Ingest events
Upload a JSON Lines file. In Simulation mode the prepared payload is shown on screen but not sent. In Live mode the call is POSTed to IndyKite using the App Agent credential configured for this deployment.
Recent ingestions
Last 20 ingestions you've run.
Import users from Entra ID
Reads all enabled users from your Entra tenant and writes them to the Identity Knowledge Graph as User and Person nodes (with manager relationships) via the Capture API. Admin only.
Switch project
Reloads the graph for another demo project: first wipe the graph in the IK Hub (no delete API exists), then this runs Reconcile (Entra users → HR org structure → workflows, 14+10 INVOKES) and ingests the project's bundled dataset, stamped with its project id. Admin only.
Import workflows
Reads the workflow master list and writes Workflow nodes plus their governance links (owned-by department, authored-by and approved-by person) to the Identity Knowledge Graph via the Capture API. Run the user import first so departments and people exist. Admin only.
Reconcile graph
One press: runs the user import (Users, Persons, Departments, can-trigger grants) then the workflow import (Workflow + Agent nodes, INVOKES chains) in the required order. Use after any workflow-seed change instead of the two buttons above. Safe to repeat (upserts); re-runs add duplicate identical INVOKES edges - harmless to the gateways, cleaned by a graph wipe when counts matter. Admin only.
Sync CIQ catalog
Reads the CIQ query master list (ciq-catalog-seed.json) and creates any missing knowledge queries + their policies in IK via the config API. Existing entries are never overwritten; description drift is reported. Idempotent - safe to run any time. Agents pick up new queries on their next chat automatically. Admin only.
IK Project
Read-only summary of the Context IQ configuration loaded from Key Vault. The credentials themselves stay server-side.
- Loading
- …
Query Runner
Execute any knowledge query by its IK ID. Useful while iterating on policies/queries. Optionally pass input parameters (one per line, name=value).
Result will appear here.
Policies & Knowledge Queries
Lists what currently exists in IK (the single source of truth). Click an ID to copy it into the Query Runner above.
Create authorization policy
Paste the inner policy JSON (the object — not pre-stringified). The server wraps and stringifies it. Author group only.
Create knowledge query
Paste the inner query JSON. Provide the policy_id it references. The server wraps and stringifies it. Author group only.
Agent activity
Agent skills & configuration
Everything an agent says is driven by one system prompt, assembled fresh on every call from five layers stacked in a fixed order. Pick an agent to see exactly what reaches its prompt — and edit the live skills layer right here. Skills shape how an agent asks and answers; what it is allowed to do is decided by graph policy, never by this screen.
Skill editor
All editable skills across every agent. Click a row (or an Edit button in the stack above) to load it; saves apply to the very next message. Every change records who and when.
New skill
loading…
Demo autopilot
Drive the demo with an agreed script — the autopilot selects the agent, types the question like a human, sends it through the REAL chat pipeline, and waits for the full reply (including any decision boxes, which pause the run until you click) before the next step. Pair it with the recorder below for the offline fallback video: live agents, zero live-wifi risk.
Recorder
Records this browser tab to a local .webm file (downloads when you stop) — nothing leaves your machine. Click Start, pick this tab in the browser prompt, switch to the AI Agents tab, then Play the script. Chrome/Edge.
Configured agents
Each user is routed to an agent based on their department.
What I am to IK
Your identity, department, and the AI agent workflows you can run — read live from the IndyKite graph and reconciled against company policy.
Raw response
Inter-agent delegation - token exchange tests
Runs RFC 8693 token exchange against Clave. Each test shows every token involved
(decoded payload and raw JWT), so you can inspect the sub, act, and chain depth.
act claims.
message/send to the deployed agent service URL and display its
response. Validates that the deployed agent accepts the exchanged token's aud and
returns a Claude answer.
authzen_evaluate tool with a delegated bearer
built to a chosen depth - no LLM in the loop. Shows IK's raw decision/error and the decoded
token chain, so you can see exactly which bearer the MCP accepts. Reuses the AuthZEN tab's
checks and workflow list.
Security Audit
Look up any subject and see their master-data chain and what they can do. Admin only. Helps verify the data is in good shape before a demo.
Raw response
AuthZEN decision runner
Ask IndyKite's AuthZEN engine "can this subject perform this action on this resource?" — a live allow/deny decision evaluated against the KBAC policies. Admin only. This is the same CAN_TRIGGER gate agent execution will use.
Raw response
Welcome.
You're signed in as an agents user via Alvicode Clave.
Agent features are still under construction. The full experience —
including agent execution gated by the AuthZEN CAN_TRIGGER
decisions you can see in the admin tooling — arrives once the
token-exchange flow goes live.
For now you can sign out (top right) and re-enter via Microsoft if you need the admin tooling.
Developer: token claims received from Clave
Useful while the federation claims are being shaped on the IdP side. This panel will be hidden once the Clave integration is settled.
Loading claims…