> For the complete documentation index, see [llms.txt](https://docs.gxc.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.gxc.io/docs/application-notes/4g-and-5g-onyx-cbrs-sas-registration.md).

# 4G & 5G Onyx CBRS SAS Registration

## Introduction

The Citizens Broadband Radio Service (CBRS) is a shared spectrum service operating in the 3550–3700 MHz band (Band n48), regulated by the Federal Communications Commission (FCC) under *47 CFR Part 96*. The FCC established CBRS to expand access to mid-band spectrum by enabling federal and commercial users to share the band through a three-tier spectrum access model.

Before a CBSD can transmit on CBRS spectrum, it must register with an FCC-approved Spectrum Access System (SAS) and receive authorization to operate. The SAS coordinates spectrum access by authorizing spectrum grants, protecting higher-priority users from interference, and continuously managing spectrum availability throughout CBSD operation.

### **CBRS Spectrum Sharing**

The CBRS uses a three-tier spectrum access model to enable efficient spectrum sharing while protecting higher-priority users from interference. The SAS enforces this priority model by authorizing spectrum access according to the priority assigned to each tier.

<p align="center"><strong>Figure: Three-Tier Spectrum Access Model</strong></p>

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2Fkxu9YzfVv8fd81D5ibyU%2Fsas-3-tier.png?alt=media&amp;token=f2f77ec6-cc1d-4bf1-85fd-192d5870b353" alt="" width="563"><figcaption></figcaption></figure></div>

* Tier 1 — Incumbents. The highest-priority tier, consisting primarily of U.S. Navy radar systems, Fixed Satellite Service (FSS) earth stations, and other federally authorized users. Incumbents receive full interference protection, when incumbent activity is detected, all lower-tier users must vacate spectrum.
* Tier 2 — Priority Access Licensees (PAL). Licensed users that acquire exclusive spectrum usage rights through FCC auctions. PAL users receive interference protection within their licensed geographic area but must yield to incumbent users when required.
* Tier 3 — General Authorized Access (GAA) users. License-by-rule access, available after incumbent and PAL users have been protected. GAA users operate on a shared, non-exclusive basis. Most private LTE and 5G CBRS deployments, including GXC Onyx deployments, use GAA spectrum.

The SAS continuously evaluates spectrum availability and authorizes spectrum access according to the CBRS priority model. As spectrum availability changes, the SAS may modify or revoke spectrum grants to protect higher-priority users.

### **Spectrum Access System**

The SAS is an FCC-approved cloud service that coordinates spectrum access for CBRS deployments. It authorizes spectrum operation by evaluating spectrum availability, enforcing the CBRS priority model, and protecting incumbent and licensed users.

The SAS performs four key functions:

* Registers and authenticates every CBSD before it may transmit
* Determines available frequencies at a given location and issues spectrum grants
* Enforces Exclusion Zones and Dynamic Protection Areas (DPAs) to protect federal incumbents
* Protects PAL holders from GAA interference on an ongoing basis

During normal operation, the SAS continuously monitors spectrum availability. When required, it may modify, suspend, or terminate active spectrum grants to maintain regulatory compliance and protect higher-priority users.

Environmental Sensing Capability (ESC) sensors complement the SAS by detecting federal incumbent activity in the 3550–3700 MHz band and adjacent frequencies. When incumbent activity is detected within a DPA, the SAS automatically reconfigures affected CBSDs by reassigning frequencies, reducing transmit power, or suspending transmissions until the incumbent ceases operation. This is normal SAS behavior and is handled automatically by the GXC Onyx platform.

### Domain Proxy

The Domain Proxy (DP) provides the communication interface between GXC Onyx and the SAS. Rather than requiring individual CBSDs to communicate directly with the SAS, the DP manages all communication with the SAS on behalf of every managed CBSD.

The DP performs two key functions:

* Registration and grant management — Submits CBSD registration and grant requests to the SAS on behalf of each CBSD.
* Heartbeat management — Sends periodic heartbeat messages to maintain grant authorization. If the SAS responds with a suspended grant, the DP flushes cached spectrum data, performs a new spectrum inquiry, and automatically attempts to obtain a replacement grant.

Because all SAS communication is performed through the DP, network operators manage CBSD registration and spectrum operations from the Onyx Portal without requiring direct communication between individual CBSDs and the SAS.

{% hint style="info" %}
**NOTE**: The DP facilitates communication with the SAS but does not make spectrum allocation decisions. Spectrum authorization and grant management remain the responsibility of the SAS.
{% endhint %}

### **SAS Provider**

GXC has chosen Federated Wireless as its primary SAS provider. However, the GXC Onyx platform is architecturally vendor-agnostic and is designed to integrate with any FCC-approved SAS.

The SAS portal procedures described in this guide are based on the Federated Wireless SAS portal. While portal interfaces and terminology may vary between SAS providers, the underlying CBSD registration, spectrum grant, and authorization workflow is standardized and functionally consistent across all FCC-approved SAS platforms.

### Certified Professional Installer

The FCC requires certain CBSD installation parameters to be verified and certified by a Certified Professional Installer (CPI) before they can be submitted for SAS registration. This requirement helps ensure that the SAS receives accurate installation information when authorizing spectrum operation.

A CPI is an individual who has successfully completed an FCC-recognized CBRS certification program and holds valid CPI credentials. Before certifying an installation, the CPI verifies that the installation parameters accurately represent the physical deployment. Installation parameters verified by the CPI include geographic location, installation height, antenna height above ground level (AGL), antenna azimuth, antenna downtilt (when applicable), antenna gain, deployment category (Category A or Category B), and any other installation parameters required for SAS registration.

After completing the verification, the CPI digitally certifies the installation record using their CPI credentials.

{% hint style="info" %}
**NOTE**: CPI certification is issued to an individual, not an organization. The individual CPI is responsible for the accuracy of every installation record they certify. See [*Roles & Responsibilities*](#roles-and-responsibilities) for a complete summary of CPI duties and authorization scope.
{% endhint %}

### Spectrum Grant Lifecycle

After a CBSD successfully registers, the SAS authorizes operation by issuing one or more spectrum grants. Each grant specifies the operating frequency range, bandwidth, maximum transmit power, and grant duration.

To maintain an active grant, the CBSD must periodically send heartbeat requests through the DP. If a heartbeat is not received within the required interval, or if spectrum availability changes, the SAS may suspend, modify, or terminate the grant.

This dynamic grant management enables efficient spectrum sharing while ensuring compliance with FCC regulations and protecting higher-priority users.

{% hint style="info" %}
**NOTE**: The SAS may modify or revoke an active spectrum grant at any time if incumbent activity is detected or spectrum must be reassigned to protect higher-priority users.
{% endhint %}

### **Scope of this Guide**

This guide describes the complete CBSD registration workflow for GXC Onyx deployments operating on CBRS Band n48, from pre-registration requirements through CPI certification, SAS portal configuration, Onyx Portal configuration, spectrum grant verification, and troubleshooting.

{% hint style="info" %}
**NOTE**: This guide assumes that the GXC Onyx network has already been deployed, powered on, commissioned, and verified as operational before CBSD registration begins.
{% endhint %}

{% hint style="info" %}
**NOTE:** For definitions of technical terms and acronyms used in this guide, refer to the *GXC Glossary*.
{% endhint %}

### Intended Audience

This guide is intended for the following roles involved in CBSD registration on Onyx CBRS deployments. Detailed task ownership for each stage of the workflow is described in [*Roles & Responsibilities*](#roles-and-responsibilities).

<p align="center"><strong>Table: Intended Audience</strong></p>

<table><thead><tr><th width="300">Role</th><th>Responsibilities</th></tr></thead><tbody><tr><td>Operator / Technical Staff</td><td>Manages the GXC Onyx network and equipment, configures RAN/SAS settings, and monitors grant status. Cannot register, modify, or delete CBSDs — a CPI is required.</td></tr><tr><td>CPI</td><td>Registers, modifies, deletes, and signs CBSD records in the SAS portal.</td></tr><tr><td>GXC / System Integrator</td><td>Provides platform support. Does not perform CPI duties on behalf of the operator by default.</td></tr></tbody></table>

## Prerequisites

Before registering CBSDs with the SAS, verify that the GXC Onyx deployment has been fully installed, commissioned, and validated. All required hardware, software, network connectivity, and regulatory prerequisites must be satisfied before registration can begin.

The following prerequisites apply to all GXC Onyx CBRS deployments.

### SAS Portal Account

The CPI must have an active SAS portal account with a validated CPI role, and a current CPI certification issued by an FCC-approved training provider.

The following CPI credentials must be available at the time of CBSD record signing.

<table><thead><tr><th width="250">CPI Credential</th><th>Description</th></tr></thead><tbody><tr><td>CPI ID</td><td>Unique identifier assigned by the CPI training and certification authority. The SAS uses this identifier to verify the certified installer.</td></tr><tr><td>CPI Name</td><td>The CPI's full name as it appears on the CPI certificate.</td></tr><tr><td>CPI Certificate (.p12)</td><td>A PKCS#12 certificate file containing the CPI's digital certificate and private key. It is used to cryptographically sign CBSD installation records.</td></tr><tr><td>Certificate Password</td><td>Password protecting the .p12 file, required at the time of signing.</td></tr></tbody></table>

{% hint style="info" %}
**NOTE**: CPI identity must be validated in the SAS portal at account setup — not during CBSD registration. Complete CPI validation when the account is created. If the certificate has expired, revalidate before attempting any CBSD registration or modification.
{% endhint %}

### Onyx Portal Account

The operator must have an active Onyx Portal account with administrator-level access.

### Network Requirements

Ensure that the Onyx Edge has been deployed, is reachable on the network, and has been verified as operational. The Onyx Edge must have outbound Internet access on port 443 (HTTPS) to the SAS endpoint. Firewall rules must permit DNS resolution and TCP connections to the SAS domain. For firewall requirements, see the *GXC Firewall Config Application Note*.

### Site Survey Data

For each CBSD to be registered, collect the following installation parameters during site survey prior to registration.

{% hint style="info" %}
**NOTE:** Site survey data may be collected by the operator, the CPI, or both working together. Regardless of who collects the data, the CPI is legally responsible for the accuracy of all parameters submitted to the SAS and must verify them against the physical installation before signing.
{% endhint %}

<p align="center"><strong>Table: Site Survey Data</strong></p>

<table><thead><tr><th width="200">Parameter</th><th width="200">Format / Units</th><th>Notes</th></tr></thead><tbody><tr><td>GPS Latitude / Longitude</td><td>Decimal degrees (WGS-84)</td><td>Use surveyed coordinates. The SAS uses these for interference calculations. Approximate values are not acceptable.</td></tr><tr><td>Antenna Height</td><td>Meters (AGL or AMSL)</td><td>Must be in meters, not feet. Above Ground Level (AGL) is the most common measurement.<br><strong>NOTE</strong>: Incorrect antenna height is one of the most common causes of registration failure.</td></tr><tr><td>Height Type</td><td>AGL or AMSL</td><td>AGL or Above Mean Sea Level (AMSL). Verify against site documentation.</td></tr><tr><td>Indoor Deployment</td><td>True / False</td><td>Determines CBSD category and maximum Equivalent Isotropic Radiated Power (EIRP) limits. Setting this incorrectly results in regulatory non-compliance.</td></tr><tr><td>Antenna Azimuth</td><td>0–359° (degrees)</td><td>Horizontal pointing direction of the antenna, measured clockwise from true north (0° = North, 90° = East, 180° = South, 270° = West).</td></tr><tr><td>Antenna Downtilt</td><td>Degrees</td><td>Mechanical and/or electrical downtilt angle.</td></tr><tr><td>Antenna Gain</td><td>dBi</td><td>Fixed per AP model. Do not estimate. See <a href="#onyx-cbrs-ap-reference"><em>Onyx CBRS AP Reference table</em></a>.</td></tr><tr><td>Max EIRP</td><td>dBm</td><td>Must not exceed CBSD category limits: Cat A ≤30 dBm, Cat B ≤47 dBm. See <a href="#onyx-cbrs-ap-reference"><em>Onyx CBRS AP Reference table</em></a> for model-specific limits.</td></tr></tbody></table>

### Onyx CBRS AP Reference

The following table provides the identity and CBSD classification for all GXC Onyx APs supporting CBRS band n48. Refer to this table when entering CBSD parameters in either portal.

<p align="center"><strong>Table: Onyx CBRS AP Reference</strong></p>

<table><thead><tr><th width="120">Model</th><th width="220">FCC ID</th><th width="100">Band</th><th width="109">Category</th><th width="100">Max EIRP</th><th width="129">Deployment</th><th>Antenna Gain</th></tr></thead><tbody><tr><td>G100</td><td>2AZH6GXI44XENBB1AA</td><td>n48 (4G)</td><td>Cat A</td><td>24 dBm</td><td>Indoor</td><td>4 dBi (internal, fixed)</td></tr><tr><td>G101</td><td>2AZH6GXO44XENBB1AA</td><td>n48 (4G)</td><td>Cat A / B*</td><td>24 dBm</td><td>Outdoor</td><td>13 dBi (external, fixed)</td></tr><tr><td>G501</td><td>2AZH6GXO44XENBB</td><td>n48 (4G)</td><td>Cat B</td><td>47 dBm</td><td>Outdoor</td><td>−5 to 30 dBi (variable)</td></tr><tr><td>G105-n48F</td><td>2AQ68RPQN4800</td><td>n48 (5G)</td><td>Cat A</td><td>24 dBm</td><td>Indoor</td><td>0–24 dBi (default: 24)</td></tr><tr><td>G105-n48P</td><td>VUIPR1450-48</td><td>n48 (5G)</td><td>Cat A</td><td>20 dBm</td><td>Indoor</td><td>0–20 dBi (default: 20)</td></tr><tr><td>G505-n48P</td><td>2AZULRS8682</td><td>n48 (5G)</td><td>Cat A</td><td>37 dBm</td><td>Outdoor</td><td>0–37 dBi (default: 37)</td></tr></tbody></table>

{% hint style="info" %}
**NOTE**: \* The G101 AP may be registered as Category A or Category B CBSD depending on its installed height and Height Above Average Terrain (HAAT). The FCC threshold for an outdoor Category B deployment is >6m HAAT. Verify the deployment category using the site survey before selecting the CBSD category.
{% endhint %}

### Roles & Responsibilities

Successful CBSD registration requires coordination between the Operator, the CPI, and GXC/System Integrator. Each participant has distinct responsibilities throughout the registration process.

The following table summarizes the primary responsibilities for each role.

{% hint style="info" %}
**NOTE**: Only a CPI may register, modify, or delete CBSD records in the SAS portal. This requirement is defined by *FCC Part 96 and WInnForum WINNF-TS-0016*. Operator accounts alone are insufficient — a CPI must validate and digitally sign every CBSD installation record.
{% endhint %}

<p align="center"><strong>Table: Roles &#x26; Responsibilities</strong></p>

<table><thead><tr><th width="214.5556640625">Role</th><th width="350.4444580078125">Responsibilities</th><th>Who Performs It</th></tr></thead><tbody><tr><td>Operator / Organization</td><td>• Owns the CBRS network and SAS account • Sets up the network deployment in the SAS portal • Configures Onyx Portal (RAN/SAS settings) • Monitors spectrum grant status • Cannot register, modify, or delete CBSDs without a CPI</td><td>Network operator or their designated team</td></tr><tr><td>CPI</td><td>• Only role authorized to register, modify, or delete CBSDs • Validates and digitally signs CBSD installation parameters • Must verify CPI credentials in the SAS portal before any CBSD work • Required for all CBSD registrations on GXC Onyx. Because GXC Onyx uses Multi-Step Registration exclusively, every record — including indoor Category A CBSDs — must be CPI-signed.</td><td>FCC-certified individual with active CPI credentials</td></tr><tr><td>GXC / System Integrator</td><td>• Provides Onyx platform and DP integration • Assists with portal configuration and troubleshooting • Does not perform CPI duties on behalf of the operator by default</td><td>GXC or certified integration partner</td></tr></tbody></table>

## CBRS Registration Overview

This section describes the two-portal CBRS registration process, including how it works, who is involved at each stage, and what is required before registration can begin. Detailed procedures and responsibilities are described in the following sections.

### How CBRS Registration Works

CBRS registration in GXC Onyx deployments uses Multi-Step Registration as defined by WInnForum *(WINNF-TS-0016, Section 10)*. This is a two-portal, two-actor process.

<table><thead><tr><th width="200">System</th><th>Description</th><th width="150">Actor</th></tr></thead><tbody><tr><td>SAS Portal</td><td>Receives and stores CPI-signed installation parameters, validates the CBSD record, and issues spectrum grants.</td><td>CPI + Operator</td></tr><tr><td>GXC Onyx Portal</td><td>Configures the AP/cell with RAN and SAS settings. The DP submits the registration request to the SAS on behalf of the CBSD.</td><td>Operator</td></tr></tbody></table>

### Multi-Step vs. Single-Step Registration

GXC Onyx deployments use Multi-Step Registration exclusively. Understanding this registration model because it defines the dependency between the SAS portal and the Onyx Portal throughout this guide.

* Multi-Step Registration (used by GXC Onyx) — The CPI pre-enters the installation parameters in the SAS portal and digitally signs the CBSD record before the CBSD submits its registration request. When the Onyx Portal initiates registration, the SAS cross-validates the CPI-signed record stored in the SAS portal with the registration request received from the CBSD through the DP. If either input is missing, incomplete, or does not match, the SAS rejects the registration request.
* Single-Step Registration — The CBSD submits all installation parameters directly in its registration request without a previously signed CPI record. This method is permitted only for certain indoor Category A CBSDs and is not used in standard GXC Onyx deployments.

## CBSD Registration Workflow

The following workflow must be completed in sequence. Performing steps out of sequence will result in registration failure.

<p align="center"><strong>Figure: CBSD Registration Workflow</strong></p>

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F5AgY2Sit1OAA9aePmlhz%2Fsas-cbsd-registration-workflow.png?alt=media&amp;token=7784e408-ec4f-4c3b-b494-b38bc8663c81" alt=""><figcaption></figcaption></figure></div>

{% stepper %}
{% step %}
Pre-Registration:

* Operator: Gather site survey data for each CBSD. See [*Site Survey Data*](#site-survey-data).
* CPI: Verify that CPI certification is current, CPI credentials are available, and CPI identity has been validated in the SAS portal.
* Operator: Confirm access to Onyx Portal and verify that the Onyx Edge is reachable on the network.
  {% endstep %}

{% step %}
SAS Portal: Create Network Deployment and CBSD Records:

1. Operator: Create a network deployment in the SAS portal if one does not already exist.
2. Operator: Add each CBSD to the deployment and enter all installation parameters.
3. CPI: Review and validate all installation parameters, then digitally sign each CBSD record.
4. SAS: Signed CBSDs display a "Pending Registration" status and are ready to receive registration requests from the DP.
   {% endstep %}

{% step %}
GXC Onyx Portal: Configure and Register:

1. Operator: Add APs/cells to the Onyx Portal and configure the required RAN and SAS settings.
2. Onyx: Automatically submits CBSD registration requests to the SAS after the AP/cell configuration is saved.
3. SAS: Validates the CPI-signed CBSD record in the SAS portal against the registration request received from the CBSD.
4. SAS: If validation succeeds, issues one or more spectrum grants.
   {% endstep %}

{% step %}
Verify:

* Operator: In the Onyx Portal, verify that all CBSDs show an Authorized status.
* Operator: In the SAS portal, verify that all CBSDs show a Registered status.
* Operator: Confirm that spectrum grants are active and CBSDs are transmitting.
* Operator: Verify that there are no active SAS-related alerts in the Onyx Portal. See [*Troubleshooting > Onyx Portal SAS-Related Alerts*](#onyx-portal-sas-related-alerts).
  {% endstep %}
  {% endstepper %}

### SAS Portal Procedures

The SAS Portal procedures prepare CBSD records for registration with the SAS. The following workflow diagram summarizes the sequence of tasks and the responsibility for each step.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2Fl40Df9TwBVVLE0lWgeuQ%2Fsas-workflow-sas-portal-procedures.png?alt=media&amp;token=d40f8ab7-d61c-46f1-8ec8-c4f7dd64199f" alt="" width="563"><figcaption></figcaption></figure></div>

{% hint style="info" %}
**NOTE**: This guide uses the Federated Wireless SAS portal for all procedures, screenshots, and navigation examples. Other FCC-approved SAS platforms follow the same CBSD registration workflow, although user interfaces and navigation may differ.
{% endhint %}

#### CPI Account Setup (One-Time)

Before a CPI can certify CBSD installation records, the CPI must associate their WInnForum-issued CPI credentials with their SAS account. This one-time configuration enables the SAS to validate digital signatures submitted during CBSD registration.

Only the CPI can complete this procedure because the CPI's digital certificate and private key remain under their exclusive control and are used to generate digitally signed certification records. This step cannot be delegated to another user.

After the CPI credentials have been successfully associated with the SAS account, the account is authorized to digitally certify CBSD installation records. Each digital signature cryptographically binds the CPI's identity to the certified installation parameters submitted during CBSD registration.

{% hint style="info" %}
**NOTE**: A CPI must successfully validate their credentials before signing CBSD installation records. Until CPI validation is complete, the SAS will not authorize the account to certify installation parameters for CBSD registration.
{% endhint %}

{% hint style="info" %}
**NOTE**: CPI credentials are associated with the SAS account only once. They remain available for future CBSD registrations unless they are removed, replaced, or expire.
{% endhint %}

{% hint style="info" %}
**NOTE**: The CPI certificate (.p12) contains the CPI's digital certificate and private key. The private key is used to generate digital signatures and must remain under the CPI's control.
{% endhint %}

**To configure CPI credentials:**

{% stepper %}
{% step %}
Log in to the SAS portal using your CPI account.
{% endstep %}

{% step %}
Navigate to the **Profile** or **CPI Settings** page.
{% endstep %}

{% step %}
Configure the required CPI information, including:

* CPI Registration ID (CPIR-ID)
* CPI Certification ID
* FCC FRN (if required)
* CPI certificate (`.p12`)
* Certificate password

See [*Prerequisites > SAS Portal Account*](#sas-portal-account) for more information.
{% endstep %}

{% step %}
Complete the verification/activation process.

A confirmation message indicates your credentials are active and the account has CPI signing privileges.
{% endstep %}
{% endstepper %}

#### Create a Network Deployment

This step is performed by the operator or personnel responsible for managing the organization's SAS account.

Before adding CBSDs, create a network deployment in the Spectrum Access System (SAS) portal. The deployment represents the physical site where the CBSDs will be installed and provides the location context used during CBSD registration and spectrum management. A deployment is typically created once for each site and can contain one or more CBSDs.

Each deployment is associated with the operator's SAS account, which governs spectrum access permissions and billing for all CBSDs within the deployment.

**To create a network deployment:**

{% stepper %}
{% step %}
Log into the SAS portal.

The home screen displays a summary of all existing CBSD deployments across your organization.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FbTyZY64UWmJ2VayGx2yU%2F01_dashboard.png?alt=media&amp;token=934eb3fd-2398-4fb7-b0ba-3b590a30ba19" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
In the left navigation, click **Installation**.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FfLj03hLk5d3M4AG7pVHW%2F02_installation-menu.png?alt=media&amp;token=f7e777d1-8b60-413a-a8c7-a435702295dd" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
Click **New Deployment**.
{% endstep %}

{% step %}
Enter the deployment name, operator account, and geographic region.
{% endstep %}

{% step %}
Click **Save**.

The new deployment appears in the Installation list, ready to receive CBSD records.
{% endstep %}
{% endstepper %}

#### Add CBSD Records

This step is performed by the operator using installation parameters provided by, or verified with, the CPI.

After creating the deployment, add a CBSD record for each AP or radio that will operate at the site. Each CBSD record contains the installation parameters that the CPI reviews and digitally signs before the device can be registered.

While operators may enter and manage CBSD records in the portal, the accuracy of physical parameters — location, height, azimuth, gain, Equivalent Isotropic Radiated Power (EIRP) capability, and category — is the CPI's legal responsibility.

**To add a CBSD record, for each CBSD at the site:**

{% stepper %}
{% step %}
In the SAS portal's left navigation, click **Installation**.

The **Installation** screen displays all existing CBSD records on a map and in a list view.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F4NcKhEZjV9mxZGwKEe7N%2F03_home-installation-screen.png?alt=media&amp;token=10f0bd69-1db5-4d40-bf94-5f6901bacc26" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
In the toolbar, click<img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FB02dyUN7s1GUUw9bK5ex%2Fimage.png?alt=media&amp;token=e2171bcb-c263-4975-9770-ac9d18ca9014" alt="" data-size="line"> (Add New CBSD Config) icon.

The configuration form opens alongside the map.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F2TAdfihbSk4mF39aFyrn%2F05_cbsd-information-installation-parameters-1.png?alt=media&amp;token=5b9af235-9436-46ce-af7a-ccf81d6a473c" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
Enter the installation parameters. Required fields are marked **\***.

Refer to the [*Onyx CBRS AP Reference table*](#onyx-cbrs-ap-reference) for device information and your site survey data for location information (see [*Site Survey Data table*](#site-survey-data)*)*.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FLFMyxVV135DQdQioPm7E%2Fcbsd-information-installation-parameters.png?alt=media&amp;token=5da7d54b-dd73-43f1-b73c-cc0ebc1e2e40" alt="" width="491"><figcaption></figcaption></figure></div>

{% hint style="info" %}
**NOTE**: Enter all installation parameters accurately. The SAS compares the CPI-signed CBSD record stored in the SAS portal with the registration request submitted later by the DP. Any missing or mismatched parameters will cause registration to fail.
{% endhint %}
{% endstep %}

{% step %}
To save the CBSD record, click **Submit**.

The CBSD appears on the map with **Unregistered** status.
{% endstep %}

{% step %}
To mark the record as ready for CPI review and signing, click **Ready for CPI**.

{% hint style="info" %}
**NOTE**: The Onyx Portal automatically submits the CBSD registration request to the SAS as soon as the SAS-enabled AP or cell configuration is saved. Ensure every CBSD record has been reviewed and signed by the CPI in the SAS portal before saving that configuration in the Onyx Portal. If the configuration is saved while CPI signing is still incomplete, Onyx will submit the registration attempt automatically anyway, and the SAS will reject it.
{% endhint %}

{% hint style="info" %}
**NOTE**: If any installation parameters are updated after CPI signing, the SAS portal will flag the CBSD as requiring re-registration. The CPI must re-sign the record before registration can be re-triggered.
{% endhint %}

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FjPW19zLPt8mDAj7NQXkm%2F11_confirmation-message.png?alt=media&amp;token=947ffc06-e79c-49ea-b138-c504900fcb07" alt=""><figcaption></figcaption></figure></div>
{% endstep %}
{% endstepper %}

#### Sign CBSD Records

After installation parameters have been entered, a CPI must review and digitally certify the information before the CBSD can be registered with the SAS.

Only the CPI associated with the verified SAS account can perform this operation. During signing, the SAS uses the CPI's validated credentials to generate a digital signature that cryptographically associates the CPI's identity with the installation parameters.

Before signing a CBSD record, the CPI is responsible for independently verifying that all installation information accurately reflects the physical deployment. This includes, as applicable, the device location, antenna configuration, installation height, azimuth, and other installation parameters required for SAS registration. By digitally signing the record, the CPI certifies the accuracy of the installation data and assumes responsibility for the information in accordance with FCC Part 96 requirements.

**To sign CBSD installation records:**

{% stepper %}
{% step %}
Log in to the SAS portal using your verified CPI account.
{% endstep %}

{% step %}
In the left navigation, click **Installation**.
{% endstep %}

{% step %}
Locate the CBSD that requires CPI certification.
{% endstep %}

{% step %}
Open the CBSD installation record.
{% endstep %}

{% step %}
Verify that all installation parameters are complete and accurate.
{% endstep %}

{% step %}
Click **Sign** to digitally certify the installation record.
{% endstep %}

{% step %}
Confirm that the CBSD status indicates the record has been signed and is ready for SAS registration.

After the record has been signed, the Onyx Portal can submit the CBSD registration request to the SAS.
{% endstep %}
{% endstepper %}

{% hint style="info" %}
**NOTE**: Any modification to CPI-signed installation parameters invalidates the existing digital signature. Before the CBSD can be registered with the SAS, the CPI must review the updated information and re-sign the installation record.
{% endhint %}

### GXC Onyx Portal Procedures

The GXC Onyx Portal procedures configure the SAS-related settings required before CBSD registration. Technology-specific differences for 4G and 5G deployments are documented in the respective subsections. The following workflow diagram summarizes the configuration steps for each deployment type.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FNIOwBJ5hsNYxMhzmdpmj%2Fsas-workflow-gxc-op-procedure.png?alt=media&amp;token=2d448aba-f142-4c5c-8d2b-0e1635cca504" alt="" width="563"><figcaption></figcaption></figure></div>

#### Common SAS Configuration Parameters

The following table describes the SAS-related parameters configured in the Onyx Portal. These parameters apply to both 4G and 5G deployments and are referenced in the configuration steps below.

<p align="center"><strong>Table: Common SAS Configuration Parameters</strong></p>

<table><thead><tr><th width="200">Parameter</th><th>Description</th><th>Guidance</th></tr></thead><tbody><tr><td><strong>Operation Mode</strong></td><td><strong>SAS</strong> enables CBRS spectrum access via the Spectrum Access System.</td><td><strong>Manual,</strong> the default mode, disables SAS integration entirely; must never be used for CBRS.</td></tr><tr><td><strong>User ID</strong></td><td>SAS account's user ID for CBSD registration and authentication.</td><td>Must match exactly what's in the SAS portal — a mismatch causes MISSING_PARAM/INVALID_VALUE rejection.</td></tr><tr><td><strong>CBSD Category</strong></td><td>FCC power class for the CBSD.</td><td>Cat A ≤30 dBm EIRP (typically indoor/short-range), Cat B ≤47 dBm EIRP (typically outdoor). Must match what's certified for the Device Class and what the CPI signs in the SAS portal. For device-specific limits, see <a href="#onyx-cbrs-ap-reference"><em>Onyx CBRS AP Reference table</em></a>.</td></tr><tr><td><strong>Antenna Gain (dBi)</strong></td><td>Gain of the installed antenna.</td><td>Do not estimate — use spec values. See <a href="#onyx-cbrs-ap-reference"><em>Onyx CBRS AP Reference table</em></a>.</td></tr><tr><td><strong>Preferred Max Pwr (dBm)</strong></td><td>Maximum transmit EIRP requested for this CBSD.</td><td>Must not exceed the CBSD Category limit — for Cat A, ≤30 dBm. See <a href="#onyx-cbrs-ap-reference"><em>Onyx CBRS AP Reference table</em></a>.</td></tr><tr><td><strong>Preferred BW (MHz)</strong></td><td>Requested channel bandwidth: 10 or 20 MHz.</td><td>10 MHz is recommended for most indoor deployments; 20 MHz for higher-capacity outdoor cells. If the preferred bandwidth isn't available, the Domain Proxy will automatically fall back to a narrower one unless Strict Freq Preference is enabled.</td></tr><tr><td><strong>Preferred Freq (MHz) in priority order</strong></td><td>The CBSD's preferred operating frequencies within the CBRS band, in priority order.</td><td>5 MHz increments. Within 3555–3695 MHz for 10 MHz BW, or 3560–3690 MHz for 20 MHz BW. Default: Auto.</td></tr><tr><td><strong>Strict Freq Preference</strong></td><td><strong>True</strong>: The CBSD only accepts a grant on one of the preferred frequencies.<br><strong>False</strong>: The SAS may assign any available frequency.</td><td>Set True for Shared Cell / multi-CBSD groups that must operate on the same channel. Set False for standalone CBSDs where operating on a non-preferred frequency is acceptable. When False, the DP will first attempt preferred frequencies; if none are available, it will select any available frequency from the SAS response.</td></tr><tr><td><strong>Transmit</strong></td><td><strong>Enabled</strong>/<strong>Disabled</strong> — administratively controls whether this CBSD is allowed to transmit once authorized.</td><td>When <strong>Disabled</strong>, even after a successful grant the AP will not radiate until switched to <strong>Enabled</strong>.</td></tr></tbody></table>

#### 4G Configuration

{% hint style="info" %}
**NOTE**: This section describes only the SAS-related configuration required for 4G APs. For complete instructions on adding and managing 4G APs, refer to *4G Onyx Portal Operations Guide* > *Manage Access Points*.
{% endhint %}

**To add a 4G AP:**

{% stepper %}
{% step %}
In the Onyx Portal, click **Equipment** > **Access Point** tab.
{% endstep %}

{% step %}
In the upper-right corner, click **Add Node** > **Add Access Point.**
{% endstep %}

{% step %}
In the **Create Access Point** page > **Access Point** tab, enter the AP's details.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F6vnC6UISbCtDIwCvQQ51%2Fimage.png?alt=media&amp;token=aa7b3342-e27f-48e7-bbd5-8170750b9cbd" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
In the **RAN** tab, configure the required fields referring to the [*Common SAS Configuration Parameters table*](#common-sas-configuration-parameters).

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FIpQJgizToBR0vpa9c1Py%2Fimage.png?alt=media&amp;token=b44d5b03-4d8b-430d-a311-13f5e82b4189" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
**NOTE**: Dual Carrier and Carrier Aggregation deployments require separate frequency grants for each carrier. Plan your preferred frequency list carefully to avoid grant conflicts between carriers on the same AP.
{% endhint %}
{% endstep %}

{% step %}
Save the AP.

After the AP is saved, registration begins automatically if SAS is enabled and the corresponding CBSD record has already been digitally signed by the CPI in the SAS portal.
{% endstep %}
{% endstepper %}

#### 5G Configuration

5G APs use an O-RAN 7-2x split architecture. SAS registration is managed at the cell level through the Onyx Edge CU/DU, not directly at the AP level.

{% hint style="info" %}
**NOTE**: This section describes only the SAS-related configuration required for 5G APs. For complete instructions on adding and managing 5G APs, see 5*G Onyx Portal Operations Guide* > *Manage Access Points*.
{% endhint %}

**To configure SAS for a 5G deployment:**

{% stepper %}
{% step %}
Add the AP.

1. In the Onyx Portal, click **Equipment**.

2. In the upper-right corner, click **Add Node** > **Add Access Point**.

   The **Create Access Point** page is displayed.<br>

   <div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FGIgw7WF94nv5oRnTt7Sd%2Fimage.png?alt=media&amp;token=6fd5c487-81ad-4d96-b061-7087ca95921d" alt=""><figcaption></figcaption></figure></div>

3. Enter the AP's details.

4. In the upper-right corner, click **Save Access Point**.
   {% endstep %}

{% step %}
Add a cell.

1. Click **Equipment** > **Onyx Edge** tab.

2. In the list of Onyx Edge, in the **Actions** column, click the corresponding Options icon, then click **Edit**.\
   The **Edit Onyx Edge (<*****onyx-edge-name*****>)** page is displayed.<br>

   <div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2Fve7N3CmTBEnxnQdj7uPX%2Fimage.png?alt=media&amp;token=87a4fabe-39e0-4d34-8b91-d11a52af504e" alt=""><figcaption></figcaption></figure></div>

3. Click the **RAN** tab.<br>

   <div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FGEgUc631Fdur2Ml6f10k%2Fimage.png?alt=media&amp;token=beb4847c-3572-49f8-b05d-f042836dd6bb" alt=""><figcaption></figcaption></figure></div>

4. If the Onyx Edge contains any SAS-enabled cells, delete all of them before continuing:
   1. For each SAS-enabled cell, click the corresponding ⋮ (options) icon, then click **Delete**.<br>

      <div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FdBzFZtiMoSA0prWyKmRu%2Fimage.png?alt=media&amp;token=ef10a7b2-20f5-4745-a2bb-8faf1bd6a10d" alt=""><figcaption></figcaption></figure></div>
   2. To save the Onyx Edge, in the upper-right corner, click **Save Onyx Edge**.
   3. To continue to the next step, once again edit the Onyx Edge and return to the **RAN** tab.

5. To add a cell, click **Add Cell**.<br>

   <div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FICoAphVL8fdubDo5IStM%2Fimage.png?alt=media&amp;token=f728a56d-d1b2-44da-8f32-f552a1fc72a8" alt=""><figcaption></figcaption></figure></div>

6. The **Add Cell** dialog box is displayed.
   * In case of Multi-Port Attach disabled:<br>

     <div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F7vOJgStnIGUY9myqng2T%2F5g-add-cell-2%20-%20Copy.png?alt=media&amp;token=0cebf57e-6759-4709-9ae8-9df6061bd345" alt=""><figcaption></figcaption></figure></div>

   * In case of Multi-Port Attach enabled:

     <div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FqRZ4oWKnQceH4BDzXHld%2F5g-add-cell%20-%20Copy.png?alt=media&amp;token=96eea620-cff7-4e76-8c12-c8600e110d41" alt=""><figcaption></figcaption></figure></div>

7. Enter the following details:
   1. **SAS Enabled**: On.
   2. **User ID**, **Preferred BW (MHz)**, **Preferred Freq (MHz) in Priority Order**, **Strict Freq Preference**: Per the [*Common SAS Configuration Parameters table*](#common-sas-configuration-parameters).
   3. **PSS**: (Physical Synchronization Signal index, 0–2). Sets the Physical Cell ID. Ensure no two adjacent cells share the same PSS value.
   4. **Associated AP/FHM**: Select the AP/FHM added in Step 1.
   5. **CBSD Category** and **Antenna Gain**: Per the [*Onyx CBRS AP Reference table*](#onyx-cbrs-ap-reference)*.*
      * When Multi-Port Attach is disabled:&#x20;
        * **Antenna Gain (dBi)**: Configure a single antenna gain.
        * **No. of Antenna Ports**: Select the number of antenna ports.&#x20;
      * When Multi-Port Attach is enabled:
        * **Antenna Gain (n) (dBi)**: Add one entry per antenna port using the ![](https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FlirRG2GUQgodytjOyiBd%2Fimage.png?alt=media\&token=ee3c55e1-0a57-4b68-9ca3-43c8129c70f5) button.
        * **CBSD Category:** Auto-selected based on **Associated AP/FHM**.

8. To save the cell, click **Submit**.

9. To save the Onyx Edge, click **Save Onyx Edge**.

{% hint style="info" %}
**NOTE**: In Multi-Cell / Shared Cell deployments where multiple APs belong to the same cell, all CBSDs must receive a spectrum grant on the same frequency before any CBSD begins transmitting. Enable Strict Freq Preference to keep the group synchronized. If any CBSD fails to obtain a grant, transmission is held off for the entire group.
{% endhint %}

{% hint style="info" %}
**NOTE**: In Multi-Port Attach deployments, a single AP serving multiple antennas requires a separate CBSD registration for each antenna. The maximum EIRP for each antenna must be calculated individually using the following formula:

`P(dBm) = EIRP(dBm) − Antenna_Gain(dBi) + 10×log₁₀(BW_MHz / number_of_ports)`

Because the effective EIRP depends on the antenna configuration, bandwidth, and port allocation, GXC recommends verifying the calculated values before submitting CBSD registrations. For assistance with deployment-specific EIRP calculations, contact GXC Technical Support.
{% endhint %}
{% endstep %}
{% endstepper %}

### Bulk Registration (DAS / Large Deployments)

For Distributed Antenna System (DAS) and other large-scale deployments, CBSD registration can be performed in bulk instead of creating and signing each CBSD record individually. Bulk registration reduces the time required to provision large numbers of CBSDs while maintaining the same SAS registration workflow and CPI certification requirements.

**Bulk Registration Workflow:**

1. In the Onyx Portal, download the preformatted bulk CBSD registration template.
2. Populate the template for each CBSD: CBSD ID/Name, Latitude/Longitude, Antenna Height (meters), Azimuth, Indoor/Outdoor flag, Antenna Gain, EIRP, FCC ID, Serial Number, and any other required parameters.
3. Review and validate all entries. Errors in bulk files can cause simultaneous registration failures across multiple CBSDs.
4. Upload the completed template file to the SAS portal.\
   The system creates a CBSD record for each entry.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>NOTE</strong>: CPI signing is not bypassed by bulk upload. After upload, a CPI must review and sign each CBSD record (or batch-sign if supported by the SAS portal) before any registration requests are submitted. Bulk upload only populates parameters; it does not replace CPI validation.</p></div>
5. CPI reviews and signs all CBSD records.
6. Save or enable the bulk-uploaded AP/cell configuration in the Onyx Portal. Registration requests for all CBSDs in the batch are submitted to the SAS automatically once CPI signing is complete for each record — no separate manual trigger is required.
7. Monitor each CBSD for Authorized status.
8. Address any individual failures using the error codes in [*SAS Response Codes*](#sas-response-codes) and [*Common Failures*](#common-failures).

## Verify CBSD Status

This section describes the CBSD registration and grant lifecycle, from initial registration through to the Authorized state — the target operational state in which CBSDs are permitted to transmit.

### **CBSD Registration and Grant Lifecycle**

The following diagram and workflow illustrate the complete CBSD registration and grant lifecycle.

<p align="center"><strong>Figure: CBSD Registration and Grant Lifecycle</strong></p>

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FMOfmV6ZLpWlR5ktvDjIS%2Fsas-cbsd-status-transitions.png?alt=media&amp;token=273ab5ea-3097-48d1-9731-dc2880b75f27" alt=""><figcaption></figcaption></figure></div>

1\. Unregistered

* The initial state of every CBSD.
* The CBSD has no contact with the SAS and is not permitted to transmit.
* The CBSD sends a registration request to the SAS through the DP.
* If registration succeeds, the SAS validates the CBSD identity and installation parameters, assigns a CBSD ID, and the CBSD transitions to the Registered state.
* The CBSD returns to the Unregistered state when:
  * The registration request is rejected.
  * The operator explicitly deregisters the CBSD.
  * Installation parameters are modified after CPI signing.
* In these cases, all active grants are removed, and the CBSD must be fully re-registered, including CPI re-signing in the SAS portal.

2\. Registered

* The CBSD has successfully completed registration and received a CBSD ID.
* The SAS has validated the CBSD identity and installation parameters.
* The CBSD does not yet hold a spectrum grant and cannot transmit.
* The CBSD automatically transitions to the Idle state.

3\. Idle

* The CBSD is registered but does not hold an active spectrum grant.
* The CBSD enters the Idle state:
  * Immediately after successful registration.
  * When a spectrum grant is terminated, relinquished, or expires.
* The CBSD automatically submits a grant request to the SAS.
* If the SAS returns Grant Request: Success, the CBSD transitions to the Granted state.

4\. Granted

* The SAS has assigned spectrum resources.
* The CBSD has not yet received transmit authorization and must not transmit.
* The CBSD sends heartbeat requests to the SAS.
* If the SAS returns Heartbeat Response: Transmit, the CBSD transitions to the Authorized state.

5\. Authorized (Normal Operating State)

* The CBSD has:
  * Successfully registered with the SAS.
  * Obtained a spectrum grant.
  * Received transmit authorization through a successful heartbeat response.
* The CBSD is permitted to transmit on its assigned spectrum.
* To maintain authorization, the CBSD sends periodic heartbeat requests.
* As long as the SAS continues to return Heartbeat Response: Transmit, the CBSD remains in the Authorized state.

#### Fallback State Transitions

During normal operation, the CBSD may temporarily transition to an earlier state based on SAS responses.

* Heartbeat does not extend transmit authorization (Response Code 400) — If the SAS does not extend transmit authorization during a heartbeat exchange, the CBSD returns to the Granted state.
  * The spectrum grant is retained, but transmit authorization is temporarily suspended.
  * The Onyx Portal automatically continues sending heartbeat requests.
  * When the SAS again authorizes transmission, the CBSD returns to the Authorized state.
  * No operator action is required for transient heartbeat failures.
* Grant is no longer valid (Response Code 401) — If the SAS indicates that the current spectrum grant is no longer valid (for example, because it has expired, been relinquished, or been terminated), the CBSD returns to the Idle state.
  * The existing spectrum grant is released.
  * The CBSD automatically requests a new spectrum grant from the SAS.
  * Once a new grant is approved and transmit authorization is restored, the CBSD returns to the Authorized state.
* Deregistration or configuration changes — If the operator explicitly deregisters the CBSD, or if installation parameters are modified after CPI signing, the CBSD returns to the Unregistered state.
  * All active spectrum grants are removed.
  * The CBSD must be fully re-registered, including CPI re-signing in the SAS portal, before the CBSD can obtain a new grant and resume transmission.

### Verify CBSD Status in Onyx Portal

Monitor the CBSD status in the Onyx Portal to confirm that registration, spectrum grant acquisition, and transmit authorization have completed successfully.

**To verify the CBSD status in the Onyx Portal:**

{% stepper %}
{% step %}
Navigate to in **Equipment** > **Access Point** tab > AP details page > **Overview** tab > **RAN** section.
{% endstep %}

{% step %}
Verify that all three status indicators—**Registered**, **Granted**, and **Authorized**—are displayed in green.

When all three indicators are green, the CBSD is successfully registered with the SAS, has an active spectrum grant, and is authorized to transmit.

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FGxfDBXSMxQYMjQZo1pIg%2Fimage.png?alt=media&amp;token=c0ac5308-fe79-41de-b392-46141124c86b" alt="" width="563"><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

<p align="center"><strong>Table: CBSD Status Descriptions</strong></p>

<table><thead><tr><th width="150">Status</th><th width="125">Color</th><th>Description</th></tr></thead><tbody><tr><td>Registered</td><td>Green</td><td>All CBSDs are registered with SAS.</td></tr><tr><td></td><td>Amber</td><td>Some CBSDs are registered, some not yet.</td></tr><tr><td></td><td>Red</td><td>No CBSDs are registered.</td></tr><tr><td>Granted</td><td>Green</td><td>Required number of spectrum grants are active.</td></tr><tr><td></td><td>Amber</td><td>Some grants are active, but not the full required number.</td></tr><tr><td></td><td>Red</td><td>No grants are available.</td></tr><tr><td></td><td>Grey</td><td>No CBSDs are registered.</td></tr><tr><td>Authorized</td><td>Green</td><td>CBSDs are authorized to transmit (normal operating state).</td></tr><tr><td></td><td>Amber</td><td>Some CBSDs authorized, partial coverage.</td></tr><tr><td></td><td>Red</td><td>No authorizations. CBSDs cannot transmit.</td></tr><tr><td></td><td>Grey</td><td>No grants are available.</td></tr></tbody></table>

### Verify CBSD Status in SAS Portal

Verify the CBSD status in the SAS portal to confirm that the CBSD is registered, has received a spectrum grant, and is authorized to transmit.

**To verify the CBSD status in the SAS portal:**

1. Log in to the SAS portal.
2. On the **Installation** page, locate the CBSD in either the **Installation Map** or **List View**.
3. Verify that the CBSD displays an **AUTHORIZED** status.\
   \
   A green **AUTHORIZED** badge indicates that the CBSD has an active spectrum grant and is authorized to transmit.<br>

   <div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FX3N5cj5Mu7sJUwpKE4xG%2F12_cbsd-status.png?alt=media&amp;token=b0ea2209-4497-4b46-a614-bf99627ee507" alt=""><figcaption></figcaption></figure></div>
4. Click **More Info** to view detailed CBSD information.
5. Review the following tabs as needed:
   * **Grant Information** — Displays active spectrum grants, assigned GAA channels, EIRP, and grant expiration times.<br>

     <div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FlOTyPcxpgetTzWQc3yLt%2F13_more-info-1.png?alt=media&amp;token=2fa5b63e-6e3f-46bf-8687-f2946fc48134" alt=""><figcaption></figcaption></figure></div>
   * **CBSD Information** — Displays the CBSD state (**AUTHORIZED**), category, GAA grant count, serial number, and FCC ID registered with the SAS.<br>

     <div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2Fdv4qfQamMBrSZbIm89Be%2F15_more-info-3.png?alt=media&amp;token=3165617d-d0fb-4d43-90d8-748ba0a98953" alt=""><figcaption></figcaption></figure></div>
   * **Logs Information** — Displays message types, timestamps, and SAS response codes.<br>

     <div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2Fgo2X9y0QutlqMKufNqDy%2F14_more-info-2.png?alt=media&amp;token=8807b4a6-15c5-4307-81a7-e842a297b764" alt=""><figcaption></figcaption></figure></div>
   * **State Changes** — Displays the CBSD state transition history.
   * **CBSD Configuration Changes** — Displays the configuration change history for the CBSD.

## Troubleshooting

Use this section to diagnose and resolve CBSD registration, grant, and authorization issues across the GXC Onyx and Federated Wireless SAS ecosystem.

Begin with the [*Troubleshooting Workflow*](#troubleshooting-workflow), then consult the Onyx Portal SAS-related alerts, SAS response codes, and common failures sections as directed for detailed diagnostics and corrective actions.

### Troubleshooting Workflow

Use the following workflow to identify and resolve CBSD registration, spectrum grant, and transmit authorization issues.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2Fm8zX2mQOTxD4yddMfJz5%2Fsas-troubleshooting.png?alt=media&amp;token=94e9981c-772e-4c1e-a139-66b56a8d7d26" alt=""><figcaption></figcaption></figure></div>

{% stepper %}
{% step %}
Check Onyx Portal alerts.

* In the Onyx Portal, check the Alerts Counter Panel.
* If active alerts are present, navigate to **Alerts** > **Active Alerts** tab and check for SAS-related alerts.
* See [*Onyx Portal SAS-Related Alerts*](#onyx-portal-sas-related-alerts) for alert details and recommended corrective actions.
  {% endstep %}

{% step %}
Verify the CBSD SAS status and review DP/SAS logs.

* In the Onyx Portal, navigate to **Equipment** > **Access Point** tab > AP details page > **Overview** tab > **RAN** section to verify the CBSD status. See [*Verify CBSD Status in Onyx Portal*](#verify-cbsd-status-in-onyx-portal).
* Review the DP logs in **Equipment** > **Access Point** tab > AP details page > **Logs** tab > **DP Logs** section. The DP logs record all registration, spectrum grant, heartbeat, and error responses.
* In the Federated Wireless SAS portal, on the **Installation** screen, locate the CBSD, and click **More Info**, then select the **Logs Information** tab. This tab displays all message types with timestamps, response codes, and transmit expiration times.
* A SAS response code of 0 indicates success. For any non-zero response code, refer to [*SAS Response Codes table*](#sas-response-codes).
  {% endstep %}

{% step %}
Identify the failure stage.

Compare the observed Onyx Portal alerts, CBSD status, and SAS response codes against the following table to identify the most likely failure stage and the appropriate resolution workflow.

| What you see                                         | Failure stage                           | Start here                                                                                                                                                                            |
| ---------------------------------------------------- | --------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| CBSD shows "Unregistered" / no change                | Domain Proxy to SAS connectivity        | Check firewall, DNS, and Onyx Edge network access to SAS endpoint.                                                                                                                    |
| SAS portal shows "Pending Registration" (no advance) | CBSD not sending registration request   | Verify AP is powered; confirm Serial No. and FCC ID match; confirm Onyx Edge is reachable.                                                                                            |
| SAS portal shows "Ready for CPI" (no advance)        | CPI signing incomplete                  | CPI must sign the CBSD record before any registration request is sent.                                                                                                                |
| Registration rejected (codes 104, 105, 106, 501)     | Parameter or certificate error          | Review error code in [*SAS Response Codes*](#sas-response-codes). Correct the parameter and re-trigger registration.                                                                  |
| Registered, no grant (codes 200, 300)                | Spectrum availability or EIRP issue     | Review error code in [*SAS Response Codes*](#sas-response-codes). Check frequency range, EIRP limits, ESC/incumbent activity.                                                         |
| Grant suspended / terminated (codes 400, 401)        | Incumbent protection event              | Review error code in [*SAS Response Codes*](#sas-response-codes). Normal SAS behavior. Onyx auto-retries. If persistent, contact SAS vendor support.                                  |
| SAS Connection Failure alert active                  | Domain Proxy cannot reach SAS           | Check Onyx Edge connectivity to SAS on port 443. See [*Onyx Portal SAS-Related Alerts*](#onyx-portal-sas-related-alerts).                                                             |
| CBSD Registration Failure alert active               | Parameter mismatch or CPI signing issue | Check DP logs. Verify FCC ID, serial number, category, location, and antenna parameters across both portals. See [*Onyx Portal SAS-Related Alerts*](#onyx-portal-sas-related-alerts). |

{% endstep %}

{% step %}
If the CBSD is Unregistered, verify the CBSD parameters are consistent across Onyx Portal and SAS portal.

Parameter mismatches between the Onyx Portal and SAS portal are the most common cause of registration failures. Before retrying registration, verify that:

* The serial number is identical in both portals and matches the physical AP label.
* The FCC ID exactly matches the [*Onyx CBRS AP Reference table*](#onyx-cbrs-ap-reference).
* Antenna height is entered in meters (not in feet).
* Height Type (AGL or AMSL) matches the configured height.
* The Indoor/Outdoor flag is set correctly (affects CBSD category and EIRP limits).
* CPI signing is complete and the record shows "Pending Registration" in the SAS portal.
  {% endstep %}

{% step %}
If the CBSD is not Authorized, verify spectrum availability. If the configured values are not available, consider switching to other available center frequencies and bandwidth.

1. Navigate to **Equipment** > **Access Point** tab > AP details page > **Overview** tab > **RAN** section > **SAS Configuration** section and note values set for **Preferred Freq (MHz)** and **Preferred BW (MHz)**.
2. To verify available spectrum, on the same AP details page, under the **SAS Status** section, click **View Available Spectrum**. The graph shows spectrum availability per 5 MHz steps — confirm that the preferred frequencies and bandwidth are shown as available.<br>

   <div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FBEN4g200H4v39dIzUFIz%2Fimage.png?alt=media&amp;token=9463506f-d133-456e-bc00-50660fc373c4" alt=""><figcaption></figcaption></figure></div>

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>NOTE</strong>: Each bar represents a 5 MHz spectrum segment. To verify bandwidth availability, confirm that the number of consecutive green bars covering your center frequency equals your bandwidth divided by 5 (for example, a 20 MHz bandwidth requires 4 consecutive green bars centered on your preferred frequency).</p></div>

{% endstep %}

{% step %}
Escalate if the issue persists.

* GXC Technical Support (*<support@gxc.io>*) — Provide the AP serial numbers, FCC IDs, SAS response codes from the DP logs, and screenshots from both the Onyx Portal and the SAS portal to expedite troubleshooting.
* SAS Vendor Support — For SAS-side issues (grant availability, ESC events, blacklisting), contact the SAS Vendor Support directly.
  {% endstep %}
  {% endstepper %}

### Onyx Portal SAS-Related Alerts

The Onyx Portal generates predefined alerts for SAS and DP events. The following alerts are directly relevant to CBRS registration and spectrum grant operation. These alerts are applicable to both 4G and 5G networks.

To monitor Onyx Portal alerts:

* Monitor the Alerts Counter Panel in the Onyx Portal's header.
* Navigate to **Alerts** > **Active Alerts** tab.

#### **CBSD Registration Failure**

<table data-header-hidden><thead><tr><th width="199.5555419921875"></th><th></th></tr></thead><tbody><tr><td><strong>Trigger Condition</strong></td><td>When one or more CBSD registration attempts fail within the last hour.</td></tr><tr><td><strong>Clear Condition</strong></td><td>When no registration failures occur for at least one hour.</td></tr><tr><td><strong>Severity</strong></td><td>Major</td></tr><tr><td><strong>System Impact</strong></td><td>The AP becomes non-functional — it cannot obtain grants or transmit.</td></tr><tr><td><strong>Where to Look</strong></td><td><strong>Equipment</strong> > <strong>Access Point</strong> tab > AP details page > <strong>Overview</strong> > SAS status — shows Registered indicator in red. The <strong>Dashboard</strong> > <strong>Access Point/DAS SAS Status</strong> tile will also reflect the failure.</td></tr><tr><td><strong>Resolution</strong></td><td><ol><li>Check the AP's DP logs for failure reason (<strong>Equipment</strong> > <strong>Access Point</strong> tab > AP details page > <strong>Logs</strong> tab > <strong>DP Logs</strong> section).</li><li>The most common cause is a parameter mismatch between the Onyx Portal and the SAS portal. Verify parameters across both portals.</li><li>Refer to the <a href="https://www.claudeusercontent.com/?domain=claude.ai&#x26;parentOrigin=https%3A%2F%2Fclaude.ai&#x26;errorReportingMode=parent&#x26;formattedSpreadsheets=true&#x26;routeHandlerPdf=true#sas-response-codes"><em>SAS Response Codes</em></a> table for code details and next steps.</li></ol></td></tr><tr><td><strong>Resolution Verification</strong></td><td>The Alerts Counter Panel reverts to pre-incident levels, and all Dashboard tiles return to their pre-incident states.</td></tr></tbody></table>

#### **CBSD Lesser BW Granted**

<table data-header-hidden><thead><tr><th width="199.5555419921875"></th><th></th></tr></thead><tbody><tr><td><strong>Trigger Condition</strong></td><td>When a CBSD has been granted less bandwidth than configured, and this condition persists for at least five minutes.</td></tr><tr><td><strong>Clear Condition</strong></td><td>When the CBSD receives the desired bandwidth or loses the grant.</td></tr><tr><td><strong>Severity</strong></td><td>Major</td></tr><tr><td><strong>System Impact</strong></td><td>Network capacity is reduced from what was planned. Dashboard <strong>Downlink/Uplink Traffic</strong> and <strong>Data Usage</strong> tiles will reflect the reduction.</td></tr><tr><td><strong>Resolution</strong></td><td><ol><li>Check if any maintenance activity is currently in progress.</li><li>In the AP's DP logs, check the Spectrum Inquiry Response to identify available frequencies (<strong>Equipment > Access Point</strong> tab > AP details page > <strong>Logs</strong> tab > <strong>DP Logs</strong> section).</li><li>If Strict Preference is enabled, consider disabling it or adjusting the preferred frequency to one with higher available bandwidth (<strong>Equipment</strong> > <strong>Access Point</strong> tab > AP details page > <strong>RAN</strong> tab > <strong>Strict Preference</strong>).</li><li>If unresolved, contact GXC Technical Support.</li></ol></td></tr><tr><td><strong>Resolution Verification</strong></td><td><ul><li>All Dashboard tiles return to pre-incident states.</li><li>Confirm the granted bandwidth (<strong>Equipment</strong> > <strong>Access Point</strong> tab > AP details page > <strong>Overview</strong> tab > <strong>RAN</strong> tile > <strong>BW (MHz)</strong> parameter).</li></ul></td></tr><tr><td><strong>Related Alert</strong></td><td><a href="#cbsd-new-grant"><em>CBSD New Grant</em></a> may trigger alongside CBSD Lesser BW Granted.</td></tr></tbody></table>

#### **CBSD New Grant**

This is an informational alert — no corrective action is required.

<table data-header-hidden><thead><tr><th width="199.5555419921875"></th><th></th></tr></thead><tbody><tr><td><strong>Trigger Condition</strong></td><td>When a new grant is received from the SAS within the last hour.</td></tr><tr><td><strong>Clear Condition</strong></td><td>When no new grants are received for at least one hour. </td></tr><tr><td><strong>Severity</strong></td><td>Warning</td></tr><tr><td><strong>System Impact</strong></td><td>For an AP already transmitting, a new grant may change the transmission frequency, bandwidth, or power level. Verify the new grant parameters do not adversely affect required KPIs. If the new grant carries less bandwidth than configured, a <a href="#cbsd-lesser-bw-granted"><em>CBSD Lesser BW Granted</em></a> alert may also trigger.</td></tr><tr><td><strong>Additional Information</strong></td><td>Each grant change generates this alert, making it useful for tracking all grant modifications. The initial grant for an AP also triggers this alert.</td></tr></tbody></table>

#### **CBSD Preferred Frequency Unavailable**

<table data-header-hidden><thead><tr><th width="199.5555419921875"></th><th></th></tr></thead><tbody><tr><td><strong>Trigger Condition</strong></td><td>When none of the preferred frequencies configured for the CBSD are available from the SAS.</td></tr><tr><td><strong>Clear Condition</strong></td><td>When a preferred frequency becomes available again or the CBSD is deregistered.</td></tr><tr><td><strong>Severity</strong></td><td>Warning</td></tr><tr><td><strong>System Impact</strong></td><td>If Strict Preference is enabled, the AP stops transmitting. If Strict Preference is disabled, the AP continues transmitting on whatever frequency the SAS grants — but that frequency will not be in the preferred list.</td></tr><tr><td><strong>Resolution</strong></td><td><ol><li>Change the preferred frequency list (<strong>Equipment</strong> > <strong>Access Point</strong> tab > edit AP details > <strong>RAN</strong> tab).</li><li>To identify available frequencies, check the Spectrum Inquiry Response log (<strong>Equipment</strong> > <strong>Access Point</strong> tab > AP details page > <strong>Logs</strong> tab > <strong>DP Logs</strong> section > <strong>Spectrum Inquiry Response</strong>), filtering for "From SAS To DP" logs.</li></ol></td></tr></tbody></table>

#### **SAS Connection Failure**

<table data-header-hidden><thead><tr><th width="199.5555419921875"></th><th></th></tr></thead><tbody><tr><td><strong>Trigger Condition</strong></td><td>When the Domain Proxy cannot reach the SAS — specifically, when connection attempts fail at least three times within 15 minutes, or when at least one HTTP error from the SAS is received within 15 minutes.</td></tr><tr><td><strong>Clear Condition</strong></td><td>When no connection errors or HTTP errors occur for at least 15 minutes.</td></tr><tr><td><strong>Severity</strong></td><td>Critical</td></tr><tr><td><strong>System Impact</strong></td><td>This alert indicates a potential network-wide outage for all APs dependent on SAS for spectrum grants. If the connection failure persists, transmit timers will expire and cells will go down.</td></tr><tr><td><strong>Where to Look</strong></td><td><strong>Equipment</strong> > <strong>Access Point</strong> tab > AP details page > <strong>Overview</strong> tab > SAS Status — the SAS state will stop progressing, and Authorized status may revert to Granted as the transmit timer expires.</td></tr><tr><td><strong>Resolution</strong></td><td><p>Contact GXC Technical Support.</p><p>Two error types appear in alert labels:</p><ul><li>HTTP errors — Typically indicate an SAS-side issue or fundamental failure in the Domain Proxy.</li><li>Transport-level errors — May indicate connectivity issues (unable to reach SAS) or TLS authentication failures.</li></ul><p>Also verify Onyx Edge outbound connectivity to the SAS endpoint on port 443. See <em>GXC Firewall Config Application Note</em>.</p></td></tr><tr><td><strong>Additional Information</strong></td><td>SAS Connection Failure generates a single consolidated alert at the network level, not individual alerts per AP.</td></tr></tbody></table>

### SAS Response Codes

Every request exchanged between a CBSD and the SAS returns a standardized response code, as defined in the *WInnForum SAS-CBSD Technical Specification (WINNF-TS-0016)*. When a request fails, the SAS may also include additional information to help identify the cause of the failure.

**To view SAS response codes in the Onyx Portal:**

{% stepper %}
{% step %}
Navigate to **Equipment** > **Access Point** tab > AP details page > **Logs** tab > **DP Logs** section.
{% endstep %}

{% step %}
Review the SAS transaction logs. Each transaction includes the corresponding SAS response code.
{% endstep %}

{% step %}
Use the **SAS Response Codes** table to interpret the response code and determine the appropriate corrective action.
{% endstep %}
{% endstepper %}

<p align="center"><strong>Table: SAS Response Codes</strong></p>

<table><thead><tr><th width="113">Response Code</th><th width="200">Name</th><th>Meaning / Likely Cause</th><th>Resolution</th></tr></thead><tbody><tr><td>0</td><td>SUCCESS</td><td>Request succeeded.</td><td>No action needed.</td></tr><tr><td>102</td><td>VERSION</td><td>Protocol version mismatch.</td><td>Verify Onyx firmware supports current WInnForum spec version.</td></tr><tr><td>103</td><td>BLACKLISTED</td><td>CBSD is blacklisted by SAS.</td><td>Contact SAS provider support.</td></tr><tr><td>104</td><td>MISSING_PARAM</td><td>Required parameter absent from registration request.</td><td>Review all required fields in the Onyx Portal RAN/SAS settings. Check for empty User ID, FCC ID, or serial number.</td></tr><tr><td>105</td><td>INVALID_VALUE</td><td>A parameter value is out of range or format is incorrect.</td><td>Verify antenna height (must be meters, not feet), GPS coordinates format, EIRP values within category limits.</td></tr><tr><td>106</td><td>CERT_ERROR</td><td>CPI certificate error.</td><td>CPI must re-validate identity in SAS portal. Certificate may be expired or incorrectly uploaded.</td></tr><tr><td>200</td><td>INTERFERENCE</td><td>Grant denied due to incumbent or PAL protection.</td><td>Move to a different frequency or reduce EIRP. Check ESC sensor activity in your area.</td></tr><tr><td>300</td><td>UNSUPPORTED_SPECTRUM</td><td>Requested frequency is outside the CBRS band.</td><td>Verify preferred frequency is within 3555–3695 MHz (10 MHz BW) or 3560–3690 MHz (20 MHz BW).</td></tr><tr><td>400</td><td>SUSPENDED_GRANT</td><td>SAS has temporarily suspended the grant.</td><td>CBSD must stop transmitting. Onyx Portal will automatically attempt reauthorization via heartbeat. Monitor for resumption.</td></tr><tr><td>401</td><td>TERMINATED_GRANT</td><td>SAS has permanently terminated the grant.</td><td>CBSD must stop transmitting. Re-initiate grant request. If persistent, check for incumbent activity or interference in the area.</td></tr><tr><td>500</td><td>DEREGISTERED</td><td>CBSD was deregistered by SAS.</td><td>Re-register the CBSD. Investigate whether parameters changed or a delete was inadvertently triggered.</td></tr><tr><td>501</td><td>INVALID_PARAM</td><td>Invalid installation parameter in signed record.</td><td>CPI must correct and re-sign the affected CBSD record. Common cause: Parameter mismatch between SAS portal and Onyx Portal entries.</td></tr></tbody></table>

### Common Failures

The *Common Failures* table summarizes the most frequently encountered CBSD registration, spectrum grant, and transmit authorization issues, along with their likely causes and recommended corrective actions to help restore normal SAS operation.

<p align="center"><strong>Table: Common Failures</strong></p>

| Symptom                                                                   | Most Likely Cause                                                                                                                                                                                                                                                                             | Check / Resolution                                                                                                                                                                                                                                                                                                              |
| ------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| CBSD stuck in Unregistered state                                          | <p>Domain Proxy cannot reach SAS endpoint<br><br>The Onyx Edge functions as the Domain Proxy for all CBSDs at a site. A connectivity issue between the Onyx Edge and the SAS can affect registration, grant management, and heartbeat processing for all CBSDs managed by that Onyx Edge.</p> | Verify firewall rules. Onyx Edge must reach the SAS FQDN on HTTPS (443). See *GXC Firewall Config Application Note*.                                                                                                                                                                                                            |
| SAS portal shows "Pending Registration" indefinitely                      | AP not powered on or not connected to Onyx Edge; serial number or FCC ID mismatch                                                                                                                                                                                                             | Confirm AP is online in Onyx Portal. Verify that the AP serial number and FCC ID in both portals exactly match those printed on the physical AP label.                                                                                                                                                                          |
| SAS portal shows "Ready for CPI" — does not advance                       | CPI signing not completed                                                                                                                                                                                                                                                                     | CPI must log in, review parameters, and click Sign. Registration request will not be sent until signing is complete.                                                                                                                                                                                                            |
| Registration rejected — MISSING\_PARAM or INVALID\_VALUE (codes 104, 105) | Parameter mismatch or missing field between portals                                                                                                                                                                                                                                           | Cross-check all fields: height in meters (not feet), GPS to 6 decimal places, correct EIRP for category, FCC ID matches AP label.                                                                                                                                                                                               |
| Registration rejected — CERT\_ERROR (code 106)                            | Invalid or expired CPI signature                                                                                                                                                                                                                                                              | CPI re-validates identity in SAS portal and re-signs the CBSD record.                                                                                                                                                                                                                                                           |
| Registration rejected — INVALID\_PARAM (code 501)                         | Invalid installation parameter in the signed record; parameter mismatch between portals after signing                                                                                                                                                                                         | This requires CPI action, not an operator retry. The CPI must correct the affected parameter and re-sign the CBSD record before registration can be re-triggered.                                                                                                                                                               |
| CBSD registers but receives no grant                                      | Frequency conflict or EIRP exceeds limits                                                                                                                                                                                                                                                     | Verify preferred frequency is within valid range. Confirm Max EIRP does not exceed category limits. Check for incumbent/ESC activity in area.                                                                                                                                                                                   |
| Grant SUSPENDED or TERMINATED (codes 400, 401)                            | Incumbent activity or interference detected by SAS                                                                                                                                                                                                                                            | <p>This is normal SAS behavior protecting incumbents.</p><p>Response Code 400 (grant suspended): Onyx auto-retries heartbeat. No operator action required unless persistent.</p><p>Response Code 401 (grant terminated): CBSD returns to Idle state and must re-request a grant. If persistent, contact SAS vendor support.</p> |
| Multi-Port: group fails to authorize                                      | One CBSD missing parameters or EIRP calculation error                                                                                                                                                                                                                                         | Each antenna CBSD needs a complete, independent parameter set. Verify per-antenna EIRP using the multi-port formula. All CBSDs in group must be authorized before any transmits.                                                                                                                                                |

## References

* [*GXC Glossary*](https://docs.gxc.io/introduction/introduction/glossary)
* [*4G & 5G Onyx Design Guide*](https://docs.gxc.io/onyx-design-guide/onyx-design-guide)
* [*Onyx Portal Specification*](https://docs.gxc.io/onyx-software/onyx-portal-specification)
* [*5G Onyx Shared Cell /* Super Cell *Architecture Solution Brief*](https://docs.gxc.io/solution-briefs/5g-onyx-shared-cell-super-cell-architecture-solution-brief)
* [*5G Onyx Portal Operations Guide*](https://docs.gxc.io/installation-and-operations-guides/5g-onyx-portal-4.x-operations) / [*4G Onyx Portal Operations Guide*](https://docs.gxc.io/installation-and-operations-guides/4g-onyx-portal-4.x-operations)
* [*5G Onyx Portal Alerts Reference*](https://docs.gxc.io/installation-and-operations-guides/5g-onyx-portal-4.x-alerts-reference) / [*4G Onyx Portal Alerts Reference*](https://docs.gxc.io/installation-and-operations-guides/4g-onyx-portal-4.x-alerts-reference)
* [*GXC Firewall Config Application Note*](https://docs.gxc.io/application-notes/4g-and-5g-firewall-configuration-for-onyx-networks)
* *Federated Wireless SAS Portal — SAS* Portal documentation provided by Federated Wireless
* *WInnForum SAS-CBSD Technical Specification (WINNF-TS-0016)* — registration protocol, response codes, CPI installation parameters
* *FCC CBRS Rules (47 CFR Part 96)* — FCC regulatory framework for Citizens Broadband Radio Service

## Contact GXC <a href="#contact-gxc" id="contact-gxc"></a>

To get in touch with GXC, please visit [*https://gxc.io/contact-us/*](https://gxc.io/contact-us/).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.gxc.io/docs/application-notes/4g-and-5g-onyx-cbrs-sas-registration.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
