Help / Systems & Tools / Lab services catalog

Systems & Tools

Lab services catalog

Every service the lab runs, what it's for, and how you sign in to it — which ones use lab single sign-on and which ones require two-factor.

Updated Jul 24, 2026 · Francisco

Everything the lab runs, grouped by what it does. Each card shows how you sign in. Addresses aren’t listed here on purpose — members get them from the member docs or from Francisco.

How to read the labels

SSO One lab sign-in, through the portal
2FA Second factor required
Lab account Same lab credentials, its own sign-in screen
Own login A separate account just for that service
Public No sign-in needed

SSO means you sign in once at the lab portal and this service accepts that session. Lab account means the service checks the same username and password, but shows you its own login form. Own login means a separate account you set up for that service alone.

Accounts and sign-in

Sign-in portal

The lab's front door. Sign in once here and the SSO services below accept it.

SSO2FA

Password self-service

Change your own lab password and manage the SSH keys that let you into lab machines.

SSO2FA

Password reset

Locked out? Start recovery here — it stays reachable when you can't sign in.

Public

Identity service

Where lab accounts and groups actually live. Administrators only, and only from campus or the VPN.

Lab account

Talking to each other

Lab chat

Day-to-day conversation, channels per project, and where to ask for help first.

Own login

Notifications

Push alerts from lab systems to phones and desktops. Mostly used by automation.

Own login

Files and storage

Lab Files

Everyday working files, with a desktop sync client, phone apps, and sharing. Start here.

SSO

Lab Archive

Long-term, redundant storage for finished datasets and material that must not be lost.

SSO2FA

Lab Storage

Bulk upload area for very large datasets, reached over SSH with per-person quotas.

Lab account

Password vault

Shared and personal credential storage. Kept deliberately outside single sign-on.

Own login

Code and documents

Git hosting

Lab code repositories. Sign in on the web with SSO; push over SSH with your key.

SSO2FA

E-signature

Send and sign lab documents. Signing links work without an account by design.

Own login

Public documents

This site — onboarding, guides, and how-tos that need no account.

Public

Member documents

Internal how-tos for lab members: machines, storage, research apps, workflows.

SSO

Administrator runbooks

Infrastructure operating procedures. Restricted to administrators.

SSO2FA

Agentic AI handbook

Open handbook on the lab's agentic-AI concepts, patterns, and tooling.

Public

Machines and AI

Lab machine login

SSH access to lab workstations and GPU servers, with your key and lab account.

Lab account

Model gateway

One endpoint for the lab's language models, for use from code and tools.

SSO

3D and XR generation

Generate 3D assets and scenes on the GPU machines, and stream to headsets.

Lab account

AgenticXR service

Backend service for the lab's agentic XR experiments.

Own login

Dashboards and monitoring

Member dashboard

Your at-a-glance view of lab machines and services.

SSO

Machine metrics

Live CPU, memory, disk, and temperature graphs for every lab machine.

SSO

Service status

Whether lab web services are up. Status pages are viewable without an account.

Own login

Fleet dashboard

Administrator control panel for the lab's machines and settings.

SSO2FA

Telemetry and logs

Central logs, metrics, and alerting dashboards. Administrators only.

SSO2FA

Backups console

Backup jobs, snapshots, and restores. Administrators only.

SSO2FA

Fleet status page

A public, summarised view of which lab machines are online.

Public

Lab operations

Equipment inventory

What hardware the lab owns, where it is, and who has it checked out.

Lab account

Grants tracker

Funding-opportunity tracking for lab proposals.

SSO

Administrator console

Create and manage lab accounts, groups, and access policies.

SSO2FA

Lab website

The public face of the lab: research, people, and publications.

Public

Contact and sign-up forms

How people outside the lab reach us, and how prospective members express interest.

Public

Project sites

Standalone sites for individual research projects and initiatives.

Public

Notes

  • A few internal machine-to-machine services aren’t listed, because they have no human interface — bridges, relays, and collectors that only other programs talk to.
  • “Own login” is not always a gap. The password vault is kept out of single sign-on on purpose: if it depended on SSO, an SSO problem would lock us out of the very credentials needed to fix it.
  • Two-factor is set per service, not per person. Administrative and state-changing tools require it; read-only and low-risk ones generally don’t.
  • Don’t have access to something you need? Ask Francisco. Most services are granted by adding you to a group.

Source: content/systems/services-catalog.md · maintained in the lab docs repository.