Deployment detail
For administrators looking after a Studio deployment, and the identity administrator setting up sign-in for an unlinked one. Viewers read every view; retention, pause, resume and delete need the Owner or Operator tier or the DeploymentOperator Role.
Before you start: open Fleet and click a deployment. It opens on Overview; View also offers Jobs (Jobs, progress and failures), Identity and Health and Analytics.
Read the header
Every view shares Name (the name you typed, with the app domain beneath), Deployment ID, Account, Version and Status (the Fleet's values; " (stale)" after 15 minutes without a health check) and three actions, each confirmed with the deployment's name. While a job runs the Overview re-reads every 15 seconds; an unknown id shows "No deployment with this id" and Back to Fleet. Pause stops every task and sign-in until you Resume; nothing is deleted. Delete starts an uninstall (Deleting a deployment) and, when the last job failed, replaces that job. Both are disabled while a job runs.
Read Deployment details and Configuration
Deployment details shows Account, Region, Version, Licence id and Licence state; a dash means not yet recorded (wizard fields at launch, configuration fields when a reconfigure or upgrade applies them).
Configuration shows what the deployment was created with:
| Row | Values |
|---|---|
| Release channel | The channel the release came from. |
| Ownership | Standard (each user owns and sees only their own resources) or Governed (everyone assigned shares every resource and workspace file; required for Programmatic Access). |
| Deployment size, Redis node type, Sonnet model, Opus model, Inference zone, Neo4j mode, Session timeout (seconds), Environment | The running values; a size, Redis or model left blank in the wizard reads "Automatic (resolved at install)". |
| Run data retention | "N days", or "90 days (default)". |
| PII redaction default | Off, Mask or Hash; workflows and runs can tighten it, never loosen it. |
| Payload template | "Studio", or "minimal target stack (not Studio)" for a test deployment. |
Change run data retention
Change… opens Change run data retention (needs the reconfigure permission; disabled while a job runs).
- Enter a whole number of days in Run data retention (days), 1 to 3650; older run inputs and outputs are deleted automatically.
- Click Apply (enabled when the value is valid and differs from the current one). The console opens the update job in Jobs; Studio users see the update screen until it finishes.
Read Identity and Endpoints on the Overview
Identity shows the Identity provider ("<tenant> (Microsoft Entra ID)" as a link, or "none linked"), Entra app id, Pool id and SP entity id, "assigned once SSO provisioning runs" until then.
Endpoints shows the App domain, the DNS target (CNAME) your record must point at ("appears once the Edge step (8 of 14) has finished, usually 20 to 25 minutes in" before it exists; "Interim" while the distribution is still being created; none after an uninstall), the Load balancer hostname and the CloudFront front door: "Always on · waiting for the CNAME" until your record resolves to the distribution, then "Always on · origin locked". Every deployment sits behind a CloudFront distribution; its certificate is issued automatically from the one you chose; you create exactly one CNAME, app domain to DNS target.
Use the Identity view
Linked. The card reads "SSO provisioned automatically via <tenant> (Microsoft Entra ID)."; a failed attempt names the failure with View job history. Who can sign in lists every assigned person and group (Name, Type) with the seat count "N of M user(s)". Assignments change from Manage in Identity & Access Management → (Users, groups and roles), not here; a group that grew after assignment is flagged with "Remove users to return under the cap."
Not linked. Use an identity provider lists your connected tenants; click one to link it. With none, connect one first or follow the manual runbook.
Follow the manual SAML runbook
For an unlinked deployment the Identity view carries everything your Microsoft Entra administrator needs; the URL is shareable. Copy all as text and Download signing certificate (.cer) sit at the top. The strip at the top reads waiting (values fill in within about a minute), ready (the job is parked for your metadata, not failed; nothing expires for 14 days) or a problem to check on the progress page. Seven steps, each with copy buttons; the Entra clicks are on Connect your identity provider and Sign in with Entra ID:
- Create a non-gallery SAML Enterprise Application
- Paste the basic SAML configuration (Identifier, Reply URL, Sign-on URL, Logout URL)
- Set NameID to a persistent, unchanging attribute
- Add the required claims
- Upload our signing certificate (optional, but do it)
- Assign the users and groups
- Send us the App Federation Metadata URL
- A mutable NameID (email or UPN) silently duplicates users and orphans their work.
- Without the signing certificate under SAML Certificates → Verification certificates, single logout fails silently; without the Logout URL, signing out leaves the Entra session open.
Read Services and Analytics
Choose Health and Analytics in the View selector.
Services lists each service's Running and desired task counts; on a paused deployment every service is at 0, "paused, not broken".
Analytics charts token usage by period (24h, 7d default, 30d), granularity (Hourly, Daily) and split (By model, By activity): UTC buckets by turn finish, the first partial, billable prompt tokens only. The activity labels are the metering event kinds listed on What leaves your account. Export CSV downloads the buckets with user id, kind, model and the four token counts; without per-user permission it falls back to the chart's series.
User attribution lists the same rows by principal with its own Export CSV; principals are people, API keys and platform runs such as a scheduled workflow.
Read Health
Health draws CPU utilization, Memory utilization, Network in and Network out over 1h (default), 3h, 12h, 1d, 3d or 1 week, refreshing every 60 seconds. Logs: the card links to the AWS ECS console.
What you should see
- An old
/settingsaddress opens the Overview. Reconfigure means the retention change only. - No update or rollback button: updates arrive through Update Manager; Jobs lists Upgrade, Reconfigure and Rollback jobs.
- Analytics and User attribution share one period and count the same rows.
Notes
- Ownership and Environment are fixed after launch; sizing, Redis node type, models and the PII redaction default change only through a Fleet Configuration Template. The front door cannot be turned off. The DNS record is yours; the console never changes it.
- User attribution needs the Owner or Operator tier. Usage is copied from the deployment every two minutes. Health charts read your account's CloudWatch metrics through the registration role; the banner "Your account role needs updating for Health metrics to work." means re-run the account template from Accounts, then Verify.
- A blocked licence serves no turns, so a busy deployment can chart nothing.