Core Concepts
How CredVault is put together — enough to choose the right surface for the job.
Workspace and tenant
Your account belongs to a workspace (tenant). Clusters, keys, logs, billing, and team membership sit inside that boundary. Other workspaces cannot see your data.
Clusters, databases, collections, documents
CredVault is document-oriented:
- Cluster — managed database instance you create in the dashboard
- Database — namespace inside a cluster
- Collection — group of related documents (schema optional until you add rules)
- Document — JSON-like record (nested objects, arrays, dates, binary)
This maps cleanly to application objects and supports evolving fields without a rigid table migration for every change. Use schema and access rules when you need validation and least privilege.
Auth layers
| Who | How |
|---|---|
| Humans | Dashboard session (email/password, Google, GitHub) |
| Apps | API keys (X-API-Key) with environment and scopes |
| CIE / Pragma | Same CredVault account after login |
All traffic to CredVault APIs is TLS. Keys can be revoked instantly from API Keys.
CIE (Intelligence Engine)
CIE is the terminal control plane for CredVault ML and platform ops: datasets, train/deploy/predict, SQL, Vault AI, webhooks, robots, billing, watch, and doctor. Install with:
curl -fsSL https://credvault.net/install/cie | sh
See CIE CLI.
Automation
- Functions — custom logic on events, HTTP, or schedule
- Triggers — react to document changes
- Webhooks — signed callbacks to your systems
- Pipelines — longer data/ML workflows (dashboard + CIE
pipeline)
Observability
- System Monitoring — native CredVault heartbeats, dashboards, alerts (
/monitoring) - Activity Logs — audit trail (
/logs) - Billing — plan, usage, invoices (
/billing)
Workspace tools (in-product)
These open from the dashboard sidebar as CredVault product surfaces (not third-party sites you configure yourself):
| Sidebar name | What it’s for |
|---|---|
| Notebook | Interactive notebooks and interpreters |
| ML Experiments | Experiment tracking and model registry |
| Orchestration | Jobs, datasets, and workflow events |
| Lineage | Assets, runs, jobs, and dependency views |
| Metadata | Catalog, quality, governance |
| Omnigent | Governed agent sessions and policies |
| Team Management | Users, groups, roles, and directory |
They are part of CredVault. Use them in the app; these docs do not republish their internal manuals.
Pragma and Coder
- Pragma — CredVault’s native desktop ADE (agent, terminal, editor, Drive). Overview.
- Coder I/O — cloud development environment via
/coder(full-page session, not a dashboard iframe).
Same backend, three doors
Dashboard ─┐
CIE CLI ─┼─► CredVault API ─► clusters, keys, jobs, billing, logs
Pragma ─┘
Pick the door that matches the job; the data and permissions stay in one place.