← All articles
Broker — connectivity

Understanding the admin console

Broker's admin console is the operator-facing view into a Separation of Powers architecture: three independent planes — Authorizer, Manager, and Receiver — each handling one part of every connection. No single plane can grant access alone, which is a deliberate security property, not an accident of implementation. Understanding these three planes makes the console much easier to reason about.

Authorizer — decides who may connect

The Authorizer is the plane that answers one question: is this identity allowed to connect, right now? It evaluates the presenting certificate, checks it against live grants and revocation state, and is fail-closed by design — if there's any ambiguity (an expired certificate, a missing grant, an unreachable dependency), the answer defaults to "no," not "yes." You won't interact with the Authorizer directly very often, but its decisions are what the Manager console reflects back to you as active, pending, or denied connections.

Manager — the global, real-time view

The Manager is what you're looking at when you open the admin console itself. It gives you a single, real-time view of every connection across your organization, and it's where point-and-click access grants happen — see Granting and revoking access for the full workflow. Rather than filing an IT ticket to open a firewall rule, an authorized administrator (or a distributed one — a plant manager can grant access to their own services without escalating to central IT) clicks a button in the Manager console, and the grant takes effect live.

Receiver — terminates the connection

The Receiver is the plane that actually terminates the encrypted point-to-point session. Once the Authorizer has said yes and the Manager has recorded a grant, the Receiver is where the two ends of the connection actually meet — and it's scoped so tightly that nothing beyond the specific authorized path is reachable through it. This is what makes Broker fundamentally different from a VPN: a VPN typically drops a device onto a subnet where much more than the intended destination is technically reachable. A Receiver-terminated Broker connection exposes exactly one path and nothing else.

Reading the console

In the Manager console you'll typically see, per connection:

  • Path — source identity to destination service (for example, vendor-tech-04 → WTP-PLC-2)
  • Method — the identity mechanism in use (mutual-TLS certificate)
  • Status — active, pending grant, or denied
  • Duration — how long the current session has been active

Every one of these events is also written to an audit trail — see Granting and revoking access for how that ties into revocation, and the audit format captures who, what, when, where, and why for every decision the three planes make together.