Appearance
Operator console
The xgress3 operator console is where you manage your account: approve agents, configure services, issue credentials and service keys, invite teammates, review account activity in Event Viewer, and trace HTTP requests.
Sign in with your organisation’s identity provider. You never type an account ID into individual forms — you choose the active account from the header, and all actions apply to that account.
Layout
| Area | Purpose |
|---|---|
| Left navigation | Dashboard, Agents, Services, Request Lookup, Event Viewer, Authentication, Billing, Settings |
| Top bar | Breadcrumbs and global actions |
| Header (top right) | Your profile, account selector, and region selector |
The region selector is available when an account is selected. Agents and services are region-scoped; always confirm the region matches where you enrolled agents and where clients send traffic.
Navigation
| Menu | Purpose |
|---|---|
| Dashboard | Account overview, stats, and first-time setup checklist |
| Agents | List agents, enroll new agents, open agent details |
| Services | All services across agents |
| Request Lookup | Find a request by X-Xg3-Request-Id — see Request logging |
| Event Viewer | Account audit log — who changed configuration, plus system activity — see Event Viewer |
| Authentication → Credentials | OAuth-style client credentials for JWT callers |
| Authentication → Service Keys | Long-lived keys for service-key callers |
| Settings → IAM → Users | Invite and manage account members |
| Settings → IAM → Roles | View and edit roles (Admin, Viewer, Account Manager, custom) |
| Billing | Subscription status, usage, subscribe, change plan, manage payment |
Menu items and buttons appear only when your role allows the action.
What you can manage
| Object | Console tasks |
|---|---|
| Agent | Approve enrollment, enable/disable, view tunnel status, attach services |
| Service | Create, update backend URL and auth modes, enable/disable, delete |
| Credential | Create client ID/secret, set allowed services, enable/disable |
| Service key | Create key (copy once), set allowed services, enable/disable |
| Users & roles | Invite colleagues, assign roles |
Getting started paths
| Situation | Document |
|---|---|
| New user, no account yet | Getting started |
| First agent and service | Agents and services |
| Subscription and billing | Billing |
| Issuing caller secrets | Authentication |
| Who changed what in the account | Event Viewer |
| Failed HTTP calls | Troubleshooting |
For a full end-to-end setup, see Quickstart.