Sheet SYN-03 — Network Operations Manual
Actions, Traffic & Reporting
Governed actions and journeys with approval gates, traffic visibility from flow export, and scheduled report delivery.
What this area covers
Seeing the estate is half the job; changing it safely is the other half. This area covers the governed action catalog and journey automation, the approval inbox that gates risky work, the traffic picture built from flow export, and the reporting layer that delivers all of it on a schedule.
Operational areas in scope
| Area | What operators need from it | Why it matters |
|---|---|---|
| Action catalog | Every governed action listed with a risk class and its required permission | An operator should know what an action can do before running it |
| Journeys | Multi-step automation with schedules, scope, and write-time validation | Repeatable work should be defined once and inspected every run |
| Approval gates | Device-write plans always wait for an approver; approving and executing are separate acts | Nobody should be able to approve their own risky change into execution |
| Run evidence | A step timeline with per-step status, results, and live configuration diffs | Automation you cannot inspect is automation you cannot trust |
| Traffic visibility | Who talked to whom and how much, from flow export the network gear already emits | Bandwidth questions should not require installing agents anywhere |
| Scheduled reporting | Recurring CSV and presentation-deck delivery to named recipients | Evidence that arrives on its own gets read; evidence you must fetch does not |
What operators are actually managing
- Decide which journeys run on a schedule, with what scope, and which require approval.
- Work the approval inbox: review the full plan and parameters, then approve or reject.
- Map flow exporters to sites so traffic history lands where the team will look for it.
- Keep signed export endpoints current so downstream systems receive verified data.
- Maintain report schedules so the right people get scores, roadmap, and compliance summaries without asking.
What this public manual area includes
- The on-site collector, configuration backup, and configuration change evidence.
- Traffic visibility: the dashboard, exporter mapping, and collector setup.
- Governed actions, journeys, the approval inbox, and signed webhook exports.
- Reporting: exports, schedules, and tenant-branded decks.
What healthy operation looks like
- Risky change flows through the gate quickly enough that nobody routes around it.
- Every run leaves a step-by-step record, including the configuration diff for device changes.
- The traffic dashboard answers bandwidth questions before anyone starts a packet capture.
- Reports arrive on schedule and match what the dashboards show, because they are computed the same way.