Access boundary
Route, scope, and shell
- Route preference
- —
- Allowed scope
- —
- Requested shell
- —
- Target state
- —
Connecting…
Configure and supervise terminal access with route preferences, approvals, session state, and recent command history.
Governed remote access
Preview resolves the exact device, route, scope, shell, approval policy, expiry, target-state version, and concurrency rows before anything is queued.
No session selected
Session state and lifecycle evidence remain empty until a UUID identifies a tenant-visible record.
Loading authority data
Not found
The identifier may be wrong, deleted, or outside this operator’s tenant boundary.
Permission required
Tunnel.HostTerminal.Start is required by the authority to preview, queue, and inspect these sessions.
Authority unavailable
No cached session, fabricated transcript, or synthetic connection state is being substituted.
Invalid authority response
Access details stay hidden until the service returns the complete governed contract.
Current host terminal request
Device —
Interactive transport not exposed
This page can prove who requested which access boundary and whether the control plane accepted it. A device-agent transport contract must report connection readiness before Fleet can honestly render an interactive shell or copyable connection command.
—
Access boundary
Governance
—
Immutable request
CLI parity
Use your configured SaaS URL and a separately supplied Firebase token. Fleet never inserts or stores credential material in this page.
——Authority activity
Loading current lifecycle evidence…
No host-terminal events are available.
Current session state is available, but lifecycle evidence could not be loaded.
New host terminal request
Preview is read-only. Queueing requires the exact unchanged target, scope, route, shell, approval, expiry, and concurrency rows.
Authority preview