Skip to main content

Feature inventory

Every capability the platform ships, module by module, with the screen each one lives on.

How this list was assembled​

The scope came from reconciling two sources: the Conflux product modules - API Gateway, Security, Developer Portal, Lifecycle & Governance, Analytics & Monitoring, plus the integration framework - and the domain model a mature API management platform actually uses, which is where revisions, API products, environment groups, the policy catalogue, monetization and the newer AI-gateway policies come from.

Every row below is implemented end to end: a database table, a service, a permission-gated REST endpoint and a console screen.

1 · API Gateway​

FeatureWhat it doesWhere
API proxiesThe programmable façade in front of a backend: base path, version, protocol, auth scheme, tags, owner, portal visibility.Proxies
Multi-protocolREST, SOAP, GraphQL, gRPC and WebSocket proxies.Proxies
RevisionsImmutable configuration snapshots. Editing a deployed proxy cuts a new revision instead of mutating what serves traffic.Proxy → Revisions
RoutesPer-route method, path, upstream rewrite, target, conditional routing, timeout, retries and edge caching.Proxy → Routes
Target serversNamed backends per environment, with connection pool, timeouts, weight and health probe.Target servers
Progressive deliveryDirect, canary, blue-green and weighted strategies, with a traffic editor that enforces a 100% total.Deployments
One-click rollbackRestores the previous revision at full weight and records what it was rolled back from.Deployments
Resilience policiesCircuit breaker, retry with backoff, timeout and concurrent-connection limits, per route.Proxy → Policies
Transformation engineAssign Message, Extract Variables, URL rewrite, JSON↔XML, XSL transform, HTTP modifier.Proxy → Policies
PerformanceResponse cache, lookup/populate/invalidate cache, compression, CORS, payload ceiling.Proxy → Policies
Configuration exportPortable JSON bundle of a revision - routes plus resolved policy config - for GitOps promotion.Proxy → Overview
EnvironmentsDev, test, staging and production, each with provider, region, deployment model and approval gate.Environments
Environment groupsBind external hostnames to environments, with a TLS certificate reference.Environments → Hostname routing

2 · Security​

FeatureWhat it doesWhere
Policy catalogue54 built-in types across five categories, each with a field schema that drives its configuration form.Policy reference
Authentication policiesOAuth 2.0 (four grant types), OpenID Connect, JWT verify/generate/decode, API key, SAML, mutual TLS, LDAP / AD, HTTP Basic, HMAC.Policies
Authorization77 fine-grained permission codes across 8 roles, enforced on every endpoint; scope and claims checks available as policy config.Roles
Threat protectionJSON and XML threat protection, regex protection for SQLi and XSS, bot and abuse detection, data masking.Policies
Rate limiting & quotasQuota per app, developer, IP or product; spike arrest; concurrent rate limit.Policies
Access controlIP allow/deny by CIDR, and geographic allow/deny by country.Policies
Credential lifecycleIssue, rotate with a grace period, revoke, and a separately audited reveal. Secrets never appear in a list response.App detail
Policy templatesFork a catalogue entry into a reusable, pre-approved org template, then attach it by name.Policies
Policy pipeline editorAttach, order, condition, enable and configure policies across the five gateway flows.Proxy → Policies
Session securityServer-side sessions behind an HttpOnly cookie; a password or role change revokes them immediately.Sessions

3 · AI Gateway​

The module that makes an LLM endpoint a governed API rather than an open door - modelled on the same policy mechanics as everything else.

FeatureWhat it does
LLM token quotaMeters prompt and completion tokens per consumer over a billing interval.
Prompt token limitRejects or truncates prompts above a token ceiling before they reach the model.
Prompt sanitisationScreens inbound prompts for injection, jailbreaks, PII, secrets and toxicity.
Response sanitisationScreens model output for leaked data, unsafe content and hallucinated links.
Semantic cachingReturns a cached completion when an incoming prompt is semantically similar; populate stores the pair with its embedding.
Model routerRoutes LLM traffic across providers by weight, lowest cost, lowest latency or failover.
Token analyticsPrompt and completion consumption per API and per consumer, on the traffic dashboard and in the ai report.

4 · Developer Portal​

FeatureWhat it doesWhere
API catalogSearchable, tag-filtered product catalog with per-product access rules enforced server-side.Portal
OpenAPI renderingPublished specifications rendered as a browsable operation list with methods, paths, summaries and response codes.Portal product
Specification versioningMultiple spec versions per proxy with a changelog; exactly one published at a time.Proxy → Specification
Spec generationDerives a starter OpenAPI 3 document from a proxy’s routes and auth scheme.Proxy → Specification
Self-service credentialsRegister an app, receive a consumer key and secret, rotate and revoke.Apps
Subscription workflowRequest access; auto-approve or route to a reviewer queue with a note, quota override and decision record.Subscriptions
Consumer workspaceA consumer’s own apps, credentials, subscriptions and usage - a different landing screen from the operator dashboard.Dashboard
Portal brandingAccent colour, welcome message and self-registration toggle, driven from settings.Settings → Portal

5 · Lifecycle & Governance​

FeatureWhat it doesWhere
Six-stage pipelineDraft → review → approved → published → versioned → retired, with the legal transitions enforced server-side.Lifecycle
Approval gatesApproved, published and retired require sign-off, and the requester cannot approve their own request.Approvals
Lifecycle boardEvery API laid out by stage, so what is stuck in review is obvious.Lifecycle
Governance standards11 built-in machine-checkable rules across naming, security, documentation, versioning, resilience and observability - plus custom rules from 11 evaluator types.Standards
Blocking vs advisoryA blocking standard stops the review → approved transition until it passes or is waived.Standards
Findings & waiversPer-proxy pass/fail/waived results with remediation text; a waiver records who accepted the risk and survives re-evaluation.Standards → Findings
Compliance scoringOrg-wide score with a breakdown by category and severity.Dashboard, Standards
Production gateA production deployment requires both the permission and an approved lifecycle stage.Deployments
Immutable audit historyAppend-only trail of user activity, configuration changes and security events with before/after diffs, actor, IP and user agent.Audit trail
Audit-ready reportingFilter by category, severity, actor, entity and date range; CSV export, itself audited.Audit trail

6 · Analytics & Monitoring​

FeatureWhat it doesWhere
Real-time dashboardsRequests, error rate, latency (avg/p50/p95/p99), availability, cache hit rate, throughput and data transferred.Traffic
Time seriesAuto-bucketed by hour, day or week from the selected window, with period-over-period trend arrows.Traffic
Error analysis4xx / 5xx / policy-block split, failure trend, and worst offenders ranked by rate rather than count.Errors
Latency analysisTotal vs backend time, so gateway overhead is visible; slowest APIs by p95.Traffic
Consumer analyticsTop apps and developers, traffic share and concentration, service quality per consumer.Consumers
Geographic usageTraffic, latency and availability by country of origin and by serving region.Geography
Product analyticsWhich commercial bundle traffic arrives through.Traffic, Consumers
SLA monitoringAvailability, latency and error-rate commitments per API, product or consumer, measured against real traffic, with error-budget consumption.SLA targets
Alert rulesThresholds on seven metrics with a comparator, sustain duration and severity; global or scoped to an API or environment.Alerts
Incident managementAlert breaches open an incident with an owner; acknowledge → investigate → monitor → resolve, each step appending to a timeline.Incidents
Gateway fleetNode-level health, CPU and memory, throughput, connections, uptime and heartbeat; regional roll-up; drain for a rolling upgrade.Fleet
Custom & scheduled reportsNine report types, saved queries, on-demand run, preview, and daily/weekly/monthly schedules with recipients.Reports
Analytics exportCSV export by proxy, product, consumer, country or environment.Every analytics screen
NotificationsPer-user in-app inbox with severity, deep links, unread badge and polling.Header
Distributed tracingPolicy that propagates W3C trace context and exports spans (OTLP, Jaeger, Zipkin, Datadog).Policies
One measurement, many screens

All of these read the same hourly traffic aggregate, which is why a report, a dashboard, an SLA calculation and an invoice can never disagree about the same hour.

7 · Monetization​

FeatureWhat it doesWhere
Rate plansFree, flat-rate, pay-as-you-go, tiered and revenue-share, each with currency, billing period, fees, allowance and per-call rate.Rate plans
Volume tiersBanded pricing walked band by band at billing time.Rate plans
Prepaid & postpaidPrepaid plans hold a balance that billing draws down; postpaid are invoiced in arrears.Rate plans
Plan lifecycleDraft → published → deprecated, with subscribers blocked from unpublished plans.Rate plans
Plan subscriptionsPut a developer on a plan, top up a prepaid balance, cancel.Rate plans → Subscribers
Billing runsMeasures each subscription’s real traffic over a period, prices it against the plan and writes an invoice with line items.Billing
Revenue dashboardBilled, collected, outstanding, revenue share, monthly trend and top developers by revenue.Billing
Portal pricingPublished plans rendered as pricing cards on the catalog entry.Portal product

8 · Integration framework​

FeatureWhat it does
Connector catalogue19 prebuilt connectors, each with its own field and secret schema.
IdentityOkta, Microsoft Entra ID, Keycloak, LDAP / Active Directory.
ITSMServiceNow, Jira.
ObservabilityDatadog, Prometheus, Grafana, Splunk.
CloudAWS, Azure, Google Cloud.
CI/CDGitHub, GitLab, Azure DevOps, Jenkins.
MessagingApache Kafka, RabbitMQ.
Write-only secretsCredentials are stored and reported as set or not-set, never returned. A partial form submission keeps the stored value.
Connection testProbes a configured connector and records the result with a last-checked timestamp.
GitOps / IaCProxy revisions export as a portable JSON bundle for a repository-driven promotion flow.

9 · Platform & administration​

FeatureWhat it doesWhere
Multi-tenancyEvery artifact is scoped to an organization. A super admin may act across tenants explicitly; nobody else sees another tenant’s data.Organizations
Deployment optionsCloud, on-premise and hybrid recorded per organization and per environment, with provider and region.Organizations, Environments
UsersInvite, edit, suspend, delete, force-reset a password. A role or status change revokes sessions immediately.Users
Roles & permissions8 system roles over a 77-code catalogue, edited as a matrix. Custom roles supported; the last super admin cannot be demoted or deleted.Roles
Session managementSee and revoke your own active sessions per device.Profile
Settings30 settings across 8 groups, resolved as platform default then tenant override, with a revert action.Settings
AuthenticationSign-up, sign-in, sign-out, forgot password, reset password (revokes all sessions), change password (keeps the current device).Auth
API documentationOpenAPI 3 generated from the API itself - 164 paths, 233 operations - served as Swagger UI, including the required permission on every operation.Architecture

Out of scope, deliberately​

The data plane runtime itself, and the operational guarantees of a running deployment - availability, multi-region, zero-downtime upgrades, disaster recovery - plus commercial services such as support and training. What is implemented is the modelling and measurement of those: deployment models, regions, node health, SLA targets and error budgets. See the FAQ for the full statement.

Counts at a glance

77 permissions · 8 roles · 54 policy types · 19 connectors · 30 settings · 11 governance standards · 9 report types · 39 tables · 164 API paths · 34 console screens.

Need a hand?

Talk to an Odoo expert

Get help with setup, custom integrations and upgrades from Odoo 17 to Odoo 20 - straight from the team that builds every SDLC Corp product.

Contact support

Official documentation for SDLC Corp connectors, Odoo modules and SaaS apps.