You have stood up a CA, issued from it, and put your own hierarchy behind the console. This section names the concepts behind what you just did — starting with what goca deliberately is not. Where is the portal? The self-service page, the discovery scanner, the expiry emails to certificate owners? Not here — on purpose. goca (the goca engine) is a certificate authority engine: the hardened core that generates and custodies CA keys, evaluates issuance policy, signs certificates and revocation data, and keeps a cryptographically verifiable record of everything it did.
It is deliberately headless. No end-user portal, no discovery scanner, no owner notifications — those belong to the RA/CLM layer you put in front of it: Keyfactor Command, Venafi, an in-house RA, or, for machine enrollment, the bundled protocol heads. The admin console that ships with goca is an operator console for the people who run the CA, not a portal for the people who consume certificates.
Now I can say what goca is — and what layer I still need in front of it.