A product manager reviewing an in-product analytics chart on a laptop covered in handwritten sticky notes, a retention dip of −41% week over week on screen.

CEDX Embedded · Data & Analytics

Your product's charts,
our meter running underneath.

Embedded puts the estate's analytics inside your product — tiles, dashboards, charts, explores and answer cards — with a p75 load budget per embed, scoped guest tokens, and tenant isolation tracked as a queue, not a promise.

The over-budget table doesn't round: Checkout health report at 5.6s p75 against the 2.0s budget, score 118.9. Embeds that miss the budget are listed, not excused.

embedded.cedxsystems.com — live build
CEDX Embedded overview: live embeds, sessions per day, p75 load, active tokens, tenants and isolation cards, platform health ring, embeds by status and diagnosed alerts.

Runs on demo data — the header reads “embed lag ~1m · demo seed” on the screen itself.

235 live embedsof a 320-embed catalog, across 48 tenants
1.7s p75 loadagainst a 2.0-second budget
129 active tokensscoped, TTL'd, counted against a 220-token ledger

What it is

Charts in your product, telemetry on ours.

Every embed carries a budget

320 embeds list kind, render mode, p75 and payload: web components average 1.5s at 154 KB against the iframe's 2.0s at 378 KB. The 76 live embeds over budget are a filter chip away.

  • Render modes: iframe, web component, SDK
  • p75 and payload KB on every row
  • Answer embeds: 30 live, 63K questions in 30 days
embedded — screen-3
Every embed carries a budget

Tokens are scoped, TTL'd and ledged

220 minted tokens carry scope — read:embed, guest:view, admin:theme — plus TTL, use counts and last-used. 35 expired tokens are still receiving traffic, and that alert names the grace TTL as the cause.

  • Scopes: read:embed, read:explore, write:filter, admin:theme, guest:view
  • TTL from 15m to 240m on screen
  • Expired-but-active flagged with the cause
embedded — screen-4
Tokens are scoped, TTL'd and ledged

Isolation is a queue, not a claim

48 tenants on the isolation map, 17 open high-and-critical risks, strict isolation at 33.3%. Diagnosed alerts read symptom, cause, fix: the cross-tenant explore filter gap names the missing locked row filter.

  • 17 open isolation risks, high + critical
  • Strict isolation 33.3% — stated, not spun
  • Migration-paused tenants named in the alert
embedded — overview
Isolation is a queue, not a claim

Product tour

Three screens, captured from the running build.

Not a mockup and not a concept deck. This is what opens at /app/embedded.

embedded.cedxsystems.com
CEDX Embedded Overview screen.CEDX Embedded Embeds screen.CEDX Embedded Tokens screen.

01 — Overview

The embed estate, metered

235 live embeds, 41.2K sessions a day, 1.7s p75, 129 active tokens, 17 isolation risks. Platform health reads 86 with budget breaches, isolation, expired tokens and over-budget counts itemized.

  • Health 86, components itemized
  • Embeds by status: 235 live, 31 paused, 27 draft, 27 deprecated
  • Annotations: SDK v4, guest TTL 15m, cache stampede

02 — Embeds

The catalog, weighed

Orders day tile at 977ms and 48 KB; a cohort LTV dashboard at 1.8s and 327 KB; the ship-delay explore on SDK at 383 KB. Kind, render, status, p75, payload and sessions on every row.

  • 320 embeds · 235 live
  • Sessions per embed over 30 days
  • Filter by kind, render mode, status, budget

03 — Tokens

The guest ledger

A read token at 60m TTL with 23K uses; a guest token at 15m with 22K. Admin tokens for theme work sit beside guest tokens for viewing — scope decides, and the ledger counts.

  • 220 tokens · 83.5K uses
  • Active, expired, revoked, pending chips
  • CSV export of the ledger

Who runs it

Three roles keep the embeds honest.

Roles, not references. We have no named customers yet, so nobody in these photographs is quoted, credited or claimed as one.

Embed engineering

Ships the web components and SDK integrations, and owns the payload budget — the 154 KB average says the wrapper work is paying off.

web component · 1.5s p75

Product management

Decides which tiles and answer cards ship to which tenants, and reads sessions-per-embed before the next rollout.

30 answer embeds · 63K questions

Tenant security

Works the isolation queue and the token ledger: rotates the 35 expired tokens still receiving traffic and closes the explore filter gap.

isolation open · 17

The shape of it

What the demo embed estate actually looks like.

Every figure below is legible in the captures above. Nothing here is a projection of your estate — it is the state of the demo data.

235live embedsof 320 in the catalog
41.2Kembed sessions a dayacross 48 tenants
76embeds over budgetlive breaches, filterable
35expired tokens in trafficgrace TTL named as cause
Live embeds by render modep75 load and payload against the iframe baseline
  • Web component · 104 live · 1.5s · 154 KB104
  • iframe · 70 live · 2.0s · 378 KB70
  • SDK · 61 live · 1.6s · 186 KB61
Embed platform healthbudget + isolation + tokens · up from 82
86
  • 235 live · 41.2K sessions a day
  • Drag: 51 budget breaches · 17 isolation risks
Tokens active on the ledger129 of 220 minted tokens
  • Active · 129
  • Expired, revoked or pending · 91

How it runs

An embed's life, in the order it actually happens.

01

Model

Tiles, dashboards and answer cards are authored in the estate and published to the embed catalog.

02

Issue

A tenant gets scoped tokens — guest:view for readers, admin:theme for branders — with TTLs on the ledger.

03

Serve

Embeds render as iframe, web component or SDK; p75 and payload are metered against the 2.0s budget per embed.

04

Enforce

Over-budget embeds, expired tokens and isolation gaps land in diagnosed queues with causes, not just counts.

One record

The same numbers,
rendered where your users are.

Embedded is not a screenshot service. Its tiles and answer cards execute against the estate's governed definitions — the same ones the metric layer certifies and the warehouse stores.

All 132 applications

Limits

What Embedded does not do yet.

Finding this out on the third call is worse for you than reading it here, and worse for us.

Start

Open it before you talk to anyone.

Pilot

Your product, our charts

  • Everything in Try
  • Embed-design workshop
  • Token and isolation review
  • Estate map
Talk to sales

Estate

Embedded with the rest of it

  • Embedded with Insight, Warehouse and Reports
  • One identity, one bill
  • CEDX delivery
Book an estate map

Questions

Before you pilot Embedded.

Is the software on this page real?

Yes. Every screenshot is a capture of the running build, and you can open the same build at /app/embedded. It runs on demo data, which the header states on screen.

What render modes exist?

Three, with the trade-offs printed: iframe (70 live, 2.0s p75, 378 KB average payload), web component (104 live, 1.5s, 154 KB — it inherits the host DOM and skips the frame wrapper), and SDK (61 live, 1.6s, 186 KB).

How do guest tokens work?

They are scoped — guest:view for readers, read:embed for embedding, admin:theme for brand work — with TTLs from 15 to 240 minutes, and every use counted against the ledger. The 35 expired tokens still receiving traffic are flagged, with the grace TTL named as the cause.

What is the isolation queue?

Per-tenant risk tracking: 17 open high-and-critical items, strict isolation at 33.3%, and tenants whose migration is paused named in the alert. It reads as a work queue because that is what it is.

Is Embedded audited or certified?

No certification has been issued. What we can evidence about hosting, encryption, tenant isolation and production access is written up on the security page.

The catalog is live. Weigh your first embed.

Live build, demo data, no card. Start with the chart your users keep asking support for.