The full flow, screen by screen
Every screen below is a capture from the running proof of concept, in the order a reviewer meets them. Nothing here is a mockup.
1. Sign in
Identity first: the product name, one line, and sign-in. No catalogue and no data render before identity is resolved.
2. Admit
The model catalogue is the default route: admission counts, the held-and-rejected control, the five-axis filter console and the scan table.
A row is the scan; the record opens in a modal with digests, the licence pin, provenance and review.
3. Hold and reject
Held and rejected candidates sit behind their own control, each with the gate's verbatim reason.
4. Compare
Retained runs, newest first; two are picked for the comparison. A run in flight reports its state while the harness works, and the report carries cost per completed task.
Base against compared, per model, with the delta. The hosted leg is labelled provenance by host attestation, not verified.
A governed hosted call through the hook, reported against its decision row.
5. Ledger
A refusal shows its reason to the person who made it, and the same reason sits in the ledger with the policy revision that decided it.
6. Entitlement
Keys are issued through the gateway admin API; the secret shows once and is never stored. Revocation lands in the same list, and budgets total the committed tokens beneath it.
7. Data flow
The generated data-flow document: classes, flows, egress, listeners and the controls awaiting a human.
Walking this flow against your own estate? Heliast runs this inside your environment, on your policy.
Book a discovery session