Pages
Integrations — Ideas

Source: qdash /integrations — c61 design-pass concepts, 2026-08-08

The page's honest live/projected split is a genuine asset — rare in the category — but it currently reads as an apology rather than a roadmap. Four concepts against the Meridian world (148,912 events ingested · 34 agents · 9 findings, 2 high · 1 undecided egress destination). Ideas 1–3 are buildable on today's data model; idea 4 designs the moment projected becomes live, and is labeled accordingly.

Idea 1

The honest directory

Everything the page knows, in one table: inbound and outbound, live and projected, each row carrying its status, its real volume, and its freshness. The loopback promise stops being a footnote and becomes the page's first object — a ledger you can check, not a sentence you have to trust. Fixes the live/projected contradiction (PagerDuty and Slack appear exactly once).

In — qcontrol stream
148,912 events
live · last event 4s ago
Out — your downloads
2 exports
findings CSV · SOC 2 packet · Sat
Out — network
0 bytes
qdash binds 127.0.0.1 — verified, not promised
ConnectorStatusCarries / would carryFreshnessAction
qcqcontrol event stream
Telemetry · inbound
live148,912 events · 34 agents · 412 sessions · 9 MCP serverslast event 4s ago
Findings export
Local export · on demand
live9 findings · JSON / CSV · client-side downloadlast export Sat 11:27
Security packet
Local export · on demand
liveSOC 2 evidence · 41 controls · 87% coveragelast packet Sat 11:27
PdPagerDuty
Alerting · outbound
routingroutes high — would have paged 2× this weekrules saved Mon 09:40
SlSlack
Alerting · outbound
routingroutes high + medium — 7 messages this weekrules saved Mon 09:40
@Email digest
Alerting · outbound
routingroutes low + info — 1 digest · 30 itemsrules saved Mon 09:40
SpSplunk
SIEM · outbound
projectedwould stream 148,912 events + 9 findings · HEC JSON / OCSF 2004
MSMicrosoft Sentinel
SIEM · outbound
projectedwould stream 9 findings + 7 egress destinations · Log Analytics DCR
S3Amazon S3 (Iceberg)
Evidence · outbound
projectedwould archive 148,912 append-only events · OCSF → Parquet
SfSnowflake
Evidence · outbound
projectedwould land 9 findings for GRC analytics
OkOkta / Entra ID
Identity · join
projectedwould verify 14 observed identities against your IdP
JiJira
Ticketing · outbound
projectedwould open tickets for 9 findings · issue + ADF
status vocabulary: live = moving data now · routing = rules authored here, delivery projected · projected = quantified from local volume, not wired · "would carry" numbers are the same computations the current page already does
Idea 2

The connector shelf

The same truth at marketplace scale: a filterable card grid, live connectors first, every projected card quantified by what it would carry today. The category filter is the buyer's checklist — a SOC analyst goes straight to SIEM, GRC to Evidence. The request tile turns the roster's gaps into a signal instead of a dead end.

qcqcontrol event streamlive
148,912 events · 34 agents · 412 sessions · 9 MCP servers
Telemetry
PdPagerDutyrouting
routes high — would have paged 2× this week
Alerting
SlSlackrouting
routes high + medium — 7 messages this week
Alerting
SpSplunkprojected
would stream 148,912 events + 9 findings · HEC JSON / OCSF 2004
SIEM
MSMicrosoft Sentinelprojected
would stream 9 findings + 7 egress destinations · Log Analytics DCR
SIEM
S3Amazon S3 (Iceberg)projected
would archive 148,912 append-only events · OCSF → Parquet
Evidence
OkOkta / Entra IDprojected
would verify 14 observed identities against your IdP
Identity
JiJiraprojected
would open tickets for 9 findings · issue + ADF
Ticketing
Don't see yours?Tell us what your evidence needs to land in.
sort: live → routing → projected · marks are monogram placeholders — real brand assets are a follow-up (the layer has no third-party logo set)
Idea 3

The routing console

The page's one real write path, promoted to the hero and inverted: severities as rows (with this week's real counts), destinations as columns with status, a test-send, and a disable path — the three affordances the current chip table lacks. The preview strip answers "what would this configuration have actually done this week?" before anything is wired.

This week
PagerDuty
not wired — dry-run
on
Slack #sec-alerts
not wired — dry-run
on
Email digest
not wired — dry-run
off
high2 this week
medium5 this week
low11 this week
info19 this week
This config, this week:2 PagerDuty pages7 Slack messages1 email digest · 30 itemsreplayed against the local event log — nothing was sent
shown configured; delivery today is projected · adds to the API: a disable path (today's /api/channels can only write enabled: true), a test-send, and a failure surface — save errors are currently swallowed silently
Idea 4

Projected → live

projected

The aspirational page: connectors split into configured and available, each configured card carrying real health, and the connect flow itself designed — because the moment a card flips from projected to live is the moment the product crosses from visibility tool to enterprise fixture. Splunk is drawn mid-crossing.

Configured — 2
SlSlack meridian.slack.com · #sec-alertshealthy
7 messages this week · last delivery 2m ago
PdPagerDuty Events API v2needs attention
routing key rejected since Fri 16:02 — 2 pages queued, not delivered
Connecting — Splunk
1 Credentials
HEC endpoint
https://splunk.meridian.dev:8088
Token
••••••••-••••-4f2a
stored in local SQLite — never leaves this machine
2 What it carries
Findings 9 now · OCSF 2004 Events ~2.1k/day · HEC JSON Evidence packets on export
counts are your real local volume — the same numbers the projected card showed
3 Verify
✓ test event accepted · HTTP 200 · 84ms · index=meridian_sec
dry-run keeps computing "would carry" — the honest state remains a first-class choice
Every connector lives on one ribbon:projectedconfigured · dry-runliveand can move left again — disconnect returns it to projected with its numbers intact
projected — requires outbound delivery, credential storage, and health checks that don't exist yet · designed so the loopback promise survives: dry-run is a destination, not a limbo
Coda

The composed page

A is buildable this cycle: ledger, directory, routing console. B is the page after outbound delivery ships. The lifecycle ribbon is the bridge — the same vocabulary (projected · dry-run · live) reads truthfully in both worlds, so the page never has to walk anything back.

A — the honest console (buildable now)
1
Loopback ledger — in · your exports · network out: 0 bytes
new
2
The directory — idea 1 — one table, one status vocabulary
new
3
Routing console — idea 3 — severity-major, test + disable
new
4
Request a connector — roster gaps become signal
new
5
Local-store footnote — kept — DB size, append-only claim
kept
B — after delivery ships
1
Configured, with health — idea 4 — real status, queued-not-delivered
new
2
Available shelf — idea 2 — filterable, quantified tiles
new
3
Connect flow — credentials → scope → verify → go live / dry-run
new
4
Loopback ledger — kept — now it counts what does leave, and why
kept
5
Lifecycle ribbon — projected · dry-run · live — one vocabulary
new

Qpoint Brand Style Guide