---
summary: "Where to find each task in the console \u2014 realms, members, databases,\
  \ accounts and grants, backups, API tokens \u2014 and which role it needs."
title: The console
path: using/console
status: published
---

# The console

The console is at `https://scuttle.scailabs.ai`. Sign in with your ScaiLabs account. What you can
see and change depends on your role; see [Tenants, realms and names](/docs/scuttle/concepts/tenancy)
for the roles themselves.

Every change is applied in the background. A change is done only when its operation shows
**succeeded**. If an operation fails, its message says why, and **Operations** lets you retry it.

## Where things are

| Task | Where | Role needed |
|---|---|---|
| Create a realm | **Overview** → **New realm** | tenant admin |
| Rename a realm or change its description | realm → **Settings** | realm admin |
| Delete a realm | realm → **Settings** → **Delete realm** (it must be empty) | tenant admin |
| Give people access to one realm | realm → **Members** | realm admin |
| Give people access to the whole tenant | **Tenant** → **Tenant admins** | tenant admin |
| Create a database | realm → **Databases** → **New database** | operator |
| Delete a database | database → **Delete database** | operator |
| Create an account | realm → **Accounts** → **New account** | operator |
| Change an account's grants | account → **Edit grants** | operator |
| Restrict networks, set limits, lock an account | account → **Access and limits** → **Edit** | operator |
| Rotate a password | account → **Rotate password** | operator |
| Restore a database to a point in time | database → **Backups** → **Restore…** | operator |
| Download a database as SQL | database → **Backups** → **Export…** | operator |
| Erase a deleted database's backups | database → **Backups** → **Purge backups now** | tenant admin |
| Create or revoke API tokens | **Tenant** → **API tokens** | tenant admin |
| See usage | **Usage** | tenant admin |

The **Tenant** entry in the menu appears only for tenant admins.

## Realms

A realm is a namespace inside your tenant, usually one per team or environment (`prod`,
`staging`). Its slug is part of every database and account name in it
(`<tenant>_<realm>_<name>`), so **the slug cannot be changed later**. The display name and
description can be.

A realm can only be deleted when it holds no databases or accounts.

## Members

Access is granted to a **person or a group** from your ScaiLabs account directory. Search for
them by name, e-mail address or group name, and pick them from the list. Only people and groups
with access to Scuttle can be found.

A group grant follows the group: people who join it get access, and people who leave lose it.
Changes take effect at the person's next sign-in.

| Grant | Scope |
|---|---|
| realm **viewer**, **operator** or **admin** | one realm (realm → **Members**) |
| **tenant admin** | every realm, plus realms, tokens and usage (**Tenant** page) |

## Accounts and grants

An account is a MariaDB login. Its access is a list of **grants**, each a *profile* on a
*scope*:

- **Scope:** one database, or the whole realm. A realm-scope grant also covers databases created
  in the realm later.
- **Profile:** `readwrite` (applications), `readonly` (reporting) or `dba` (migrations and
  schema owners).

You never pick individual privileges. The profiles are listed in
[Tenants, realms and names](/docs/scuttle/concepts/tenancy).

Saving grants **replaces the account's whole grant list** with what you see in the editor. To
take something away, remove its row and save.

Under **Access and limits** you can:
- restrict the source networks (CIDR, one per line; empty means anywhere);
- change the connection limit and the maximum statement time;
- **lock** the account, which refuses new logins but doesn't end sessions that are already open.

Passwords are shown **once**, when an account is created or its password is rotated. Scuttle
doesn't store them, so copy the password before closing the dialog.

## Deleting a database

A deleted database is kept for a grace period (14 days by default) before it's dropped. Its
name stays taken until then. Its backups remain restorable for their own retention window.

A database can't be deleted while an account still has a grant on it. Remove those grants first.

## Backups

Every database is backed up continuously, encrypted, in another region. The **Backups** section
of a database shows:

- **The restorable window:** from the oldest point your retention covers, up to the latest
  backed-up change. That is usually within 15 minutes of now.
- **The backups behind it:**
  - **Full dump** — the first backup;
  - **Rolled forward** — refreshed weekly;
  - **Monthly check** — a real dump compared with the rest. "matches the cluster" means the
    check passed.

**Restore…** rebuilds the database as it was at a moment you choose, into a **new** database in
the same realm. The original is never touched.
- Times are entered in your local time.
- Afterwards the console shows the exact moment the restore reached. It can be a few seconds
  earlier than you asked, because it stops at the last change committed at or before your time.
- A restored database may have one more index than the original: an index MariaDB would have
  dropped by itself on the original. It's harmless.

**Export…** produces a plain `.sql.gz` of the database at a moment you choose. It's built from
the backups, so it adds no load to your database. The download link works for 24 hours. The
file names no database, so you can import it under any name.

**Purge backups now** appears on deleted databases only. It erases their backups immediately
instead of letting them age out, for example for an erasure request. This can't be undone. The
result states what could not be erased at once: shared replication logs expire within 7 days.

## API tokens

`sct_…` tokens let scripts and CI use the [API](/docs/scuttle/reference/api) without signing in.
- **Role:** each token carries one role and can be limited to one realm.
- **Expiry:** optional.
- **Storage:** only a hash is stored. The token is shown once, when you create it.
- **Revoking:** takes effect immediately.
