Get started with Platform
Grant platform roles, describe your environments, review the shipped alert policies and jobs, and register your first packages.
Before you begin
You must be the workspace owner: a superuser, or an administrator of every company. Only the owner can grant platform roles. An administrator of only some companies is not an owner and needs a granted role.
Set up in this order
- Grant platform roles. Open Platform > Configuration > Platform roles and press Grant a role. Choose the person (an active user who is not an owner) and the role: Operator, Release manager, Independent approver, Configuration owner or Viewer / auditor. Give approval roles to people other than those who prepare releases. See Roles, audit trail and reports.
- Describe each environment. A configuration owner opens Platform > Releases > Environments and creates one per place the system runs: for example
STAGINGandPRODUCTION. Set the tier, the RPO and RTO in minutes, the maintenance window and the time zone, and tick This server is this environment on the one you are signed in to. Another person approves it and an operator marks it deployed. See Set up environments and release policies. - Create a release policy if you want more than one approver or extra gates. Without one, a default applies. Details are in the same guide.
- Check the shipped jobs. Open Platform > Operations > Scheduled jobs. The first visit creates seven platform jobs. Metrics snapshot, alert scan, package scan and prune are enabled; SBOM, restore drill and upgrade rehearsal are tested but not scheduled. See Run and monitor scheduled jobs.
- Check the shipped alert policies. Open Platform > Configuration > Alert policies. Six are active: queue lag, p95 latency, server errors, dead jobs, backup age and failed drills. See Alerts and workload.
- Register your packages. An operator opens Platform > Packages > Packages and presses Sync from this build to register every module of this build as a draft package. See Register, review and certify packages.
- Take a first SBOM (a bill of materials of the software components) under Platform > Configuration > Bills of materials: Supply chain evidence.
- Take and verify a backup under Administration > Settings > Storage and backup, then run a first restore drill: Run restore drills.
Feature flags to know about
Two flags exist from the start, both off:
platform.enforce_registry(whole workspace): when on, installing or upgrading an app is refused unless its package has a reviewed or certified version.platform.uninstalled_apps_readable(per company): lets a company read the data of an app that is turned off, while every change stays refused.
Turning a flag on needs a proposal and a second person's approval: Feature flags.
The server banner
The Overview shows the server tier (Production, Staging and so on) and the current environment code. On a staging or recovery copy it also says Outgoing mail and webhooks off, because a copy must not email real customers. It shows Schema is not at this build's head when the database has not been migrated to the version this build expects.
Permissions at a glance
| To do this | Platform role |
|---|---|
| Register packages, create and submit releases, run jobs and drills | Operator |
| Review packages, stage and cancel releases | Release manager |
| Certify packages, approve releases and environments | Independent approver |
| Create environments, jobs, policies; retire releases | Configuration owner |
| Read only | Viewer / auditor |
Try each role with a test user. Buttons the role cannot use are not shown, and the server refuses them with 'This needs the platform role ...'.