Enrol workbenches
Approve the code an AI Workbench shows when it connects, see it in the fleet, and revoke it later.
A workbench joins your organisation when a signed-in person approves the code it shows. Approval binds the workbench to that person and to your organisation, and gives it its own token for everything it does from then on. Nobody types a password into the workbench, and no long-lived secret is copied between machines.
Approve a workbench
Start in the workbench
In AI Workbench, open Settings, Organisation:
Choose Mojo Up to sign in with Mojo Up AI Cloud.
The workbench shows an eight-character code, such as BCDF-2345, and opens the console's Enrol a workbench page in your browser with the code filled in.
Check what you are approving
Sign in to the console if asked. If the page did not open, open Enrol a workbench in the console's sidebar, type the code and choose Look up.
The console shows the workbench's name, its workspace, and what it will be able to do. Check that the name is the machine you are sitting at.
The page names the organisation the workbench will join: the one active in the console. To approve it into another of your teams, switch to that team at the top of the sidebar first.
Approve
Choose Approve. The workbench receives its token on its next poll, a few seconds later, and appears under Workbenches. Choose Open it to go straight to it.
Choose Deny instead if you do not recognise the workbench.
Codes expire ten minutes after the workbench shows them, and each code works once. If the console says "No workbench is waiting with that code", start again in the workbench for a new one.
Who can approve
Any signed-in person can approve their own workbench: it becomes theirs. They can see and control it from the console and the mobile app. Administrators, and in self-hosted AIOE operators, can see and control every workbench.
Nodes are different
A headless node asks to join the same way, but its code lasts 24 hours, because the person who may approve it is not always at their desk. If you look up a node's code and may approve nodes, you can Approve or Refuse it; approving makes you its sponsor. To trim what the node may offer first, approve it from Nodes, Pending instead. If you may not approve nodes, Pass to an approver puts it in front of the people who may. See Nodes.
Owners and admins approve nodes.
What an enrolled workbench does
Once approved, the workbench:
- registers with the fleet and sends a heartbeat, so Workbenches shows it online, with its workspaces;
- sends its events, usage and audit records to the organisation;
- pulls the organisation's catalogue and policy;
- keeps one outbound connection open, so the people allowed to can control it remotely.
A workbench shows offline when it stops sending heartbeats (after 90 seconds by default in self-hosted AIOE).
Revoke a workbench
Open the workbench from Workbenches and choose Revoke access. Its tokens stop working at once, and the revocation is recorded in the audit trail. The workbench's owner and administrators can revoke it. To use it with the organisation again, its owner enrols it again.