Selected for the next certification batch. Live verification has not yet started. The page shows what we intend to investigate, not what we already read.
Intended capabilities
What we want to monitor
Documentation feasibility verdict: NEEDS_LIVE_TEST. OAuth project:viewer is the preferred read role and serviceInstanceLimits is an exact documented GraphQL query. CLI metrics cover CPU, memory, network, and volume history, but exact remote GraphQL metric and cost queries still require authenticated introspection. Project tokens are operational, not read-only.
How to connect
Connection model
Auth
OAuth (recommended)(not yet verified)
Read-only scopes. We request the minimum needed to read usage and plan information. You can revoke from the provider app settings at any time.
Boundaries
Plan, usage, and limits (the data you see in the dashboard)
Account or organization name (so you can pick the right one)
×Database rows, customer data, application source, env vars
×Anything write or admin scoped
Capability manifest
What BeforeRed can read
Every capability reflects the real state of the provider. The V0 reconciliation harness (PRD §9) is the only thing that promotes a capability to certified.
Authentication
BeforeRed can connect to the provider at all.
Supported
OAuth
OAuth is available, with a documented flow.
Supported
Account discovery
BeforeRed can list the user's account or organization.
Supported
Project discovery
BeforeRed can pick a specific project or service to monitor.
Supported
Plan detection
BeforeRed can read which plan you are on.
Under verification
Free-plan support
Useful signal is available on the Free / Hobby tier.
Under verification
Usage monitoring
Current usage values for the metrics you care about.
Under verification
Historical usage
BeforeRed can read past values, not only current usage.
Under verification
Limit retrieval
BeforeRed can read the currently applicable limit.
Supported
Cost monitoring
Spending can be attributed to specific projects or services.
Not available
Token refresh
OAuth tokens are refreshed automatically without re-auth.
Supported
Disconnect
The user can revoke access from the provider side and we know.