The Platform
The shared vocabulary and mechanics that the whole module reference depends on.
This section establishes what the product is, the objects it manipulates, the lifecycle those objects move through, how access is controlled, and how the product is packaged commercially.
Read this before the module reference
Every module page assumes the concepts defined here. If a module page uses workspace, finding, opportunity, or remediation class without explaining them, this is where they are explained.
The five-stage operating cycle
The product organises itself around a five-stage cycle, and the navigation groups map onto it directly:
| Stage | The question it answers | Where it lives |
|---|---|---|
| Observe | Where is the money going, and what changed? | Operate, Analyze |
| Understand | Why did it change, and what is it costing per unit of business value? | Analyze |
| Prevent | How do we stop the next expensive change before it ships? | Govern |
| Optimize | What waste exists right now, and what is it worth to fix? | Operate, Analyze |
| Act & Prove | Fix it safely, and prove the saving was real. | Operate, Govern |
What is in this section
Core Concepts
The nine objects that carry most of the meaning in the product — organisation, workspace, connection, spend record, finding, opportunity, approval, execution, audit entry.
The Data Lifecycle
Nine stages from Connect to Emit. Knowing where a module sits on this pipeline explains most of its behaviour.
Cloud Coverage
Five infrastructure surfaces treated as first-class citizens, each with its own credential model, ingestion path, and detector family.
Access Control
Two independent server-side permission layers, the authentication methods available, and the additional safety controls around dangerous actions.
Plans & Limits
Four tiers, what each includes, and the two capability flags that matter most when choosing between them.