Privacy | `/privacy` | Permission to export or erase a person or an account, or `ingestion:pipelines:read`, or `governance:read` |
| Agent safety | `/agent-safety` | `quarantine:request` or `quarantine:approve` |
| Published links | `/published-links` | `live:read` |
| Billing and usage | `/billing` | `billing:read`, `usage:read` or `settings:read` |
| Audit log | `/audit-log` | `audit:read` |

The header has two controls: the project switcher and the account menu. The switcher chooses the
project that the control pages work in. A proof page always uses the project named in its own link.

An address that is not on this list shows the not-found page. The Console does not redirect old
addresses.

## Home

Address: `/`. Who can open it: any signed-in account.

Home is where you connect your agent. Until an agent is connected, Home shows **Connect your
agent**. Choose **Claude Code**, **Codex**, or **CLI / another agent**. Copy the commands, run them in your
application's terminal, and sign in when the browser asks. The commands sign you in, create a
narrow key for the project, set up the agent, and check the connection. The same steps are in
[Quickstart](/docs/start/quickstart).

After an agent is connected, Home lists your connected agents and shows how far setup has gone. An
agent counts as connected when it has an active approval or a key that has been used. Home shows no
product data.

Home also shows **Recent agent activity**: each agent that called Anectico in the last 24 hours,
how many calls it made, how many were refused or failed, and its latest calls with their outcome.
You see it with `activity:read`, which every role has. You see your own agents; owners and admins
see every agent. **See all activity** opens the full list on **Agents and keys**. See
[See what your agents did](/docs/manage/agent-activity).

Home links to the setup guide at `/get-started`. The setup guide is for people who prefer to set up
by hand. It installs an SDK, creates the application keys, and checks one test customer from end to
end. See [Verify your setup](/docs/start/verify-setup).

## Agents and keys

Address: `/agents`. Who can open it: `oauth:connections` or `api_key:read`.

This page has three parts.

- **Connected agents.** Each row is one approval that you gave to an agent. It shows the client name
  and host, the workspace, the permissions you approved, when it was created and last used, and its
  status. Select **Revoke** to stop that approval. Other approvals keep working. An administrator
  with `members:write` can also open **Everyone's connections** to review and revoke other people's
  approvals.
- **API keys.** Create a key, choose its purpose and project, choose its scopes and expiry, rename
  it, change its scopes, or revoke it. A key's purpose decides what it can do. A management key
  reads or manages the project through REST, MCP and the CLI. Other purposes send telemetry,
  browser or mobile events, or experiment assignments, and they cannot be used as an agent key.
- **Agent activity.** Every call an agent made to Anectico through MCP, the CLI or the API, reads
  included, newest first: the agent, the call, the outcome and the time. It is read-only and kept
  for 30 days. You see your own agents; owners and admins see every agent. What a signed-in person
  does in the Console is not listed. The one thing the Console reports is that a proof page was
  opened. That is a separate record, and owners and admins can see who opened. See
  [See what your agents did](/docs/manage/agent-activity).

Your agent can also do the key work with the CLI. Use `anectico apikey create`, `anectico apikey
list` and `anectico apikey revoke`, or `anectico auth connections list` and `anectico auth
connections revoke` for approvals. Approvals need a person who is signed in. See
[Revoke an agent's access](/docs/agents/revoke-agent-access),
[Authentication and API keys](/docs/reference/authentication) and
[How agent access is enforced](/docs/agents/security-model).

## People

Address: `/people`. Who can open it: `members:read`.

This page shows who is in the workspace and what role each person has. Owners and administrators
can invite a teammate by email with a role (Member, Viewer or Admin), revoke an invitation that has
not been accepted, change a role, and remove a person. Other roles see the list and cannot change
it.

The CLI does the same work: `anectico members list`, `anectico members set-role`, `anectico
members remove`, and `anectico invitations create`, `anectico invitations list` and `anectico
invitations revoke`. See
[Manage an organization and projects](/docs/manage/workspace-and-projects).

## Projects

Address: `/projects`. Who can open it: any signed-in account.

A project keeps one application's data apart from the others. This page creates, renames and
removes projects. The page keeps at least one project in the workspace. Removing a project deletes
its data, so read [what deletion removes](/docs/manage/workspace-and-projects) first.

Your agent can list projects with `anectico projects list` and the MCP tool `list_projects`, and it
can create and update them with `anectico projects create` and `anectico projects update`.

## Connections and notifications

Address: `/connections`. Who can open it: `connections:read` or `channels:read`.

This page has two tabs.

- **Connections.** Connect Slack, GitHub, an issue tracker and other services. The sign-in step at
  the other service is a person's job, so it happens here. The page at
  `/connections/handoff/...` is where you approve a connection that your agent asked for.
- **Notifications.** Choose where alerts and escalations are sent: notification channels and your
  contact methods. You can send a test message to a channel.

Your agent can read and set up both with `anectico connections ...` and `anectico channels ...`.
See [Connect tools and notification delivery](/docs/manage/connections-and-notifications).

## Privacy

Address: `/privacy`. Who can open it: permission to export or erase a person or an account, or
`ingestion:pipelines:read`, or `governance:read`.

This page has three tabs.

- **Requests.** Enter a person id or any identifier of the person. The page looks the person up
  first, and you can start a request only for a person it finds. You can export the person's data,
  erase the person, turn on diagnostic capture for the person, and correct an identity that was
  linked wrongly. You can also find an account by type and key and erase it. The page lists
  the progress of every person erasure and account erasure.
- **Browser capture.** Choose what the browser SDK may capture, and manage page snapshots.
- **Content policy.** Decide what recorded content may be used for.

An erasure cannot be undone. It needs a typed confirmation, and it returns a receipt. See
[Erase a person](/docs/manage/erase-a-person), [Export a person's data](/docs/manage/export-a-person),
[Erase an account](/docs/manage/erase-a-group) and
[Decide what recorded content may be used for](/docs/manage/content-policy).

## Agent safety

Address: `/agent-safety`. Who can open it: `quarantine:request` or `quarantine:approve`.

This page stops an agent that is misbehaving, whatever it is doing. One person requests the stop.
A different person approves it. The same person can never do both. You can also lift a stop, or
withdraw a request that is not approved yet. See [Contain an agent](/docs/agents/contain-an-agent).

## Published links

Address: `/published-links`. Who can open it: `live:read`.

A Live link shows a screen to anyone who holds the link, without signing in. This page lists every
Live link in the current project and revokes one. Revoking stops the link for good. Your agent
creates, pauses and rotates links. Only an owner or an administrator with `live:publish` can
revoke. See [Live viewing links and access](/docs/manage/live-links-and-access).

## Billing and usage

Address: `/billing`. Who can open it: `billing:read`, `usage:read` or `settings:read`.

This page shows your plan and subscription, and lets you change it. Checkout and plan changes are
a person's decision, so they happen here. It also shows what the workspace has used, how the
allowance is split between product events and technical events, and the model prices that are used
to work out the cost of your AI calls. The payment provider returns you to this page after
checkout. See [Manage billing and subscriptions](/docs/manage/billing) and
[Review usage, model prices and decision scoring](/docs/manage/usage-and-ai-settings).

## Audit log

Address: `/audit-log`. Who can open it: `audit:read`.

This page records who did what in the workspace: sign-ins, access changes, keys and settings. You
can filter by resource, action and result. Sensitive request metadata is hidden. Your agent can
read the same record with `anectico audit list`. See
[Credential revocation and audit behavior](/docs/reference/credential-revocation).

## Ask your agent

Your agent can do the work behind most of these pages. The decisions stay with people: an agent
cannot approve its own stop, and a destructive change asks for a preview and a confirmation first.

> Show me who changed an API key or a role in the last week.

| Job | MCP tool or action | CLI command |
| --- | --- | --- |
| Read the audit trail | `list_audit_events` | `anectico audit list` |
| See what each agent did | `list_agent_activity`, `summarize_agent_activity` | `anectico activity list`, `anectico activity summary` |
| See which proof pages people opened | `summarize_proof_link_opens` | `anectico activity opens` |
| List API keys and revoke one | `list_api_keys`, `revoke_api_key` | `anectico apikey list`, `anectico apikey revoke` |
| List members and change a role | `list_members`, `update_member_role` | `anectico members list`, `anectico members set-role` |
| Invite a teammate | `create_invitation` | `anectico invitations create` |
| List and create projects | `list_projects`, `create_project` | `anectico projects list`, `anectico projects create` |
| Read the plan and usage | `get_billing_subscription`, `get_org_usage` | `anectico billing status`, `anectico usage` |
| List Live links and revoke one | `list_live_grants`, `revoke_live_grant` | `anectico live grant list`, `anectico live grant revoke` |
| Ask for a stop, or approve one | `request_quarantine`, `approve_quarantine` | `anectico quarantines request`, `anectico quarantines approve` |

## Where to go next

- [Proof pages](/docs/agents/proof-pages): the read-only pages that your agent's links open.
- [Quickstart](/docs/start/quickstart): sign up, connect your agent, ask, and open the proof.
- [Run an agent end to end](/docs/agents/zero-dashboard-quickstart): connect, ask, and act with a
  second key.


## Agent budgets

The API keys card and Connected agents show each credential’s effective operation limits and accepted usage today in UTC. Owners/admins can edit them there; the API keys card also sets workspace defaults and totals. See [Manage agent budgets](/docs/manage/agent-budgets).
