Control D
for LuumenAI

Read your DNS policy state, then change it as an approved step

Control D holds the DNS policy for your fleet: which endpoints resolve, what they can reach, and when. Luumen reads devices, profiles, organization membership, and resolver access IPs on request, so you can answer a question without opening the dashboard. Changes — a new blocking rule, a device edit, a profile clone — are previewed and sent for approval first.

The Control D toolbox

54 tools: 33 read, 21 write. Reads answer instantly. Writes require approval by default. Everything is logged.

  • ReadList Known Access IPsList up to the latest 50 IP addresses that were used to query against a specific Device (resolver).
  • ReadGet Analytics EndpointsList analytics storage regions and their endpoints.
  • ReadGet Analytics LevelsRetrieve available analytics log levels for Control D devices.
  • ReadGet Billing PaymentsRetrieve billing history of all payments made.
  • ReadGet Billing ProductsRetrieve all products currently activated on the Control D account.
  • ReadGet DevicesLists all Control D devices (endpoints) associated with the account.
  • ReadGet Device TypesList all allowed device types in Control D.
  • ReadGet IPRetrieve the current IP address and datacenter information for the API request.
  • ReadGet Network StatsRetrieve network stats on available services in different POPs (Points of Presence).
  • ReadGet Organization MembersView organization membership.
  • ReadGet Organization DetailsView the authenticated organization's details.
  • ReadGet Sub-OrganizationsView sub-organizations and their details.
  • ReadGet ProfilesList all profiles associated with the authenticated account.
  • ReadGet Profile OptionsRetrieves all available configuration options for DNS profiles in Control D.
  • ReadGet Profile by IDRetrieve details of a specific profile by its ID.
  • ReadGet Profile AnalyticsRetrieve analytics data for a Control D profile.
  • ReadGet Profile Analytics LogsRetrieves DNS query activity logs for a specific Control D profile.
  • ReadGet Analytics Log EntryRetrieve a specific analytics log entry by its ID.
  • ReadGet Profile Analytics SummaryFetch a summary of analytics data for a given profile.
  • ReadGet Profile Analytics Top DomainsFetch top domains accessed within a specific profile.
  • ReadGet Profile Top ServicesFetch top services accessed within a profile.
  • ReadGet Profile FiltersList all native (Control D curated) filters for a profile and their current states.
  • ReadList External Filters for ProfileList third-party filters for a specific profile.
  • ReadGet Profile FoldersList all rule folders (groups) within a Control D profile.
  • ReadList Custom DNS Rules for ProfileRetrieve custom DNS rules for a Control D profile.
  • ReadGet Specific Rule in FolderRetrieve a specific rule within a folder by its ID.
  • ReadGet Profile SchedulesList schedules associated with a specific profile.
  • ReadGet Profile ScheduleRetrieve a specific schedule by its ID within a profile.
  • ReadGet Profile ServicesList services associated with a specific profile.
  • ReadGet ProxiesRetrieve the list of usable proxy locations that traffic can be redirected through.
  • ReadGet Service CategoriesList all available service categories in Control D.
  • ReadList Services by CategoryRetrieves all services within a specific ControlD service category.
  • ReadGet UsersRetrieve the authenticated user's account information from Control D.
  • WriteDelete Device by IDPermanently delete a Control-D device/endpoint by its ID. Approval by default
  • WriteDelete ProfilePermanently deletes a Control D profile by its unique identifier (PK). Approval by default
  • WriteDelete Profile Rule by Rule IDDelete a custom DNS rule from a Control D profile by its rule identifier (hostname/domain). Approval by default
  • WriteDelete Rule from FolderDelete a custom DNS rule from a specific folder in a Control D profile. Approval by default
  • WriteDelete Profile ScheduleDelete a specific schedule within a profile. Approval by default
  • WriteCreate DeviceCreate a new device (DNS endpoint) in Control D. Approval by default
  • WriteCreate ProfileCreate a new blank profile or clone an existing one. Approval by default
  • WriteCreate Custom DNS RuleCreate custom DNS rules for a profile to control domain resolution. Approval by default
  • WriteCreate Custom Rules in Profile FolderCreate custom rules within a specific folder for a profile. Approval by default
  • WriteCreate Profile ScheduleCreate a new time-based schedule within a Control D profile. Approval by default
  • WriteModify DeviceModify an existing Control D device's settings. Approval by default
  • WriteModify OrganizationModify organization settings such as name, contact details, website, and device limits. Approval by default
  • WriteModify ProfileModify an existing profile by its ID. Approval by default
  • WriteBulk Update Profile FiltersBulk update filters on a specific profile. Approval by default
  • WriteUpdate External Filters for ProfileUpdate external filters for a specific profile. Approval by default
  • WriteModify Profile FilterModify the enabled state of a specific native filter on a profile. Approval by default
  • WriteModify Custom Rule for ProfileModify an existing custom DNS rule for a profile in Control D. Approval by default
  • WriteUpdate Custom Rule by Rule IDUpdate an existing custom rule by its ID. Approval by default
  • WriteMove Profile Rule to FolderMove a specific custom rule into a different folder. Approval by default
  • WriteUpdate Profile ScheduleUpdate a specific schedule within a profile. Approval by default
  • WriteModify Service for ProfileModify a specific service rule for a profile. Approval by default

One prompt, start to finish

What a governed Control D run looks like inside Luumen.

Questions

How does LuumenAI connect to Control D?

Authorize once with API token. Luumen lists the scopes each action needs before you approve the connection, and credentials never appear in the chat.

Can LuumenAI change things in Control D on its own?

Read actions answer immediately. Anything that writes — delete device by id, delete profile, delete profile rule by rule id, delete rule from folder, and more — is shown as a plan and requires approval by default, including the 5 actions classified as destructive. Administrators configure that per tool, so you decide exactly which actions can ever run unattended.

Who gets access to the integration?

You decide. Actions are granted per agent, skill, and team, and per environment — production is not staging. Read access can be broad while writes stay narrow.

Is there an audit trail?

Every call to Control D — read or write, approved or declined — is recorded with the actor, the input, and the result, and can be linked to the ticket or change record.

Put Control D to work with Luumen

Connect in minutes. Every action scoped, approved, and audited from day one.