Source: qdash /integrations — c61 design-pass concepts, 2026-08-08
The page's honest live/projected split is a genuine asset — rare in the category — but it currently reads as an apology rather than a roadmap. Four concepts against the Meridian world (148,912 events ingested · 34 agents · 9 findings, 2 high · 1 undecided egress destination). Ideas 1–3 are buildable on today's data model; idea 4 designs the moment projected becomes live, and is labeled accordingly.
The honest directory
Everything the page knows, in one table: inbound and outbound, live and projected, each row carrying its status, its real volume, and its freshness. The loopback promise stops being a footnote and becomes the page's first object — a ledger you can check, not a sentence you have to trust. Fixes the live/projected contradiction (PagerDuty and Slack appear exactly once).
| Connector | Status | Carries / would carry | Freshness | Action |
|---|---|---|---|---|
| qcqcontrol event stream Telemetry · inbound | live | 148,912 events · 34 agents · 412 sessions · 9 MCP servers | last event 4s ago | |
| ⤓Findings export Local export · on demand | live | 9 findings · JSON / CSV · client-side download | last export Sat 11:27 | |
| ⤓Security packet Local export · on demand | live | SOC 2 evidence · 41 controls · 87% coverage | last packet Sat 11:27 | |
| PdPagerDuty Alerting · outbound | routing | routes high — would have paged 2× this week | rules saved Mon 09:40 | |
| SlSlack Alerting · outbound | routing | routes high + medium — 7 messages this week | rules saved Mon 09:40 | |
| @Email digest Alerting · outbound | routing | routes low + info — 1 digest · 30 items | rules saved Mon 09:40 | |
| SpSplunk SIEM · outbound | projected | would stream 148,912 events + 9 findings · HEC JSON / OCSF 2004 | — | |
| MSMicrosoft Sentinel SIEM · outbound | projected | would stream 9 findings + 7 egress destinations · Log Analytics DCR | — | |
| S3Amazon S3 (Iceberg) Evidence · outbound | projected | would archive 148,912 append-only events · OCSF → Parquet | — | |
| SfSnowflake Evidence · outbound | projected | would land 9 findings for GRC analytics | — | |
| OkOkta / Entra ID Identity · join | projected | would verify 14 observed identities against your IdP | — | |
| JiJira Ticketing · outbound | projected | would open tickets for 9 findings · issue + ADF | — |
The connector shelf
The same truth at marketplace scale: a filterable card grid, live connectors first, every projected card quantified by what it would carry today. The category filter is the buyer's checklist — a SOC analyst goes straight to SIEM, GRC to Evidence. The request tile turns the roster's gaps into a signal instead of a dead end.
The routing console
The page's one real write path, promoted to the hero and inverted: severities as rows (with this week's real counts), destinations as columns with status, a test-send, and a disable path — the three affordances the current chip table lacks. The preview strip answers "what would this configuration have actually done this week?" before anything is wired.
| This week | PagerDuty not wired — dry-run on | Slack #sec-alerts not wired — dry-run on | Email digest not wired — dry-run off | |
|---|---|---|---|---|
| high2 this week | ||||
| medium5 this week | ||||
| low11 this week | ||||
| info19 this week |
Projected → live
projectedThe aspirational page: connectors split into configured and available, each configured card carrying real health, and the connect flow itself designed — because the moment a card flips from projected to live is the moment the product crosses from visibility tool to enterprise fixture. Splunk is drawn mid-crossing.
The composed page
A is buildable this cycle: ledger, directory, routing console. B is the page after outbound delivery ships. The lifecycle ribbon is the bridge — the same vocabulary (projected · dry-run · live) reads truthfully in both worlds, so the page never has to walk anything back.