Tenant console

LinkRidge Cloud app.

Dev-only session scaffold with account context, QR service state, and operator evidence. Signup, billing, invite delivery, hosted redirects, and production execution stay disabled.

Session state Preview only
API contract Operator review QR service
Loading Seed-backed static data is bundled into this page; live fetch wiring can replace it later.
Error Fail closed: mutation controls stay disabled when account context or auth evidence is missing.
Empty Panels render explicit empty states instead of implying customer access exists.
Runtime connection Static preview

Checking /health when the dev control-plane runtime is reachable; protected /v1 reads still require internal/dev authorization.

Build Not connected

Static app data stays visible when live health is unavailable.

Auth diagnostics protected Not checked

No browser token is sent from this preview shell.

Read-only API routes
/v1/accounts/v1/accounts/{account_id}/auth/token-policy/v1/accounts/{account_id}/memberships/v1/accounts/{account_id}/invites/v1/accounts/{account_id}/services/v1/accounts/{account_id}/service-tokens/v1/accounts/{account_id}/services/{account_service_id}/entitlements/v1/qr/workspaces/v1/qr/workspaces/{workspace_id}/mutation-requests/{mutation_request_id}/execution-rehearsal-requirements/v1/billing/export-requests/v1/review-packets/v1/review-packets/{review_packet_id}/decision-requirements/v1/operator-approvals/v1/audit-events
Selected account Local QR Demo

acct_local_qr_demo; status draft; external effects false.

Dev actor Local QR Owner

owner@example.invalid is owner / planned; auth-provider membership grants are disabled.

Workspace context qrw_local_demo

Service qr-codes on plan starter; hosted redirects false.

Invite delivery not_sent

1 draft invite(s); no invite email, customer login, or external user access is sent from this app.

Provisioning boundary rehearsal_only

not_executed; customer activation, billing, DNS, production routes, and QR redirects stay blocked.

Tenant home

Command center preview

read-only start
Tenant home Local QR Demo draft

Start from selected tenant identity and owner context without creating a customer account, password, magic link, provider user, or browser session.

/v1/accounts/acct_local_qr_demo
Workspace qrw_local_demo ready to inspect

QR codes, campaigns, scans, imports, and draft changes stay readable while hosted redirects, QR writes, and import execution remain blocked.

/v1/qr/workspaces/qrw_local_demo
Team access editor@example.invalid not_sent

Members and invite drafts are visible, but delivery, acceptance links, auth-provider grants, and external sessions stay disabled.

/v1/accounts/acct_local_qr_demo/invites
Launch gate Blocked safely blocked_pending_matthew_approval

Approval requirements are visible for operators, but this home screen cannot submit decisions, run production jobs, export usage, or contact customers.

/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements

The tenant home command center makes the first selected-account screen useful from account-scoped reads only; it does not create signup sessions, passwords, magic links, auth-provider users, invite delivery, customer access, billing records, hosted redirects, QR writes, usage exports, approval decisions, customer contact, or production jobs.

Onboarding guide

First-run setup path

setup writes disabled
Welcome Local QR Demo dev actor visible

Shows the first-run account welcome state from local account and owner reads without creating a signup session, password, magic link, provider user, or customer account.

/v1/accounts/acct_local_qr_demo
Workspace setup qrw_local_demo workspace readable

Lets the tenant see QR workspace setup progress while hosted redirects, destination changes, imports, customer QR writes, and mutation execution remain blocked.

/v1/qr/workspaces/qrw_local_demo
Team setup editor@example.invalid not_sent

Shows team invite and role context as setup progress only; invite delivery, acceptance links, membership activation, auth-provider grants, and external sessions stay disabled.

/v1/accounts/acct_local_qr_demo/invites
Launch review service_token blocked_pending_matthew_approval

Keeps launch completion behind operator requirements; this app does not submit approval decisions, create billing records, export usage, contact customers, or run production jobs.

/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements

The onboarding guide gives the selected tenant a first-run setup path from account-scoped reads only; it does not create signup sessions, passwords, magic links, auth-provider users, customer accounts, invite delivery, membership activation, billing records, hosted redirects, QR writes, usage exports, approval decisions, customer contact, or production jobs.

Session center

Login context preview

real login disabled
Signed-in preview Local QR Owner dev session only

Shows who the app would treat as the selected tenant actor without creating a password, magic link, provider session, browser token, or customer login.

/v1/accounts/acct_local_qr_demo/auth/token-policy
Membership check owner planned

Membership scope is visible for account context only; auth-provider grants, membership activation, external user access, and invite acceptance remain disabled.

/v1/accounts/acct_local_qr_demo/memberships
Account switcher Local QR Demo hash-scoped

Switching tenants changes the visible account panel and route context, but it never broadens read scope or enables cross-account writes.

/app/
Auth diagnostics Protected read tokens hidden

Diagnostics can prove runtime auth posture without returning token values, token hashes, request hashes, or idempotency keys to the browser.

/v1/auth/diagnostics
Invite handoff editor@example.invalid not_sent

Invite handoff stays as local read state; no invite email, acceptance link, provider user, customer session, or membership activation is created.

/v1/accounts/acct_local_qr_demo/invites

The session center makes login context visible from account-scoped read state only; it does not create passwords, magic links, browser tokens, provider users, external sessions, invite delivery, membership activation, token secrets, hosted redirects, QR writes, customer contact, billing records, or production jobs.

Account settings

Tenant configuration preview

settings disabled
Account profile Local QR Demo draft

Name, owner, and account status can be reviewed in dev without creating customer login sessions or external account access.

/v1/accounts/acct_local_qr_demo
Workspace defaults qrw_local_demo planned

QR workspace defaults stay read-only; hosted redirects, destination writes, imports, and QR record mutations remain disabled.

/v1/qr/workspaces/qrw_local_demo
Team and roles 1 member(s) 1 invite draft(s)

Role and invite settings are visible for account context only; invite delivery, acceptance links, and auth-provider grants stay off.

/v1/accounts/acct_local_qr_demo/invites
Plan and billing starter blocked

Plan and usage settings show local read state without creating billing customers, subscriptions, invoices, or export jobs.

/v1/billing/export-requests
Security access owner@example.invalid owner

Security settings link to token policy diagnostics but never issue token secrets, store hashes, or broaden tenant scope.

/v1/accounts/acct_local_qr_demo/auth/token-policy
Support preferences Review Starter Open QR import before tenant writes blocked

Support preferences remain local preview state; replies, ticket sync, customer contact, and external archives are disabled.

/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/support-cases

The account settings preview makes tenant configuration visible from account-scoped read routes only; it does not save profile changes, connect domains, change plans, enable SSO, create signup sessions, send invites, grant auth-provider access, issue token secrets, publish hosted redirects, write QR records, contact customers, export usage, or run production jobs.

Integrations center

Connection setup preview

connectors disabled
Webhook endpoint Review Starter Open QR import before tenant writes delivery disabled

Future webhook setup can show the event source and support context, but this app does not create endpoints, send webhooks, or sync ticket systems.

/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/support-cases
API access 1 token request(s) secrets disabled

API access is visible as non-secret request state only; token values, hashes, automation credentials, and external API calls stay disabled.

/v1/accounts/acct_local_qr_demo/service-tokens
QR adapter welcome planned

The QR adapter can point at rehearsal requirements without importing codes, writing destinations, publishing redirects, or executing mutations.

/v1/qr/workspaces/qrw_local_demo/mutation-requests/qrm_local_demo_welcome_destination_change/execution-rehearsal-requirements
Billing connector qrbill_local_demo_scan_review blocked

Billing connector setup stays local and non-billable; no Stripe customer, subscription, metered event, invoice, or CSV export is created.

/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/billing-export-requests
Operator sync service_token blocked_pending_matthew_approval

Operator sync remains a read-only handoff to decision requirements; this app does not submit approvals, run jobs, contact customers, or deploy production.

/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements

The integrations center previews customer connection setup from account-scoped read state only; it does not create webhook endpoints, send webhooks, issue API keys or token secrets, sync third-party systems, create billing connectors, publish hosted redirects, write QR records, submit approvals, contact customers, or run production jobs.

Billing and plan center

Plan controls preview

money movement disabled
Current plan starter modeled

Plan context is visible for tenant setup, but plan changes, paid subscriptions, invoices, and customer billing records are not created.

/v1/accounts/acct_local_qr_demo/services
Entitlements 5 entitlement(s) not_created

Entitlement reads can explain feature access in dev while billing sync, provider grants, and customer-visible upgrades stay disabled.

/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/entitlements
Usage meter 1 local scan(s) non-billable

QR scan evidence remains local and non-billable; no usage record, invoice item, export, or customer charge is produced.

/v1/qr/workspaces/qrw_local_demo
Billing exports qrbill_local_demo_scan_review blocked

Export requests are inspectable as read-only state; CSV files, PII exports, billing jobs, and customer delivery remain off.

/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/billing-export-requests
Activation packet local-qr-starter-demo blocked_pending_matthew_approval

Activation evidence stays in the operator path; customer activation, paid access, DNS, redirects, and production jobs remain blocked.

/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
Plan changes Upgrade path preview approval required

The dev app can show the future upgrade path without enabling checkout, payment methods, subscription updates, usage exports, or customer contact.

/platform/admin/

The billing and plan center is a read-only tenant preview: it shows plan, entitlement, usage, export, and activation state without creating billing customers, payment methods, paid subscriptions, invoices, usage records, CSV exports, customer emails, hosted redirects, QR writes, or production jobs.

Customer profile center

Profile and contact preview

profile changes disabled
Profile identity Local QR Owner local_pending

The app can show local profile and account identity from seed state, but profile writes, signup sessions, passwords, magic links, and auth-provider users are not created.

/v1/accounts/acct_local_qr_demo
Contact email owner@example.invalid local only

Email is displayed for dev account context only; no verification email, customer notification, acceptance link, or external contact is sent.

/v1/accounts/acct_local_qr_demo/memberships
Workspace role owner planned

Role context stays account-scoped and read-only; this surface does not grant provider access, activate memberships, or broaden tenant scope.

/v1/accounts/acct_local_qr_demo/memberships
Team invitation editor@example.invalid not_sent

Invite recipients can be previewed, but delivery, acceptance, external user creation, and membership activation remain disabled.

/v1/accounts/acct_local_qr_demo/invites
Service contact asvc_local_qr_demo blocked

Service contact preferences are visible as setup context only; support replies, customer contact, ticket sync, and external archives stay off.

/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/support-cases

The customer profile center is a customer-like dev preview assembled from account-scoped reads only; it does not save profile changes, verify emails, send customer notifications, deliver invites, create auth-provider users, grant membership, contact customers, issue token secrets, publish hosted redirects, write QR records, export usage, or run production jobs.

Security center

Access controls preview

credentials disabled
Session policy Dev read-only no real session

The account can show a signed-in preview state, but no password, magic link, provider session, browser token, or external customer access is created.

/v1/accounts/acct_local_qr_demo/auth/token-policy
Token posture 1 token request(s) secrets not issued

Service-token requests are inspectable as non-secret records only; secret values, hashes, automation credentials, and external API access stay disabled.

/v1/accounts/acct_local_qr_demo/service-tokens
Audit coverage 3 recent event(s) account_service.seed_packet_prepared

Audit evidence gives operators a tenant-scoped trail without exposing idempotency keys, request hashes, token values, customer exports, or private notes.

/v1/audit-events
Access grants editor@example.invalid planned

Member and invite context can be reviewed, but invite delivery, acceptance links, provider grants, account activation, and customer sessions remain blocked.

/v1/accounts/acct_local_qr_demo/invites
QR write boundary welcome planned

QR destinations, imports, and rehearsal requirements are readable, while hosted redirects, customer QR writes, mutation execution, and route changes stay off.

/v1/qr/workspaces/qrw_local_demo/mutation-requests/qrm_local_demo_welcome_destination_change/execution-rehearsal-requirements

The security center preview keeps tenant access, token posture, audit coverage, and QR write boundaries visible without enabling credentials: it does not create sessions, send magic links, grant auth-provider access, issue token secrets, expose hashes, publish hosted redirects, write QR records, execute mutations, export customer data, or run production jobs.

Audit history center

Tenant timeline preview

exports disabled
Recent evidence account_service.seed_packet_prepared 3 event(s)

Shows account-scoped audit events as local product history while hiding idempotency keys, request hashes, token values, and private operator notes.

/v1/audit-events
Review trail rev_service_token_stok_local_qr_demo_agent_preview blocked_pending_matthew_approval

Approval requirements stay visible as read-only history; this app does not submit decisions, execute actions, or publish customer effects.

/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
QR change log welcome planned

QR code and rehearsal history can be inspected without importing codes, changing destinations, publishing redirects, or writing customer-visible records.

/v1/qr/workspaces/qrw_local_demo/mutation-requests/qrm_local_demo_welcome_destination_change/execution-rehearsal-requirements
Access history editor@example.invalid not_sent

Membership and invite history remains local evidence only; invite delivery, acceptance links, provider grants, and real sessions stay disabled.

/v1/accounts/acct_local_qr_demo/invites

The audit history center makes account history visible to the dev app from read-only routes only; it does not export logs, reveal idempotency keys, reveal request hashes, expose token values, open private notes, replay actions, contact customers, write QR records, publish redirects, submit approvals, or run production jobs.

Action workbench

Draft the next tenant workflow

controls staged
Session Preview signed-in state ready

owner@example.invalid

Shows the selected tenant and role without creating a password, magic link, auth-provider user, or browser token.

Onboarding Draft tenant setup draft

Local QR Demo

Keeps account creation as a local draft and blocks activation, billing, DNS, production routes, and external customer access.

QR workspace Prepare QR changes workspace ready

qrw_local_demo

Lets the app frame QR code and destination edits as draft work before any hosted redirect or tenant QR write can run.

Team Invite collaborator draft available

editor@example.invalid

Captures who should get access while email delivery, acceptance links, and auth-provider membership grants stay off.

Launch Request operator review blocked

service_token

Moves external effects into the operator path; the app still does not submit approval decisions or production jobs.

Task Owner State Next move
Open tenant dashboard Local QR Owner available Use the account selector and read-only workspace panels.
Draft QR destination change QR workspace queued Review rehearsal requirements before any write can run.
Invite teammate Access drafted Keep delivery disabled until the invite acceptance flow is approved.
Enable customer launch Operator blocked Requires explicit approval for signup, billing, redirects, QR writes, token secrets, and production execution.

Session task board

Customer session task queue

GET routes only
Session Confirm selected account draft

The app can show Local QR Demo as selected tenant context without creating credentials or customer access.

Read route
/v1/accounts/acct_local_qr_demo
Blocked write
real signup session creation
Workspace Open QR workspace readable

qrw_local_demo backs QR panels with 1 local code(s) and 1 non-billable scan event(s).

Read route
/v1/qr/workspaces/qrw_local_demo
Blocked write
hosted redirect publishing and QR record writes
Access Review team draft draft visible

1 invite draft(s) are visible without sending email or activating external users.

Read route
/v1/accounts/acct_local_qr_demo/invites
Blocked write
invite delivery and auth-provider grants
Operator Check approval boundary requirements readable

28 blocked action(s) remain routed through operator evidence.

Read route
/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
Blocked write
approval decisions and production execution

The action workbench is the customer-product direction for the dev app: workflow controls, drafts, queues, and empty states first. Buttons stay disabled until their matching local draft API and approval boundary are proven; this app still does not create sessions, send invites, publish redirects, issue secrets, export usage, or run production jobs.

The session task board gives each selected tenant a customer-session queue backed by read-only routes only; it blocks signup sessions, invite delivery, auth-provider grants, hosted redirects, QR writes, approval decisions, billable exports, and production execution.

Workspace inbox

Next visible checks

read-only queue
  • Workspace ready qrw_local_demo read-only

    1 QR code(s), 1 campaign(s), and 1 local scan event(s) are visible without hosted redirects.

    /v1/qr/workspaces/qrw_local_demo
  • Team access editor@example.invalid not_sent

    1 invite draft(s) can be reviewed; delivery and auth-provider grants stay disabled.

    /v1/accounts/acct_local_qr_demo/invites
  • QR review welcome planned

    Mutation rehearsal requirements are inspectable, but customer-visible QR writes remain blocked.

    /v1/qr/workspaces/qrw_local_demo/mutation-requests/qrm_local_demo_welcome_destination_change/execution-rehearsal-requirements
  • Operator queue service_token blocked_pending_matthew_approval

    28 approval-gated action(s) stay out of the app surface.

    /v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
  • Launch blocker Customer launch disabled blocked

    Signup, invite delivery, billing, hosted redirects, token secrets, QR writes, and production execution remain off.

    /platform/admin/

The workspace inbox is assembled from account-scoped read state only; it links to existing GET routes and never creates sessions, invites, billing records, QR redirects, token secrets, customer-visible QR writes, or production jobs.

Launch readiness

What blocks customer launch

launch actions disabled
Account identity planned owner@example.invalid

The selected tenant can be displayed in dev, but no customer account, password, magic link, provider user, or browser session is created.

Read route
/v1/accounts/acct_local_qr_demo
Blocked launch action
real signup session creation
Workspace content readable 1 code(s), 1 campaign(s)

QR workspace state is visible as read-only product data while redirects, destination writes, imports, and mutation execution stay blocked.

Read route
/v1/qr/workspaces/qrw_local_demo
Blocked launch action
hosted redirect publishing and customer QR writes
Team access draft invite visible editor@example.invalid

Members and draft invites are visible for tenant context, but email delivery, acceptance links, grants, and external sessions stay disabled.

Read route
/v1/accounts/acct_local_qr_demo/invites
Blocked launch action
invite delivery and auth-provider grants
Usage and billing blocked 1 local scan event(s)

Usage evidence remains local and non-billable; the app cannot create customers, invoices, paid usage, CSVs, or export jobs.

Read route
/v1/billing/export-requests
Blocked launch action
billing customers, subscriptions, and usage export jobs
Operator launch gate blocked blocked_pending_matthew_approval

Launch stays behind the operator path; this app only links requirements and never submits decisions, runs jobs, or changes production.

Read route
/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
Blocked launch action
approval decisions and production execution

The launch readiness preview turns tenant setup into a customer-facing checklist while all customer effects remain blocked: signup sessions, invite delivery, auth-provider grants, billing customers, hosted redirects, QR writes, usage exports, approval submissions, and production execution stay disabled.

Service status center

Tenant services and runtime health

service changes disabled
Service catalog QR Codes 1 service(s) visible

Services are visible as tenant dashboard context only; no customer access, production deployment, repo setting, or external service activation is changed.

/v1/accounts/acct_local_qr_demo/services
Plan entitlement active_qr_codes not_created

Entitlement state can be reviewed without creating billing customers, subscriptions, invoices, paid usage, or export jobs.

/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/entitlements
Activation packet local-qr-starter-demo blocked_pending_matthew_approval

Activation remains an operator-read path; this app cannot submit approvals, run jobs, issue secrets, deploy production, or contact customers.

/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
Support status Review Starter Open QR import before tenant writes blocked

Support state stays local to the dev app and operator evidence; no replies, ticket sync, customer outreach, or external notifications are sent.

/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/support-cases
Runtime health /health read-only check

Runtime health helps operators verify the dev build while production deploy jobs, DNS changes, customer redirects, and infrastructure changes remain manual and disabled here.

/health
Activation draft exercise Prepare tenant locally draft account, service, invite, and activation packet

Uses guarded dev-only POSTs with Idempotency-Key headers for local draft state only, then records local-only operator approval from the current decision requirements. Invite delivery, auth-provider grants, billing, token secrets, QR redirects, activation jobs, customer access, and production execution remain blocked.

Not submitted. Customer activation, invite delivery, billing, token secrets, hosted redirects, customer effects, and production execution remain disabled.

The service status center gives each tenant a customer-like service health view and a guarded local activation draft plus local approval path; it does not enable services, create billing records, issue token secrets, run activation jobs, contact customers, change DNS, publish hosted redirects, write QR records, or deploy production.

Message center

Customer notices preview

delivery disabled
Invite notice editor@example.invalid not_sent

1 draft invite notice(s) are visible for review; delivery, acceptance links, and auth-provider grants are disabled.

/v1/accounts/acct_local_qr_demo/invites
QR change notice welcome planned

QR import and mutation notices point to read-only requirements; no hosted redirect, QR write, or import execution is triggered.

/v1/qr/workspaces/qrw_local_demo/mutation-requests/qrm_local_demo_welcome_destination_change/execution-rehearsal-requirements
Billing notice qrbill_local_demo_scan_review blocked

Billing and usage messages stay local and non-billable; no customer, subscription, invoice, or export job is created.

/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/billing-export-requests
Support notice Review Starter Open QR import before tenant writes blocked

Support and operator messages can be inspected in dev without emailing customers, posting outreach, or submitting approval decisions.

/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/support-cases

The message center preview shows invite, QR change, billing, and support notices from account-scoped read state only; it does not send email, create acceptance links, grant auth-provider access, export usage, publish hosted redirects, write QR records, submit approvals, or contact customers.

Notification preferences

Delivery settings preview

all channels off
Invite updates Email off draft visible

Invite notifications can be previewed from draft recipient state, but no email, acceptance link, or auth-provider grant is sent.

/v1/accounts/acct_local_qr_demo/invites
QR change alerts Webhook off review required

QR alerts stay tied to read-only rehearsal requirements; hosted redirects, webhooks, import execution, and QR writes remain disabled.

/v1/qr/workspaces/qrw_local_demo/mutation-requests/qrm_local_demo_welcome_destination_change/execution-rehearsal-requirements
Billing summaries Export off blocked

Usage summaries stay local and non-billable; no customer, subscription, invoice, or export job is created.

/v1/billing/export-requests
Support replies Contact off blocked

Support replies are local review evidence only; this app does not send outreach, submit approvals, or contact customers.

/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/support-cases
Security and audit SMS off local evidence

Audit notices show non-secret local evidence without sending SMS, exposing token values, or broadening account scope.

/v1/audit-events

The notification preferences preview gives each tenant visible delivery choices without enabling delivery: email, webhooks, SMS, billing exports, support contact, invite acceptance links, auth-provider grants, hosted redirects, QR writes, and production jobs stay disabled.

API console

Try read routes later

requests disabled
Account API Local QR Demo draft

The future tenant API console can show account reads without creating signup sessions, browser tokens, customer accounts, or auth-provider users.

/v1/accounts/acct_local_qr_demo
Workspace API qrw_local_demo planned

QR workspace reads are visible, but hosted redirects, destination writes, imports, mutation execution, and customer-visible route changes stay blocked.

/v1/qr/workspaces/qrw_local_demo
Access API owner@example.invalid planned

Membership and invite context can be inspected without sending a browser token, invite email, magic link, password, or external access grant.

/v1/accounts/acct_local_qr_demo/memberships
Operator API service_token blocked_pending_matthew_approval

Decision and rehearsal requirements stay behind operator read paths; this app does not submit approvals, run jobs, write QR records, or deploy production.

/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
Response export Local preview payload downloads disabled

API responses remain on-screen guardrail evidence only; CSV downloads, billing exports, token material, customer data exports, and customer contact stay disabled.

/platform/api/

The API console preview makes future read-route testing visible while keeping the browser inert: it does not send tokens, create sessions, deliver invites, export responses, write QR records, submit approvals, publish hosted redirects, contact customers, or run production jobs.

Export center

Download requests preview

downloads disabled
Usage report qrbill_local_demo_scan_review blocked

Usage can be previewed from local scan evidence, but no billing customer, invoice, usage record, CSV, or export job is created.

/v1/billing/export-requests
QR code list qrw_local_demo 1 code(s) visible

QR code rows stay in the dev app preview only; hosted redirects, destination writes, import execution, and file downloads remain off.

/v1/qr/workspaces/qrw_local_demo
Access roster editor@example.invalid 1 member(s), 1 invite draft(s)

Team access can be reviewed from account-scoped reads without exporting PII, sending invites, or granting auth-provider membership.

/v1/accounts/acct_local_qr_demo/invites
Audit packet account_service.seed_packet_prepared local evidence

Audit evidence remains non-secret and in-app; idempotency keys, request hashes, token values, and customer-facing downloads stay hidden.

/v1/audit-events
Support archive Review Starter Open QR import before tenant writes blocked

Support history and review evidence stay local; no customer contact, email thread export, approval submission, or external archive is produced.

/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/support-cases

The export center preview shows tenant usage, QR, access, audit, and support download requests without generating files: billing exports, CSV downloads, PII exports, customer contact, hosted redirects, QR writes, token material, approval submissions, and production jobs remain disabled.

Support workspace

Case and escalation preview

contact disabled
Case timeline Review Starter Open QR import before tenant writes blocked

Support context is shown from local review state only; customer replies, email threads, public comments, and ticket sync stay disabled.

/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/support-cases
Escalation draft issue_secret_material operator gated

Escalations point to operator requirements but do not submit decisions, run production jobs, change DNS, or contact customers.

/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
Workspace note qrw_local_demo read-only

Notes can reference QR workspace and route evidence without writing QR records, publishing hosted redirects, or changing destinations.

/v1/qr/workspaces/qrw_local_demo
Audit note account_service.seed_packet_prepared local evidence

Audit notes stay in the dev app preview and never expose idempotency keys, request hashes, token values, or customer data exports.

/v1/audit-events

The support workspace preview keeps customer help and operator escalation visible without external effects: replies, email delivery, public comments, ticket sync, customer contact, approval submissions, QR writes, hosted redirects, DNS changes, secret exposure, and production jobs remain disabled.

Help center

Tenant support articles preview

self-service disabled
Getting started Open qrw_local_demo article drafted

The first help article can explain the read-only workspace, code library, and launch blockers without enabling signup or QR writes.

/v1/qr/workspaces/qrw_local_demo
Team access editor@example.invalid not_sent

Access guidance can describe draft invites and roles, but invite delivery, acceptance links, auth-provider grants, and external sessions stay disabled.

/v1/accounts/acct_local_qr_demo/invites
QR changes welcome planned

QR help can point to rehearsal requirements while hosted redirects, imports, destination writes, mutation execution, and customer-visible changes remain blocked.

/v1/qr/workspaces/qrw_local_demo/mutation-requests/qrm_local_demo_welcome_destination_change/execution-rehearsal-requirements
Billing questions starter blocked

Billing help stays local and non-billable; no customer, subscription, invoice, payment method, usage export, or support contact is created.

/v1/billing/export-requests
Operator review service_token blocked_pending_matthew_approval

Help content can send operators to read-only decision requirements, but this app does not submit approvals, contact customers, or run production jobs.

/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements

The help center preview gives tenants a customer-facing support surface from account-scoped read state only; it does not publish articles, run search, send help email, create tickets, contact customers, grant access, write QR records, export billing data, submit approvals, or run production jobs.

Launch operations

Go-live handoff preview

go-live disabled
Launch review service_token blocked_pending_matthew_approval

Operator evidence is visible for scheduling, but this app does not submit approvals, run jobs, or change production state.

/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
Customer access editor@example.invalid draft

Membership and invite context can be checked before launch; invite delivery, acceptance links, provider grants, and real sessions stay off.

/v1/accounts/acct_local_qr_demo/invites
QR launch welcome planned

QR destinations and rehearsal requirements are readable, while hosted redirects, QR writes, imports, and mutation execution stay blocked.

/v1/qr/workspaces/qrw_local_demo/mutation-requests/qrm_local_demo_welcome_destination_change/execution-rehearsal-requirements
Post-launch watch Review Starter Open QR import before tenant writes blocked

Support and audit notes stay local; there is no customer contact, ticket sync, external archive, secret exposure, or usage export.

/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/support-cases

The launch operations preview gives each tenant a go-live handoff checklist without enabling effects: approval decisions, customer access, invite delivery, auth-provider grants, hosted redirects, QR writes, imports, mutation execution, support contact, usage exports, and production jobs remain disabled.

QR editor

Draft tray preview

writes disabled
welcome Welcome packet planned
Current destination
https://example.invalid/welcome
Draft destination
https://example.invalid/welcome-updated
Style
round
Campaign
Launch packet
Draft API POST /v1/qr/workspaces/qrw_local_demo/mutation-requests Idempotency-Key required; persists planned review request plus audit readback.
/v1/qr/workspaces/qrw_local_demo/mutation-requests/qrm_local_demo_welcome_destination_change/execution-rehearsal-requirements
Operator draft exercise Create one planned QR change dev credential required

Credential stays in browser memory only and is cleared after submit. The response is sanitized: auth preflight, planned request, draft requirements readback, requirements binding readback, missing and stale requirements rejection readback, queue readback, exact request readback, review packet readback, decision requirements preview, execution rehearsal requirements readback, missing and stale rehearsal requirements rejection readback, pre-approval rehearsal block readback, planned request readiness readback, audit event readback, blocked actions, idempotency replay, and retry-conflict confirmation render without token values, token hashes, request hashes, raw fingerprint inputs, or raw retry keys.

Not submitted. Publish, rehearsal, hosted redirects, billing, customer effects, and tenant QR writes remain disabled.

The QR editor draft tray points at guarded dev-only POSTs for draft creation, local review approval, and local execution rehearsal with idempotency and audit readback. Browser controls stay disabled here; tenant QR record writes, hosted redirects, billable scan updates, customer-visible route changes, and production execution remain blocked until explicit approval exists.

QR campaign planner

Campaigns before launch

launch disabled
qrw_local_demo Launch packet planned
Codes
welcome
Local scans
1
QR reviews
1
Draft destination
https://example.invalid/welcome-updated
/v1/qr/workspaces/qrw_local_demo/mutation-requests/qrm_local_demo_welcome_destination_change/execution-rehearsal-requirements

The QR campaign planner groups code, scan, destination, and review state into a customer-like product view without enabling launch actions: campaign creation, code writes, hosted redirects, usage exports, invite notices, customer messages, and production execution remain disabled.

QR library

Codes ready for review

redirects blocked
welcome Welcome packet

https://example.invalid/welcome

Campaign
Launch packet
Status
planned
Local scans
1
Hosted redirect
blocked
/v1/qr/workspaces/qrw_local_demo Billable usage false; QR writes and redirect publishing remain disabled.

The QR workspace library is read-only customer-facing state: it shows code destinations, campaign grouping, local scan evidence, and route links without publishing hosted redirects, writing QR records, exporting billable usage, or changing customer access.

Account status draft

Local QR Demo

Session Local QR Owner

owner@example.invalid; external auth provider false.

Services 1

Account service records are modeled before customer enablement.

Credentials 1

Service-token requests are visible without secret material.

Usage events 1

Scan evidence is local and non-billable until exports are approved.

Review packets 6

Approval evidence is readable before local-only decisions execute.

Dashboard summary

What is visible now

read-only product view
Customer app state Preview only customer effects false

Dev users can inspect workspace state, but signup, real sessions, invite delivery, hosted redirects, billing, token secrets, QR writes, and production jobs remain disabled.

#account-acct_local_qr_demo
Workspace signal 1 QR code(s) read-only data

1 campaign(s), 1 local scan event(s), and hosted redirects false.

/v1/qr/workspaces/qrw_local_demo
Operator attention 6 packet(s) approval-gated

28 blocked action(s) stay in operator read paths; the app does not POST decisions.

/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
Access readiness 1 member(s) 1 invite draft(s)

Membership and invite context is visible for account selection only; auth-provider grants, magic links, and external sessions are not created.

/v1/accounts/acct_local_qr_demo/memberships

The dashboard summary is a customer-like dev view assembled from account-scoped reads only; it does not create signup sessions, send invites, grant auth-provider access, issue token secrets, enable billing, publish hosted redirects, write QR records, export usage, or run production jobs.

Tenant health

Workspace status summary

read-only
Account Local QR Demo draft

Account context is visible in dev with external customer effects disabled.

/v1/accounts/acct_local_qr_demo
Workspace qrw_local_demo read-only

1 code(s), 1 campaign(s), and hosted redirects false.

/v1/qr/workspaces/qrw_local_demo
Access owner@example.invalid planned

Membership and invite state is readable, but real login, invite delivery, and auth-provider grants stay disabled.

/v1/accounts/acct_local_qr_demo/memberships
Usage 1 local scan event(s) non-billable

Local usage evidence can be inspected without exporting billable usage or creating billing records.

/v1/qr/workspaces/qrw_local_demo
Operator evidence 6 packet(s) approval-gated

Decision and rehearsal requirements stay operator-gated; this app only submits local-only review approval and rehearsal POSTs after fresh fingerprint readback, never customer-visible execution.

/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
Launch Customer launch disabled blocked

Signup, billing, invites, hosted redirects, QR writes, token secrets, and production execution require explicit approval.

/platform/admin/

The tenant health overview is generated from account-scoped read state and existing /v1 routes only; it does not create sessions, send invites, grant access, enable billing, publish hosted redirects, write QR records, issue token secrets, or run production jobs.

Login readiness

Session and workspace access

no credentials issued
Login identity owner@example.invalid preview only

Email is displayed from seed data for dev session context; no password, magic link, or auth-provider credential is created.

Membership scope owner planned

Visible reads stay scoped to acct_local_qr_demo; cross-account access remains blocked by the protected /v1 routes.

Invite state not_sent delivery disabled

Draft invites can be inspected here, but invite email delivery and external user access remain disabled.

Workspace selector qrw_local_demo read-only

Switching accounts changes the visible tenant context without enabling customer signup, hosted redirects, or QR writes.

Auth flow preview

From email to workspace

no real session
  1. Enter email prefilled

    owner@example.invalid

    /app/
  2. Check membership planned

    owner access is read from account membership seed data; auth-provider grants are not created.

    /v1/accounts/acct_local_qr_demo/memberships
  3. Select workspace available

    qrw_local_demo opens as the visible workspace for Local QR Demo.

    /v1/qr/workspaces/qrw_local_demo
  4. Open dashboard read-only

    Account, QR, usage, access, review, and audit panels render without POST actions or customer effects.

    #account-acct_local_qr_demo-qr
  5. Ask operator approval required

    Real signup, invite delivery, service-token secrets, billing, hosted redirects, QR writes, and production execution stay blocked.

    /v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements

The dev auth flow preview is local and read-only: it does not create passwords, magic links, provider users, customer accounts, invites, token secrets, billing records, QR redirects, or production access.

Access review

Who can see this workspace

no grants sent
  • Member owner@example.invalid owner / planned

    This identity can be inspected in dev account context, but no auth-provider grant, password, magic link, or external session is created.

    /v1/accounts/acct_local_qr_demo/memberships
  • Invite draft editor@example.invalid editor / not_sent

    The invite is visible as a draft only; delivery, acceptance, external user access, and membership activation remain disabled.

    /v1/accounts/acct_local_qr_demo/invites

The access review preview is account-scoped and read-only: it does not deliver invites, create customer sessions, grant auth-provider membership, activate external users, or expose token material.

Route readiness

Read paths behind this workspace

GET only
Account overview /v1/accounts/acct_local_qr_demo account scoped

Backs selected-account context without exposing broad operator data or cross-account tenant state.

Workspace reads /v1/qr/workspaces/qrw_local_demo seed available

Feeds QR workspace, code, campaign, usage, and route panels while hosted redirects remain disabled.

Operator evidence /v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements requirements readable

Keeps approval evidence in the operator path; this app does not submit decisions or reveal idempotency values.

Disabled writes POST actions blocked from app fail closed

Signup, invite delivery, token issuance, hosted redirects, customer QR writes, import execution, billing exports, and production execution need explicit approval.

Workspace activity

Tenant activity timeline

read-only feed
  • QR code Welcome packet planned

    Slug welcome; hosted redirect false.

    /v1/qr/workspaces/qrw_local_demo
  • Import review open_qr_links_json planned

    1 planned / 1 rejected; import performed false.

    /v1/qr/workspaces/qrw_local_demo
  • Mutation rehearsal welcome planned

    Approval required true; customer-visible write false.

    /v1/qr/workspaces/qrw_local_demo/mutation-requests/qrm_local_demo_welcome_destination_change/execution-rehearsal-requirements
  • Redirect check welcome external_redirects_not_approved

    Redirect performed false; destination remains read-only in dev.

    /v1/qr/workspaces/qrw_local_demo
  • Audit evidence account_service.seed_packet_prepared skipped

    account_service asvc_local_qr_demo; actor system/local.

    /v1/audit-events
  • Audit evidence account_service.operator_decision_blocked skipped

    operator_approval_decision opd_local_qr_demo_001; actor system/local.

    /v1/audit-events
  • Audit evidence qr_code.created skipped

    qr_code qrc_local_demo_welcome; actor usr_local_qr_owner.

    /v1/audit-events

Activity is assembled from account-scoped seed and /v1 read routes only; it does not create login sessions, send invites, write QR records, publish redirects, export usage, or reveal token values.

Customer journey

First-run setup preview

preview only
  1. 1
    Choose workspace ready

    Local QR Demo opens qrw_local_demo with 1 read-only QR code(s).

  2. 2
    Invite team drafted

    1 invite draft(s) are visible; delivery and auth-provider access stay disabled.

  3. 3
    Review QR changes approval-gated

    1 QR change rehearsal(s) can be inspected without writing tenant records.

  4. 4
    Launch blocked

    Launch remains blocked: signup, billing, hosted redirects, invite delivery, token secrets, and production execution are off.

This journey is a dev-only preview assembled from account-scoped read state; it does not create accounts, send invites, grant access, enable billing, publish redirects, issue token secrets, or run production jobs.

Customer action map

What customers can see today

Approve before enabling
  • Workspace read visible in dev Customer effect false

    Already GET-only; no approval needed for local reads.

    /v1/qr/workspaces/qrw_local_demo
  • Signup session preview scaffold Customer effect false

    Matthew approval required before real accounts, credentials, or auth-provider users exist.

    /app/
  • Invite delivery drafts visible Customer effect false

    Operator approval required before email delivery, acceptance links, or external user access.

    /v1/accounts/acct_local_qr_demo/invites
  • Token secret issuance requests visible Customer effect false

    Operator approval required before any secret value, hash storage, or external API access.

    /v1/accounts/acct_local_qr_demo/service-tokens
  • Hosted redirect publishing blocked by workspace Customer effect false

    Approval required before hosted redirects, QR writes, import execution, or destination changes.

    /v1/qr/workspaces/qrw_local_demo
  • Billing usage export request visible Customer effect false

    Matthew approval required before billing customers, subscriptions, billable usage, or export jobs.

    /v1/billing/export-requests

The customer action map separates visible read-only app surfaces from future customer effects; signup sessions, invite delivery, token secrets, hosted redirects, QR writes, billing records, and production execution stay disabled.

Data source map

Read routes behind each app panel

static fallback
  • Session and account /v1/accounts/acct_local_qr_demo

    seeded account context

    Blocked write: customer signup and real session creation
  • Workspace library /v1/qr/workspaces/qrw_local_demo

    bundled QR workspace, codes, campaigns, and scan evidence

    Blocked write: hosted redirect publishing, QR writes, and import execution
  • Team access /v1/accounts/acct_local_qr_demo/memberships

    planned members and invite drafts

    Blocked write: invite delivery and auth-provider membership grants
  • Billing and usage /v1/billing/export-requests

    local non-billable scan and export-request evidence

    Blocked write: billing customers, subscriptions, and usage export jobs
  • Operator review /v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements

    review packet and blocked-action evidence

    Blocked write: customer-visible decisions, token secrets, and production execution
  • Runtime health /health and /v1/auth/diagnostics

    static preview when runtime reads are unavailable

    Blocked write: browser token submission and mutation retries

The data source map keeps the visible tenant app honest: every panel either reads an account-scoped GET route or falls back to bundled seed data, and it never retries with POST, sends browser tokens, creates sessions, delivers invites, exports usage, publishes redirects, writes QR records, or runs production jobs.

Setup readiness

Account launch checklist

dev-only
ready Session scaffold

owner@example.invalid can preview this account with local/dev read-only context.

ready Workspace data

qrw_local_demo has 1 code(s), 1 import review(s), and 1 mutation rehearsal(s).

blocked Access handoff

1 invite(s) are drafted; real delivery and auth-provider grants require approval.

blocked Customer effects

External signup, invites, billing, hosted redirects, token secrets, and usage exports remain disabled.

Access policy

Dev auth stays account-scoped

read-only
Account-scoped token policy QR Codes

Scoped automation credentials for future QR import, read-only review, and billing-review helpers. Fixture records must never issue secret material before Matthew approval.

Account route
/v1/accounts/acct_local_qr_demo/auth/token-policy
Tenant isolation
cross-account reads fail closed with problem+json
Secret material
not issued, returned, hashed, or stored

Allowed read scopes

  • qr:read Read QR workspace, campaign, code, route, usage, and audit fixture records.
  • qr:plan_import Prepare Open QR import previews without writing hosted QR records.
  • billing_export:read Read blocked billing-export review records without exporting usage.

Blocked until approval

  • Admin-only token approval records exist.
  • Secret material can be issued once and stored only as a hash.
  • Every token action writes an audit event before customer or external automation access opens.

Operator handoff

Local-only decision path

No POST from this app

Reviewers can inspect the current account-scoped requirements before any local-only decision or QR rehearsal. Idempotency-Key required; key values and request hashes stay hidden.

External signup, invites, billing, hosted redirects, token secrets, customer-visible QR writes, import execution, and production execution remain disabled.

Decision requirements

Packet Status Read route Blocked
service_token blocked_pending_matthew_approval /v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements 6 blocked action(s)
import blocked_pending_matthew_approval /v1/review-packets/rev_import_qrimp_local_demo_open_qr_links/decision-requirements 9 blocked action(s)
qr_mutation blocked_pending_matthew_approval /v1/review-packets/rev_qr_mutation_qrm_local_demo_welcome_destination_change/decision-requirements 5 blocked action(s)
activation blocked_pending_matthew_approval /v1/review-packets/rev_activation_local-qr-starter-demo/decision-requirements 8 blocked action(s)
billing_export blocked_pending_matthew_approval /v1/review-packets/rev_billing_qrbill_local_demo_scan_review/decision-requirements 4 blocked action(s)

QR rehearsal requirements

Code Status Read route Reason
welcome planned /v1/qr/workspaces/qrw_local_demo/mutation-requests/qrm_local_demo_welcome_destination_change/execution-rehearsal-requirements local_mutations_not_approved

Services

Account service state

read-only
Service Plan Status External effects
QR Codes starter modeled false

Workspace

QR tenant preview

planned
QR workspace qrw_local_demo

planned; hosted redirects false; 1 planned code(s); 1 import review(s); 1 mutation rehearsal(s).

QR codes

Codes and redirect status

redirects off
Slug Label Status Redirect enabled
welcome Welcome packet planned false

Imports

Open QR import review

no writes
Source Status Imported External effect
open_qr_links_json planned false false

Changes

Mutation rehearsal status

approval-gated
Code Status Approval External effect
welcome planned true false

Routes

Hosted redirect readiness

blocked
Slug Workspace Redirected Reason
welcome planned false external_redirects_not_approved

Campaigns

QR campaign usage

local data
Campaign Status Codes Scan events
Launch packet planned 1 1

Scan evidence

Usage stays non-billable

export off
Code Quantity Billable Export
welcome 1 false not_enabled

Credentials

Service-token requests

no secrets
Name Status Secret issued Scopes
Local QR agent preview planned false qr:read, qr:plan_import, billing_export:read

Plan

Entitlements and billing sync

not synced
Entitlement Kind Value Billing sync
active_qr_codes limit 25 not_created
monthly_scans metered-limit 5000 not_created
scan_retention_days limit 90 not_created
custom_domains feature false not_created
branded_exports feature true not_created

Activation

Account enablement packet

blocked
Packet Status Billing customer External effect
local-qr-starter-demo blocked_pending_matthew_approval null false

Usage

Billing export requests

not exported
Request Status Billable External export
qrbill_local_demo_scan_review blocked false false

Approval

Review packet evidence

guarded
Packet Status Approval External effect
service_token blocked_pending_matthew_approval matthew false
import blocked_pending_matthew_approval matthew false
qr_mutation blocked_pending_matthew_approval matthew false
activation blocked_pending_matthew_approval matthew false
billing_export blocked_pending_matthew_approval matthew false
support blocked_pending_matthew_approval matthew false
issue_secret_materialenable_external_api_accessstore_token_hashsend_invitecreate_billing_customerexport_metered_usagecreate_customer_accountcreate_subscription

Decisions

Operator approval state

evidence
State Result Approved Blocked
blocked not_executed 0 6

Access

Members and invites

no delivery
  • Local QR Owner owner / planned / invite not_sent
  • editor@example.invalid editor / draft / delivery not_sent

History

Recent audit evidence

local
  • account_service.seed_packet_prepared account_service asvc_local_qr_demo
  • account_service.operator_decision_blocked operator_approval_decision opd_local_qr_demo_001
  • qr_code.created qr_code qrc_local_demo_welcome

Support

Local review cases

no outreach
  • Review Starter Open QR import before tenant writes blocked / customer visible false / notification false

Safety

Disabled customer effects

fail closed
Auth and invites Not enabled

Login is a preview scaffold, memberships are planned, and invite delivery remains not sent.

Billing and redirects Not enabled

No billing customer, usage export, hosted redirect, or customer-visible support timeline is active.