Onboarding & Deboarding
A gateway's birth into the system, and its exit. Nothing else lives on this page — ongoing configuration, grants, and entitlements are under Configuration Management.
Onboarding
Name and node assignment happen together, in one action, at claim time — no separate trip to Gateway Inventory needed just to name a new gateway. No node ID is ever typed — assignment is always a pick from the tree.
Decommission
Starting a decommission, tracking it in the pending list, and placing a compliance/legal hold are all real, enabled actions below. Owner-tier is required for every write action. Each pending row's own "Review attestation" still opens that device's attestation review right here -- the same review is also reachable by device id on the Erasure & attestation tab, for a device not (or no longer) in this list.
Loading…
Grants, Module entitlements, Config diff/rollback, and Bulk push are NOT on this page — see Configuration Management.
Erasure and attestation
Reviewing an attestation is real, and confirming erasure is now real and enabled too -- sql/152 added the confirm_erasure_verified GRANT EXECUTE that was previously missing (see this file's own header comment). Owner-tier is required for every write action below. Raw device-side attestation ingest (receive_decommission_attestation) deliberately stays superuser/CLI-only -- no device-side signing key infrastructure exists yet to let a real gateway authenticate that claim (a disclosed blocker).
Loading…