slug: tessell provider: Tessell generated_by: planning/capability-mapping/scripts/classify_capabilities.py model: claude-opus-5 frame: - Software & Technology min_confidence: 0.7 capability_model: source: https://github.com/vincentmakes/turbo-ea-capabilities license: CC-BY-4.0 attribution: Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0 notice: NOTICE edge_count: 33 edges: - tag: Users spec_file: tessell-users-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.85 evidence: POST /iam/users/invite-user inviteUser; POST /iam/users/login; forceResetPassword; refreshToken; schemas MfaVerificationPayload, UserPersonaDTO, UserAccessControlFlags reason: 'Under /iam: user invitation, login/logout, password reset, MFA verification and access-control flags — plainly identity and access management, not HR employee records.' - tag: azure-netapp-admin-controller spec_file: tessell-azure-netapp-admin-controller-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.85 evidence: POST /storages/governance/azure-netapp/register registerAzureNetApp Register Azure NetApp if not already registered; GET /storages/governance/azure-netapp/quotas reason: Discovery, registration and quota management of Azure NetApp storage accounts and capacity pools — cloud storage infrastructure management. - tag: Compute Resource spec_file: tessell-compute-resource-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '"Resize a Database Server Compute Resource"; "Starts Database Server Compute Resource"; "Delete a Database Server"' reason: Lifecycle operations (create/read/update/delete, start/stop, resize) over database server compute resources — squarely compute/infrastructure provisioning and operation. - tag: DB Service spec_file: tessell-db-service-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: '"POST /services provisionTessellService Provision a DB service"; "Resize DB service storage/compute"; "Switchover a DB Service"' reason: Core provisioning and lifecycle management of managed database services (provision, start/stop, resize, switchover) — database/cloud infrastructure management. 'Service' here means a database instance, not a customer service capability. - tag: DB Service ACL spec_file: tessell-db-service-acl-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.8 evidence: '"Create or update the DB Service ACLs"; "Revoke DB Service ACLs"; "Get list of all the users by privileges for the given DB Service"' reason: 'Purely access-control operations: granting, updating and revoking user privileges on a database service — identity and access management.' - tag: Identity Providers spec_file: tessell-identity-providers-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.8 evidence: '''Create a new integration with an Identity Provider''; ''Get a list of integrated Identity Providers''; schema IdentityProviderType' reason: Configuration of federated identity providers for the platform is squarely Identity & Access Management (federation/SSO). Some ambiguity with tenant identity federation framing, hence 0.8. - tag: Metering spec_file: tessell-metering-api-openapi.yml capability_id: BC-4250 capability_id_l1: BC-4250 capability_name: Subscription Billing & Revenue Management confidence: 0.8 evidence: GET /billing/meters getMeteringData; POST /billing/bills generateBill; GET /billing/rates getRates; GET /billing/credits reason: Consumption metering, rate cards, bill generation, credits and billing profile are squarely subscription/usage billing and revenue management. Spans metering, rating and invoicing so no single L2 is claimed. - tag: Privileges spec_file: tessell-privileges-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.8 evidence: POST /iam/i/privileges createPrivilege 'Create a privilege'; schema PrivilegeCreatePayload reason: CRUD over IAM privileges is plainly access-rights administration under Identity & Access Management. - tag: VPC Governance spec_file: tessell-vpc-governance-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: POST /network/governance/vpcs createVpcGovernance Create a VPC; GET /network/governance/vpcs/{name}/acls Get ACL (Access Control List) of a VPC reason: Operations provision and govern cloud VPC networks, subnets and ACLs — cloud network infrastructure management. Not a business-domain capability; ACL bits are secondary to infrastructure provisioning. - tag: VPC Peering Governance spec_file: tessell-vpc-peering-governance-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: POST /network/governance/vpc/{vpcName}/vpc-peerings createVpcPeeringGovernance Create a Peering between VPCs reason: Creation and deletion of cloud VPC peering connections is network infrastructure management (compute/storage/network/cloud infrastructure). - tag: azure-netapp-service-controller spec_file: tessell-azure-netapp-service-controller-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.8 evidence: GET /storages/azure-netapp getAzureNetAppsConsumerResponse Get Azure NetApp(s) available for Provisioning DB services reason: Lists cloud storage capacity pools available for provisioning database services — storage/cloud infrastructure management. - tag: exadata-infrastructure spec_file: tessell-exadata-infrastructure-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.78 evidence: GET /infrastructures/exadata/infrastructures getExadataInfrastructures; POST /infrastructures/exadata/infrastructures/register registerExadataInfrastructure; ExadataVMCluster, TessellDbserverComputeResourceDTO reason: Operations discover, register, sync and deregister Exadata infrastructure and VM clusters, plus cluster metrics — management of compute/storage infrastructure estate, i.e. IT Infrastructure Management. No business-domain reading fits. - tag: fsx-netapp-admin-controller spec_file: tessell-fsx-netapp-admin-controller-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.78 evidence: registerFsxNetApp Register FSx NetApp if not already registered; discoverFsxNetAppSvms Discover Storage Virtual Machine(s) for a FSx NetApp reason: Registration, discovery, credential update and metrics for AWS FSx NetApp storage filesystems and storage virtual machines — cloud storage infrastructure administration. 'governance' in the path is administrative scoping, not corporate governance. - tag: security-profiles-acls spec_file: tessell-security-profiles-acls-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.78 evidence: updateSecurityProfileAcls Create or update the Security Profile ACLs; revokeSecurityProfileAcls; getPrivilegedUsersForSecurityProfile Get eligible users for a Security Profile reason: Granting and revoking access control lists for users against security profiles, including privileged-user eligibility — this is identity and access management over platform resources. - tag: tessell-compute-resource-acl-controller spec_file: tessell-tessell-compute-resource-acl-controller-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.78 evidence: updateDbServerAcls Create or update the DB Server ACLs; getPrivilegedUsersForDbServer Get eligible users for a DB Server; Bulk share multiple DB Servers with multiple users reason: Grant, revoke and bulk share of access rights over database servers to users, including privileged-user listing — identity and access management over infrastructure resources. - tag: DB Profile ACLs spec_file: tessell-db-profile-acls-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.75 evidence: '"Create/Update ACLs of a Parameter Profile"; "Revoke access of given users from an Options Profile"; "Get a list of all users along with role they are eligible on a Parameter Profile"' reason: Grant/revoke of user access rights and role eligibility over platform objects — access control administration, i.e. identity & access management. No business-domain reading applies. - tag: DB Service Instance spec_file: tessell-db-service-instance-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: GET /services/{id}/service-instances 'View a list of available DB Service instances'; POST .../private-link 'Create private link for instance'; schemas AwsInfraConfig, InstanceAzureNetAppConfig reason: Operations manage cloud database service instances and their network/private-link connectivity — provisioning and stewardship of compute/storage/network infrastructure, i.e. IT Infrastructure Management. Not a business-domain capability despite 'Service' in the tag. - tag: Personas spec_file: tessell-personas-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.75 evidence: POST /iam/personas createPersona 'Create a new Persona'; schemas PrivilegeDTO, PersonaStatus under /iam/ reason: Despite the marketing-sounding word 'persona', these are IAM entities bundling privileges under /iam/ — access role definition, i.e. identity and access management, not customer segmentation. - tag: Roles spec_file: tessell-roles-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.75 evidence: GET /iam/roles getRoles 'Get a list of Roles'; schemas RoleResponse, PermissionResponse reason: Role and permission listing under /iam/ is role-based access control, i.e. Identity & Access Management; only a read operation, so slightly reduced confidence. - tag: alert-controller spec_file: tessell-alert-controller-api-openapi.yml capability_id: BC-4220.20 capability_id_l1: BC-4220 capability_name: Observability Management confidence: 0.75 evidence: POST /monitoring/alert-profiles createAlertProfile; GET /monitoring/alert-policy getAlertPolicies reason: Monitoring alert profiles, entities and policies for the running database service — observability/monitoring configuration, not financial-crime or business alerting. - tag: cloud-resource spec_file: tessell-cloud-resource-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.75 evidence: GET /tenant-infra/dp-network-rules getNetworkOutboundAccessRules Get details of outbound access requests from the vpc / vnet reason: Tenant infrastructure network rules and private endpoint enablement — cloud network infrastructure configuration. - tag: VPC spec_file: tessell-vpc-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.72 evidence: GET /network/vpcs getVpcs 'Get a list of VPCs'; getDefaultVpcConfig 'Get Default VPC Configuration'; schemas SubnetConfigurations, VpcEndpoint reason: Reads of cloud VPCs, subnets and endpoints under /network — network infrastructure configuration, i.e. IT infrastructure management. - tag: security-profiles spec_file: tessell-security-profiles-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.72 evidence: POST /security-config/security-profiles createSecurityProfile; addSecurityProfileRule Add rule to a Security Profile; IpRangeSourceOps, AwsRuleSourceOps reason: Lifecycle of security profiles and their network access rules (IP ranges, cloud rule sources) applied to database servers — security control configuration. L1 Cybersecurity is clear; the evidence does not cleanly pick between access management and security architecture, so no L2. - tag: Compute spec_file: tessell-compute-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '"GET /compute-service/computes getComputeProfiles Get a list of Compute Profiles."; "Get all available vcpus, even if some are disabled for an user"' reason: Read-only catalogue of compute profiles and vCPU availability used to size database infrastructure — this is compute/cloud infrastructure management, not a business-domain capability. No industry-specific reading fits. - tag: Database spec_file: tessell-database-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: '''Create a new database in a DB service''; ''Starts a database in the DB Service''; ''Clone a PDB from native backup to an existing Oracle service''' reason: Lifecycle administration of database instances (create, start, stop, clone) is database/infrastructure administration, not a business data-governance capability. - tag: Encryption Key spec_file: tessell-encryptionkey-api-openapi.yml reanchored_from: tessell-encryption-key-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '''Creates new encryption key''; ''Disable Encryption Key''; ''Creates/updates encryption key acls''' reason: Cryptographic key lifecycle and key access control is a security control capability. Sits between IAM and security architecture, so only the L1 Cybersecurity Management is asserted. - tag: EncryptionKeysAdminView spec_file: tessell-encryptionkeysadminview-api-openapi.yml capability_id: BC-620 capability_id_l1: BC-620 capability_name: Cybersecurity Management confidence: 0.7 evidence: '''Validate encryption key permissions for a key''; ''Get the encryption key policy''; ''Register Encryption Key from a BYOA Subscription''' reason: Administration, registration and policy validation of customer-managed encryption keys — a security control capability. L2 left unset as it spans key governance and access control. - tag: Genie spec_file: tessell-genie-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: '''Request access to VMs of a specific ÐB_SERVICE''; ''Extend Genie expiry time''; schemas GenieForceRevokePayload, AuthenticationMethod' reason: Time-bounded, revocable elevated access to database VMs is privileged access management, a sub-capability of Identity & Access Management. - tag: Payment spec_file: tessell-payment-api-openapi.yml capability_id: BC-4250.40 capability_id_l1: BC-4250 capability_name: Payment Collection & Dunning confidence: 0.7 evidence: POST /billing/payments createPaymentOptionRequest; GET /billing/payments/default getDefaultPaymentOption; schema TessellCardDTO reason: Payment-method (card) management plus invoice retrieval for the platform's own billing — payment collection within subscription billing. Some overlap with invoicing L2, so confidence moderate. - tag: Snapshot and Backup spec_file: tessell-snapshot-and-backup-api-openapi.yml capability_id: BC-4220.60 capability_id_l1: BC-4220 capability_name: Disaster Recovery & Resilience confidence: 0.7 evidence: createDatabaseSnapshotRequest 'Submit a request to capture the associated DB Service's snapshot'; 'View a list of available Tessell Backups'; getBackupRestoreInfo 'Get the restore or clone information for the specified snapshot or the recovery-timestamp' reason: Operations create, list, delete and restore database snapshots/backups with RPO policy schemas — backup and restore of the running service, i.e. disaster recovery & resilience. Could also be framed as generic IT/DR management, so not maximal confidence. - tag: Userpool spec_file: tessell-userpool-api-openapi.yml capability_id: BC-620.20 capability_id_l1: BC-620 capability_name: Identity & Access Management confidence: 0.7 evidence: GET /iam/i/userpools getUserpools 'Get list of all the userpools'; createUserpool; schemas UserpoolDTO, UserpoolType, IamApiResponse reason: CRUD over IAM user pools — containers for user identities — which is identity and access management infrastructure. - tag: fsx-netapp-service-controller spec_file: tessell-fsx-netapp-service-controller-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: GET /storages/fsx-netapp getFsxNetAppsConsumerResponse Get FSx NetApp(s) available for Provisioning DB services reason: Single read operation listing storage filesystems available for provisioning database services — a storage infrastructure inventory view. Thin surface, so moderate confidence. - tag: tessell-cloud-controller spec_file: tessell-tessell-cloud-controller-api-openapi.yml capability_id: BC-600.50 capability_id_l1: BC-600 capability_name: IT Infrastructure Management confidence: 0.7 evidence: GET /clouds getClouds Get a list of enabled clouds in Tessell; POST /clouds addCloud Add a cloud in Tessell reason: Enabling and listing cloud providers for the platform — registration of cloud infrastructure targets. Small surface, so moderate confidence.