Flags, plans and overrides — with the debt priced in.
Entitlements evaluates 320 flags 104.4 million times a day in the demo estate, and remembers what most flag tools forget: which of the 68 temporary flags became permanent, which overrides never expire, and which flag is 868 days old and still serving traffic.
The retirement queue is the feature: 24 flags score high enough on debt to be candidates, led by one at 94 that has been stuck at 100% with no kill switch and no owner.
entitlements.cedxsystems.com — live build
Runs on demo data. Northline Platform in the captures is the software's demo workspace, not a customer.
104.4M evaluations a dayacross 320 flags in all environments
24 high-debt flagsa retirement queue, scored 55 and above
96 open overrides21 of them permanent, 20 set to never expire
What it is
Flag tooling grows up in three places.
Every flag carries debt and blast
The Flags table does not stop at on and off: kind, state, environment, exposure, debt, blast and age on every key. Sorting by debt puts a 94-scoring legacy flag at the top — 868 days old, still on in production — which is a retirement decision presented as a row, not a post-mortem.
48 plans with seats, feature counts and attach rate: 1,366 feature slots across plans, 84% of features wired to flags. The MRR column is labelled demo SKUs on the screen itself — $391,320 packaged — so the wiring between a plan and its flags is the thing being shown, not a revenue claim.
Attach rate 84% — features wired to flags
Enterprise, Partner and Growth tiers with seat counts
Sunset status is a first-class plan state
entitlements — screen-3
Overrides with an expiry, or a reason
96 force-rules, each typed segment, account, user or device, each with an expiry or the word never in red. The reasons are the honest part: month-end freeze, sales demo, contract exception, incident mitigation, QA holdout. Twenty set to never are a review queue, by design.
21 permanent overrides flagged no auto-expiry
Risk-only filter for the board view
Environment on every override — production, sandbox, staging
entitlements — screen-4
Product tour
Four screens, captured from the running build.
Not a mockup and not a concept deck. This is what opens at /app/entitlements.
entitlements.cedxsystems.com
01 — Overview
Flag hygiene as a scored discipline
Estate health reads 40% hygiene, and the alerts say why: a temporary dual-write flag never retired at 413 days; a legacy payments flag stuck at 100% with no kill switch; six permanent overrides piled on one partner integration at 703 days old.
189 of 320 flags active and serving traffic
45 live rollouts of 72 staged
Highest-debt queue printed on the dashboard
02 — Flags
The registry, with its skeletons
Three hundred twenty keys with kind, state, environment, exposure, debt, blast and age. The temp-permanent card counts 68 flags that were never cleaned up — the failure mode every flag system has, made into a number you can work down.
On · Off · Draft · Archived as filter chips
CSV of the view you are looking at
Blast radius scored separately from debt
03 — Plans
What each tier actually turns on
Forty-eight plans with code, tier, status, seats, feature count and attach rate per row — the top plan attaches 38 of 42 features to flags. Sunset plans stay visible, because retiring a plan is a lifecycle, not a deletion.
1,366 feature slots across all plans
84% of features wired to flags
Internal and Sandbox tiers filterable
04 — Overrides
The exceptions, with dates or confessions
Ninety-six overrides where the REASON column does the governance: partner SLA, contract exception, beta cohort. The ones expiring never are red, counted at 20, and one click from a review.
Segment · account · user · device targeting
Value on, off or variant per override
Expires column shows dates or never — nothing hidden
Who runs it
Three roles keep flags from fossilising.
Roles, not references. We have no named customers yet, so nobody in these photographs is quoted, credited or claimed as one.
Platform engineering
Owns the flag registry: debt and blast on every key, and the retirement queue of 24 that turns spring cleaning into a sorted list.
retire queue · 24
Release management
Owns the 45 live rollouts and the staged 72 behind them — and the kill switches, because a rollout without one is an alert on this console, not a risk accepted silently.
live rollouts · 45
Operations
Owns the overrides: 96 open, 20 that never expire, and the monthly review that asks whether the month-end freeze reason is still true.
never-expire · 20
The shape of it
What the demo workspace actually looks like.
Every figure below is legible in the captures above. Nothing here is a projection of your estate — it is the state of the demo data.
320flags in the registry189 active and serving
104.4Mevaluations a dayall environments
68temporary flags gone permanentnever cleaned up
84%attach ratefeatures wired to flags
The retirement queue, by debt scoreflags scoring 55 and above · top of queue
Legacy mobile payments — stuck at 100%, no kill switch, no owner94
Partner EDI v2 — six permanent overrides, 703 days old91
Billing dual-write — temporary, never retired, 413 days86
Shipping quota index — config flag, 513 days77
Payments config — 411 days in production76
Flags by kind157 boolean of 320 total
Boolean · 157
Percentage 55 · multivariate 50 · config 58
Override hygiene96 open force-rules
21
Permanent overrides · 21 with no auto-expiry
Dated overrides · the rest of the 96
How it runs
A flag's life, in the order it actually happens.
01
Gate
A feature ships behind a flag — one of the 189 active, typed boolean, percentage, multivariate or config, with a kill switch from day one.
02
Roll out
Staged rollouts move exposure up — 45 live now — with the gate stable for days before the next stage, as the checkout alert describes.
03
Serve
Plans attach the flag to tiers: 84% of features are wired this way, so a plan change is a flag change, not a deploy.
04
Retire
Debt and age accumulate on the key until the retirement queue says the obvious: 24 flags are past the line, and the queue is the to-do list.
One record
Who gets what, decided in one place.
Entitlements is the switchboard between identity and product: the person is known elsewhere, but what their plan turns on is decided here.
Finding this out on the third call is worse for you than reading it here, and worse for us.
Entitlements is not generally available. What opens today is the live build running on demo data — Northline Platform in the captures is the software's demo workspace, not a customer.
We have no named customers to show you, so this page shows none. The plan names in the demo captures are fictional demo SKUs, labelled as such on the screen.
The 104.4M daily evaluations are the demo estate's seeded load, not a benchmark of your traffic or a capacity promise.
The MRR column on Plans is labelled demo SKUs on the screen itself. Nothing on this page is a price list — yours or ours.
SDK surface and language coverage are not evidenced by these captures and are not claimed here; that is a pilot conversation.
No audit or compliance certification has been issued for Entitlements. What we can evidence about hosting, encryption and access is on the security page.
Yes. Every screenshot is a capture of the running build and you can open the same build at /app/entitlements. It runs on demo data, which the page says next to the figures rather than in a footnote.
What is flag debt?
A score per flag that weighs age, stuck exposure, missing kill switch and ownership. Twenty-four flags score 55 or above and form the retirement queue — the top one has been on at 100% for 868 days with no owner, which is precisely the state debt scoring exists to surface.
What is the difference between debt and blast radius?
Debt asks how overdue a flag is for retirement; blast asks how much it costs if it flips wrongly. Both are columns on the registry — a fraud holdout config scores 72 on debt and 95 on blast, which is a different conversation than a stale experiment.
How do overrides stay governed?
Every override has a type, a value, an environment, an expiry and a reason on its row. The 20 set to never expire are red and counted, so the exception register is the same table engineers already read.
Can plans differ by tier without code changes?
That is the attach rate's job: 84% of features across the 48 demo plans are wired to flags, so moving a feature between tiers is a plan edit. The remaining 16% is visible as unwired, not assumed away.
Is Entitlements audited or certified?
No certification has been issued. What we can evidence about hosting, encryption, tenant isolation and production access is written up on the security page.
The console is running. Go and look at it.
Live build, demo data, no card. Then ask how old the oldest temporary flag in your own codebase is.