Starail v3.2 · Control Console

Authorize rails before money may move.

Evaluate → approve if needed → revalidate → attest. Soft* products are optional references — Starail never holds keys.

Open Control Plane
Loading runtime status…

Control Plane

Recommended path

Evaluate → (approve if needed) → revalidate → attestation. Soft* products are optional references only.

Rail Registry

Click “Refresh rails” to load the Rail Registry.

Decision Inspector

Run evaluate to inspect ALLOW / DENY / REQUIRES_APPROVAL with reason codes and rule trace.

Policy versions

Click “Load policy” to inspect ACTIVE / SHADOW versions.

Start here (Control Plane)

Control first

Partner path: evaluate rails before signing. Legacy Route Builder analyze remains below for TransferIntent demos.

1 · Evaluate

Set amount/currency above, then Evaluate (or Run full loop).

2 · Approve if needed

REQUIRES_APPROVAL → Approve last, then revalidate.

3 · Attest before your signer

Issue attestation / use @starail/sdk guard() — Starail never holds keys.

Partner onboarding wizard

Run integration checks before going live. Each step calls a real API endpoint.

  1. Auth status & API key readiness
  2. Control rails + evaluate/loop smoke
  3. Integration quickstart manifest
  4. Ops SLO + KYT smoke
Open Control Plane
Click “Run onboarding checks” to verify partner readiness.
Plain-language glossary
KYT (Know Your Transaction)
A wallet or address screening step — like a compliance check before you send money.
Policy
Your organization's rules (fees, chains, approvals) that decide allow, review, or block.
Proof packet
An exportable record showing what was checked before any transfer was requested.
Database warm-up
Starail loading saved data from Postgres after restart. New writes still save during warm-up.

Provider Matrix

loading
Loading provider capabilities…

Runtime Health

read-only
Loading provider health…

Radar Signals

Open Infra Map
No radar signals loaded yet.

Provider Health Overrides

Simulate degradation or outage signals and watch Firewall circuit breakers change policy decisions.

v1.5 health collector
No health snapshot collected yet.

Route Builder (legacy)

TransferIntent analyze path for demos. Prefer Control Plane evaluate above for partners.

legacy firewall

Route Candidates

No intent created yet.

waiting
Run analysis to compare routes.

Policy Decision

Waiting for analysis.

KYT Screening

mock provider
Waiting for KYT screening.

Simulation Lab

waiting
Waiting for simulation.

Approval Queue

operator review
Waiting for approval request.

Pre-execution Run

no signing
Waiting for preparation.

Reconciliation Model

no funds moved
Prepare a no-execution reconciliation report after pre-execution.

Proof Packet

Waiting for proof.

Immutable Audit Trail

hash chained
Waiting for audit events.

Prepared Execution

no signing · no submission
Approve the flow, then prepare a pre-signing execution record.

Incident Operations

health + reconciliation
No incidents loaded yet.

Webhook Outbox

vault-signed · delivery disabled by default
No webhook events loaded yet.

Secret Vault Boundary

metadata only
No secret metadata loaded yet.

Connector Registry

disabled by default
No connector registry loaded yet.

Signer Boundary

customer-owned
No signer integrations loaded yet.

Managed Vault

metadata only
No vault status loaded yet.

Persistence Runtime

memory · file · postgres
No persistence status loaded yet.

Partner API keys

admin · RBAC
No API keys loaded yet.

Ops Summary

readiness · auth · webhooks
No ops alerts loaded yet.
No ops summary loaded yet.
No connector runtime status loaded yet.
No worker task runs loaded yet.

Durable Workflow Boundary

idempotency locks
No workflow runs loaded yet.

Scheduler Operations

health + retry jobs
No scheduler jobs loaded yet.

Knowledge Graph Changes

daily diff

Compare the latest knowledge graph snapshot against the previous baseline to see what changed in issuers, providers, chains, and rails.

No graph change report loaded yet.

Benchmark Studio

private · no execution

Run policy-aligned route benchmarks for design-partner onboarding. Results combine quote ranking and simulation only.

No benchmark runs yet.

AgentPay Firewall

Evaluate x402/AP2-style agent payment attempts before an AI agent spends stablecoins.

budget + merchant policy
No agent payment evaluated yet.