Appearance
Bring your vendors into your house
Available now A house is your publisher workspace with your vendors in it:your own sandbox, where their systems exchange SOM messages with yours and with each other. You decide who joins, and what each of their apps may publish or receive. Everything here happens on the portal's Your house: vendors page, in your publisher workspace.
The sandbox is for synthetic test data only. Going to production is a separate step with RND.
Planning an evaluation from start to finish? Follow the publisher track.
How it works
- You invite a vendor, by email or from the vendor directory.
- The vendor joins. An owner or admin of the vendor's workspace reads the house terms and accepts them for their organisation.
- The vendor chooses which of its apps connect, and asks for what each needs: a producer app asks for
system_ids and message types; a consumer or skill app for message types (and, optionally, a topic prefix). - You grant what they asked for, or less, or reject the request with a reason. Nothing reaches your house's bus until you grant it.
- The vendor gets the connection's client secret itself. It is theirs: you never see it, and you can't rotate it.
- Either side can disconnect at any time, after seeing what is kept.
Owners and admins of your workspace invite, decide and disconnect. Developers and viewers see the page.
Invite a vendor
By email. Enter the address of the person at the vendor who should accept. The invitation:
- works once, and only for that email address: the person must sign in with it;
- expires after 14 days;
- carries a pre-approved sign-up for a vendor new to SOM Managed Bus: the email's link opens the access request form, and a request sent with it from the invited address is approved at once, on the minimal tier. RND still sees it in its approval queue. A vendor already on the bus signs in and accepts under Houses.
You can resend an open invitation (at most three emails in all; each resend replaces the sign-up link, so the old one stops working) or revoke it.
If the email can't be sent, the page tells you, and shows you the invitation's sign-up link with a copy button, so you can send it to the vendor yourself. Only you, the admin who just sent or resent it, see it, and only then: it isn't kept, and a resend makes a new one. It's the same pre-approved sign-up the email would have carried, so pass it on by a channel you trust. Once the vendor has signed up there is no link to show: they sign in and accept under Houses.
From the directory. Press Pick from the directory to see vendors that chose to be listed, with a line about what they build, and invite one by name. The invitation is shown to that vendor's owners and admins in the portal; there is no email.
Limits. A house has at most 10 open invitations at a time, and sends at most 30 invitations in 30 days. Ask RND if you need more.
Decide on a connection
A vendor's request appears under Waiting for your decision, with what it asked for. Untick anything you don't want to grant, then press Grant what's ticked. You can't grant more than the vendor asked for.
- A producer may then publish into your house as the
system_ids you granted, and only the message types you granted. Each is checked by the gateway, as for your own apps. - A consumer or skill app gets its own queue on your house's topic, receiving the message types you granted. It counts toward the workspace's limit of 50 consumer connections.
If the vendor has shared a results statement for that app with your organisation, the request shows it, so you can see what the app has passed before it goes live.
Reject instead to say no. The vendor sees your reason, and may ask again.
Disconnect a vendor
Disconnect one connection, or Remove from house to disconnect all of a vendor's connections and take the vendor out of your house. Before you confirm, the page shows what is kept:
| What | For how long |
|---|---|
| Messages already accepted, in your story timeline | Until they expire, 7 days after they were published |
| The gateway's decisions on the connection's messages | 30 days in the decision log: counts for you, detail for the vendor |
| A producer's client secret | Stops at once; its tokens within 30 seconds. The connection stays on record, revoked |
| A consumer's queue and dead-letter queue | Deleted, with any messages still in them |
| The audit log entries, yours and the vendor's | One year |
A vendor can leave your house, or disconnect its own connections, in the same way.
On Apps and credentials and Consumer connections, a vendor's connection has no Revoke and no secret actions: its credential is the vendor's. Disconnect it here instead.
Another organisation's app RND connected
RND can connect another organisation's app into your workspace directly, without a house request. It shows under Other organisations' apps RND connected here on Apps and credentials (a producer), or on Consumer connections with the organisation's name (a consumer). You can't revoke it, rotate its secret or revoke its secret: its credential is that organisation's. An owner or admin can Disconnect it instead, after reading what happens:
| What | What happens |
|---|---|
| A producer connection | Revoked: the bus refuses its client secret at once, and its tokens within 30 seconds. It stays on record, revoked |
| A consumer connection | Unsubscribed: no new messages and no tokens. Its queue, dead-letter queue and their messages are kept |
| The organisation's client secret | Not changed or deleted: it stays theirs |
| Connecting it again | The organisation asks RND |
| The audit log entries, yours and the organisation's | One year. Theirs names your organisation, never your people |
This works in any workspace, not only a house.
What you see of your vendors
Your house's pages show every connection's counts: accepted, refused, failed and duplicate messages, and when each was last seen. You never see a vendor's rule ids, refused messages or credentials: see Who sees what in a house. What each app has shown, per message family, scenario and skill case, and where the gaps are, is on the Coverage page: see Reading the coverage matrix.
When a vendor's connection goes quiet or starts failing
The bus emails your house when one of your vendors' producer connections:
- goes silent: it was sending, and has sent nothing for 12 hours (you choose 1 to 168 hours);
- comes back: it sends again after going silent;
- has too many messages refused: 25% or more of its messages in the last hour were refused (you choose 1% to 100%), counted once it has sent 20 messages in that hour.
The emails carry the connection id, the app and vendor names, and counts, never which rules refused the messages. They're the Vendor connections email under Notifications: same choice of who gets them, same unsubscribe link. Admins and owners set the hours and the percentage there. Your own connections in the house keep their usual emails, such as consumer queues and lag. Each vendor gets its own emails about its connections in your house, in its own workspace, with its own detail; you don't get those.
The house terms
What a vendor accepts when it joins, recorded with the terms version (house-2026-09):
- The house is a shared bus: messages its connected apps publish, and their payloads, reach every connection you grant them to.
- You see counts of its accepted, refused, failed and duplicate messages per connection, and when each was last seen, never its rule ids, paths or other verdict detail. A results statement it shares with you shows its test results, not these.
- Other vendors in the house see payloads, never its verdicts.
- Your consent to RND support access covers its traffic in your house.
- Its traffic in your house counts against its own allowance, never yours.
- You grant what each of its connections may publish or receive, and either side can disconnect at any time.
- The sandbox takes synthetic test data only.
Support access Available now: an owner of your house can let RND read it for up to 7 days, read-only. RND then sees what your house's viewers see, payloads in your story timeline included, and a vendor's connections as counts, as you do, never its refused messages or credentials. Without a grant, RND never sees payloads, yours or your vendors'. See Let RND look.
Quotas
Every vendor connection has its own allowance on the bus, so a vendor's traffic in your house never spends yours or its neighbours'. Its limits are the vendor's quota tier, never your house's. Your own connections get your house's tier.
Known limits
- Test runs stay in vendor workspaces: a house doesn't run them, since test messages would reach your vendors' consumers. Grade your own apps in your workbench. To see a workflow play between your vendors' systems, rehearse it: its messages are identifiable and your vendors are told.
- The Playground publishes only as your own organisation's apps, never as a vendor's connection.
- A vendor's connection uses a client secret. Its AWS role (SigV4) or its own identity provider are for connections in the vendor's own workspace for now.