The console
A tour of the console, in the order of its menu: Overview; Build; Validate; Monitor; and Settings.
Most of what the copilot knows and does lives in the console, not in your build. Your coding agent fills it in at setup and on every sync; every page here can also be changed by hand. This is the tour, in the order of the menu.
Overview
While a setup runs, Overview is the live setup panel: the thirteen steps of Set up with AI, each ticking as it finishes, the latest lines of the active step, which agent is working, and Stop. The steps that matter are ticked by what Rendel saw — the app calling in, a smoke test passing — not by the agent's word. If nothing arrives for 15 minutes, the panel says the agent is quiet; it is usually waiting for you in its window.
When the setup finishes, the app goes live by itself if its four checks pass, and Overview says Setup complete and Live. If one is still open, Overview names it, and Go live turns the live key on once it passes. Run smoke test is there for an agent that stopped before it ran one.
Once the app is live, Overview is its home, on the key the header's switch is set to:
- The last 7 days: conversations, people, grounded answers and actions completed, each against the week before.
- Needs you: what a person has to do, most urgent first — failures, drafts live devices do not have yet, keys an action is waiting for, and what your newest build added that the copilot was not told about. Each row links to the page that fixes it.
- Latest conversations, and Gaps in your content: questions answered with nothing of yours behind them.
- Health: the SDK version, when the app last called in, the last smoke test and the answer time.
Sync with code sits in the header; on a live app its proposals wait in a Sync review card, area by area, to apply or reject. See Sync with code.
Build
What the copilot can do and say. A setup or sync agent writes here; values it took from your code say where they came from, such as From AI setup · lib/theme/app_colors.dart.
Actions
What the copilot may do, in two tabs of one list: In app code (what your app registers with registerAction, as its last build reported) and On server (endpoints Rendel's server calls). Connect an API reads an address or your API's documentation and lists its endpoints to tick. Every action has a risk level, can be made stricter or switched off at once. See Connect an endpoint and Actions and risk levels.
Screens
Every screen your app registers with registerRoute, from its latest build, with a switch to stop the copilot offering one. Screens a setup agent said it wrote but no build has registered yet are listed as planned. See Screens.
Knowledge
What the copilot answers from: links Rendel reads, texts, and files. Only a source marked Ready can be found. Test retrieval runs the same search a real turn runs and shows each passage's score. See Knowledge grounding.
Experience and Appearance
Experience is who the assistant is: its one name, tone, rules, the topics it won't discuss, the languages it answers in, and the welcome screen — headline, line and suggestions. Appearance is how it looks: colours for light and dark, corners, type, card styles and the logo. Values a setup agent took from your code are marked with where they came from, such as From AI setup · lib/theme/app_colors.dart.
Both work the same way. Saving writes a draft, which your test key uses at once. Your users see it only after you press Publish, and every published version can be restored. A setup agent only ever writes drafts. See Change the look without shipping a build and Write the persona.
Validate
Test
A real conversation on your test key, drawn as answer pages the way the SDKs draw them. When the copilot calls a handler that lives in your app, the page asks you for its result.
Talk as picks who is asking, so actions that run as the signed-in user run for real. Create a test user signs a new user up through your app's own sign-up, with a made-up rendel-test+…@test.rendel.ai address, and talks as them at once. It is offered when your API document, or what the setup agent reported, has a sign-up and a password sign-in. You can also add an existing account, or paste a token when sign-in goes through Google, Apple or SSO. See Use the signed-in user.
To watch a real build of your app instead, pair it with the console.
Conversations
Every conversation on the key the header is set to, with each answer as the user saw it, the actions it ran and whether it was grounded. Paste a request id into the search to land on one turn.
Monitor
Users
Everyone who has talked to your copilot, with every conversation they have had. A person named with identify appears under your id for them; anyone else is an anonymous device.
Improve
What the copilot could not do, with the fix for each. Read it weekly; it is your backlog. See Improve answers.
- Knowledge gaps: questions it answered with nothing of yours behind it, said it could not do, or got a thumbs-down on, grouped by what they share. Each comes with a few likely answers drawn from your knowledge, persona and app. Tap one, or type the answer in a few words, and the console writes a knowledge source from it and indexes it. Not something we answer puts a topic away.
- Failing actions: calls that failed or timed out, grouped by action and error. An endpoint connected in the console can often be fixed there. One in your app's code gets a prompt for your coding agent, with the action, its parameters, the error and the calls that failed, in the same first-person style as the setup prompt.
Analytics
Turns, grounded answers, ratings and actions over a window you pick, on the test or live key, and broken down by persona version, so you can see whether an edit to the persona helped.
Settings
Grouped by whose they are: this app's, the organization's, and the record of what happened.
Keys & environments
The test and live keys, each with what it reaches and its rotation. Rotating issues the new key at once and keeps the old one working for seven days on live, one day on test.
Security
Allowed domains: the websites the web SDK may run on. A browser request from any other origin is refused (a test key also answers on localhost); the mobile SDK is unaffected.
Request verification: Generate identity secret creates the secret your server signs user ids with (see Sign-in and identity). Require a verified identity refuses a turn that names a user without a valid signature. Record confirmations on the server has the device report each Confirm tap before your handler runs, and only a tap the server recorded counts (see Security).
Both switches are off until you turn them on, and only an owner can change them.
Handoff & files
Contact channels: Up to six ways to reach a person: a phone line, an email address or a help page, each with a label and optional hours. The copilot is shown this list and nothing else, and the server checks every contact block against it. An app with no channels is never offered the block. The copilot never chats on a person's behalf or promises one is coming.
Files in forms: Off by default. When it is on, a form may include an upload field for photos or documents, up to 20 MB each. The copilot still never asks for a photo of an ID card, a passport or a bank card, and a form asking for a password or a card number is refused whatever this switch says.
AI setup sessions
Every setup and sync session on this app: who started it, which agent claimed it, how it ended, the agent's summary and the to-dos it left you. A running session can be cancelled here; its token stops working at the agent's next request. Each change an agent made is also in the audit log, under its session rather than under the person who started it.
Members & roles
Five roles: owner, admin, developer, analyst and support. An analyst sees aggregate numbers only: no transcripts, no keys, no writes. Any member can be limited to named apps.
Data & privacy
How long this app's conversations are kept before a nightly job deletes them. Changing it is an owner's call.
Erase one user deletes one person's conversations (with their messages and rating answers), the notes the copilot kept about them, and their user record. It cannot be undone, and only an owner can do it.