Zovelty Customer Workspace
Browser identity, tenant onboarding, plans, usage and protected operational access.
Sign in with your organization, then complete tenant onboarding.
Browser sessions are bound to durable tenant membership and existing role permissions. Service-account access remains available only as an explicit compatibility path. No external identity provider is claimed qualified until a real provider is tested.
Organization sign-in
Authorization Code + PKCE S256. Provider tokens never enter browser JavaScript.
Checking browser identity-provider configuration.
Service-account compatibility access
Existing machine/API authentication remains supported. Explicit credentials stay authoritative and never fall through to a browser session.
The token is sent only as an explicit request credential and is not written to local or session storage.
Plans and limits
Versioned server-owned plans. Clients cannot submit arbitrary entitlements.
Onboarding evidence
A step is never reported complete without bounded evidence. External connector and identity readiness are not inferred.
Connector permissions and readiness
Choose one tenant-visible connector profile and review its server-published least-privilege permissions. Connector readiness requires an active profile, an active non-expired credential and explicit permission review. External provider connectivity is not inferred by this onboarding step.
Select a tenant-visible connector profile to review its permission guidance.
No connector profile selected.
No connector onboarding evidence is loaded.
Selected operational scope
Choose a tenant-visible environment and the services Zovelty may use for operational context. Readiness is derived from the authoritative registry; missing owner, on-call, SLA/SLO, resource or location evidence remains visible.
Create or import operational context
No operational-context changes submitted.
No operational scope selected.
No operational-context onboarding evidence is loaded.
Support and escalation notification route
Review server-owned masked notification-route information and confirm organizational ownership. This confirmation does not configure SMTP credentials, expose raw recipients, or prove external email delivery.
Load protected notification-route status first.
No notification-route onboarding evidence is loaded.
Usage and resource limits
Calendar-month counters are replay-safe and limit enforcement is atomic in PostgreSQL.
Support operations
Latest tenant-scoped support cases. Raw credentials are not accepted or returned.