Tenant console
LinkRidge Cloud app.
Dev-only session scaffold with account context, QR service state, and operator evidence. Signup, billing, invite delivery, hosted redirects, and production execution stay disabled.
Checking /health when the dev control-plane runtime is reachable; protected /v1 reads still require internal/dev authorization.
Static app data stays visible when live health is unavailable.
No browser token is sent from this preview shell.
acct_local_qr_demo; status draft; external effects false.
owner@example.invalid is owner / planned; auth-provider membership grants are disabled.
Service qr-codes on plan starter; hosted redirects false.
1 draft invite(s); no invite email, customer login, or external user access is sent from this app.
not_executed; customer activation, billing, DNS, production routes, and QR redirects stay blocked.
Tenant home
Command center preview
Start from selected tenant identity and owner context without creating a customer account, password, magic link, provider user, or browser session.
/v1/accounts/acct_local_qr_demo
QR codes, campaigns, scans, imports, and draft changes stay readable while hosted redirects, QR writes, and import execution remain blocked.
/v1/qr/workspaces/qrw_local_demo
Members and invite drafts are visible, but delivery, acceptance links, auth-provider grants, and external sessions stay disabled.
/v1/accounts/acct_local_qr_demo/invites
Approval requirements are visible for operators, but this home screen cannot submit decisions, run production jobs, export usage, or contact customers.
/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
The tenant home command center makes the first selected-account screen useful from account-scoped reads only; it does not create signup sessions, passwords, magic links, auth-provider users, invite delivery, customer access, billing records, hosted redirects, QR writes, usage exports, approval decisions, customer contact, or production jobs.
Onboarding guide
First-run setup path
Shows the first-run account welcome state from local account and owner reads without creating a signup session, password, magic link, provider user, or customer account.
/v1/accounts/acct_local_qr_demo
Lets the tenant see QR workspace setup progress while hosted redirects, destination changes, imports, customer QR writes, and mutation execution remain blocked.
/v1/qr/workspaces/qrw_local_demo
Shows team invite and role context as setup progress only; invite delivery, acceptance links, membership activation, auth-provider grants, and external sessions stay disabled.
/v1/accounts/acct_local_qr_demo/invites
Keeps launch completion behind operator requirements; this app does not submit approval decisions, create billing records, export usage, contact customers, or run production jobs.
/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
The onboarding guide gives the selected tenant a first-run setup path from account-scoped reads only; it does not create signup sessions, passwords, magic links, auth-provider users, customer accounts, invite delivery, membership activation, billing records, hosted redirects, QR writes, usage exports, approval decisions, customer contact, or production jobs.
Session center
Login context preview
Shows who the app would treat as the selected tenant actor without creating a password, magic link, provider session, browser token, or customer login.
/v1/accounts/acct_local_qr_demo/auth/token-policy
Membership scope is visible for account context only; auth-provider grants, membership activation, external user access, and invite acceptance remain disabled.
/v1/accounts/acct_local_qr_demo/memberships
Switching tenants changes the visible account panel and route context, but it never broadens read scope or enables cross-account writes.
/app/
Diagnostics can prove runtime auth posture without returning token values, token hashes, request hashes, or idempotency keys to the browser.
/v1/auth/diagnostics
Invite handoff stays as local read state; no invite email, acceptance link, provider user, customer session, or membership activation is created.
/v1/accounts/acct_local_qr_demo/invites
The session center makes login context visible from account-scoped read state only; it does not create passwords, magic links, browser tokens, provider users, external sessions, invite delivery, membership activation, token secrets, hosted redirects, QR writes, customer contact, billing records, or production jobs.
Account settings
Tenant configuration preview
Name, owner, and account status can be reviewed in dev without creating customer login sessions or external account access.
/v1/accounts/acct_local_qr_demo
QR workspace defaults stay read-only; hosted redirects, destination writes, imports, and QR record mutations remain disabled.
/v1/qr/workspaces/qrw_local_demo
Role and invite settings are visible for account context only; invite delivery, acceptance links, and auth-provider grants stay off.
/v1/accounts/acct_local_qr_demo/invites
Plan and usage settings show local read state without creating billing customers, subscriptions, invoices, or export jobs.
/v1/billing/export-requests
Security settings link to token policy diagnostics but never issue token secrets, store hashes, or broaden tenant scope.
/v1/accounts/acct_local_qr_demo/auth/token-policy
Support preferences remain local preview state; replies, ticket sync, customer contact, and external archives are disabled.
/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/support-cases
The account settings preview makes tenant configuration visible from account-scoped read routes only; it does not save profile changes, connect domains, change plans, enable SSO, create signup sessions, send invites, grant auth-provider access, issue token secrets, publish hosted redirects, write QR records, contact customers, export usage, or run production jobs.
Integrations center
Connection setup preview
Future webhook setup can show the event source and support context, but this app does not create endpoints, send webhooks, or sync ticket systems.
/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/support-cases
API access is visible as non-secret request state only; token values, hashes, automation credentials, and external API calls stay disabled.
/v1/accounts/acct_local_qr_demo/service-tokens
The QR adapter can point at rehearsal requirements without importing codes, writing destinations, publishing redirects, or executing mutations.
/v1/qr/workspaces/qrw_local_demo/mutation-requests/qrm_local_demo_welcome_destination_change/execution-rehearsal-requirements
Billing connector setup stays local and non-billable; no Stripe customer, subscription, metered event, invoice, or CSV export is created.
/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/billing-export-requests
Operator sync remains a read-only handoff to decision requirements; this app does not submit approvals, run jobs, contact customers, or deploy production.
/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
The integrations center previews customer connection setup from account-scoped read state only; it does not create webhook endpoints, send webhooks, issue API keys or token secrets, sync third-party systems, create billing connectors, publish hosted redirects, write QR records, submit approvals, contact customers, or run production jobs.
Billing and plan center
Plan controls preview
Plan context is visible for tenant setup, but plan changes, paid subscriptions, invoices, and customer billing records are not created.
/v1/accounts/acct_local_qr_demo/services
Entitlement reads can explain feature access in dev while billing sync, provider grants, and customer-visible upgrades stay disabled.
/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/entitlements
QR scan evidence remains local and non-billable; no usage record, invoice item, export, or customer charge is produced.
/v1/qr/workspaces/qrw_local_demo
Export requests are inspectable as read-only state; CSV files, PII exports, billing jobs, and customer delivery remain off.
/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/billing-export-requests
Activation evidence stays in the operator path; customer activation, paid access, DNS, redirects, and production jobs remain blocked.
/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
The dev app can show the future upgrade path without enabling checkout, payment methods, subscription updates, usage exports, or customer contact.
/platform/admin/
The billing and plan center is a read-only tenant preview: it shows plan, entitlement, usage, export, and activation state without creating billing customers, payment methods, paid subscriptions, invoices, usage records, CSV exports, customer emails, hosted redirects, QR writes, or production jobs.
Customer profile center
Profile and contact preview
The app can show local profile and account identity from seed state, but profile writes, signup sessions, passwords, magic links, and auth-provider users are not created.
/v1/accounts/acct_local_qr_demo
Email is displayed for dev account context only; no verification email, customer notification, acceptance link, or external contact is sent.
/v1/accounts/acct_local_qr_demo/memberships
Role context stays account-scoped and read-only; this surface does not grant provider access, activate memberships, or broaden tenant scope.
/v1/accounts/acct_local_qr_demo/memberships
Invite recipients can be previewed, but delivery, acceptance, external user creation, and membership activation remain disabled.
/v1/accounts/acct_local_qr_demo/invites
Service contact preferences are visible as setup context only; support replies, customer contact, ticket sync, and external archives stay off.
/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/support-cases
The customer profile center is a customer-like dev preview assembled from account-scoped reads only; it does not save profile changes, verify emails, send customer notifications, deliver invites, create auth-provider users, grant membership, contact customers, issue token secrets, publish hosted redirects, write QR records, export usage, or run production jobs.
Security center
Access controls preview
The account can show a signed-in preview state, but no password, magic link, provider session, browser token, or external customer access is created.
/v1/accounts/acct_local_qr_demo/auth/token-policy
Service-token requests are inspectable as non-secret records only; secret values, hashes, automation credentials, and external API access stay disabled.
/v1/accounts/acct_local_qr_demo/service-tokens
Audit evidence gives operators a tenant-scoped trail without exposing idempotency keys, request hashes, token values, customer exports, or private notes.
/v1/audit-events
Member and invite context can be reviewed, but invite delivery, acceptance links, provider grants, account activation, and customer sessions remain blocked.
/v1/accounts/acct_local_qr_demo/invites
QR destinations, imports, and rehearsal requirements are readable, while hosted redirects, customer QR writes, mutation execution, and route changes stay off.
/v1/qr/workspaces/qrw_local_demo/mutation-requests/qrm_local_demo_welcome_destination_change/execution-rehearsal-requirements
The security center preview keeps tenant access, token posture, audit coverage, and QR write boundaries visible without enabling credentials: it does not create sessions, send magic links, grant auth-provider access, issue token secrets, expose hashes, publish hosted redirects, write QR records, execute mutations, export customer data, or run production jobs.
Audit history center
Tenant timeline preview
Shows account-scoped audit events as local product history while hiding idempotency keys, request hashes, token values, and private operator notes.
/v1/audit-events
Approval requirements stay visible as read-only history; this app does not submit decisions, execute actions, or publish customer effects.
/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
QR code and rehearsal history can be inspected without importing codes, changing destinations, publishing redirects, or writing customer-visible records.
/v1/qr/workspaces/qrw_local_demo/mutation-requests/qrm_local_demo_welcome_destination_change/execution-rehearsal-requirements
Membership and invite history remains local evidence only; invite delivery, acceptance links, provider grants, and real sessions stay disabled.
/v1/accounts/acct_local_qr_demo/invites
The audit history center makes account history visible to the dev app from read-only routes only; it does not export logs, reveal idempotency keys, reveal request hashes, expose token values, open private notes, replay actions, contact customers, write QR records, publish redirects, submit approvals, or run production jobs.
Action workbench
Draft the next tenant workflow
owner@example.invalid
Shows the selected tenant and role without creating a password, magic link, auth-provider user, or browser token.
Local QR Demo
Keeps account creation as a local draft and blocks activation, billing, DNS, production routes, and external customer access.
qrw_local_demo
Lets the app frame QR code and destination edits as draft work before any hosted redirect or tenant QR write can run.
editor@example.invalid
Captures who should get access while email delivery, acceptance links, and auth-provider membership grants stay off.
service_token
Moves external effects into the operator path; the app still does not submit approval decisions or production jobs.
| Task | Owner | State | Next move |
|---|---|---|---|
| Open tenant dashboard | Local QR Owner | available | Use the account selector and read-only workspace panels. |
| Draft QR destination change | QR workspace | queued | Review rehearsal requirements before any write can run. |
| Invite teammate | Access | drafted | Keep delivery disabled until the invite acceptance flow is approved. |
| Enable customer launch | Operator | blocked | Requires explicit approval for signup, billing, redirects, QR writes, token secrets, and production execution. |
Session task board
Customer session task queue
The app can show Local QR Demo as selected tenant context without creating credentials or customer access.
- Read route
- /v1/accounts/acct_local_qr_demo
- Blocked write
- real signup session creation
qrw_local_demo backs QR panels with 1 local code(s) and 1 non-billable scan event(s).
- Read route
- /v1/qr/workspaces/qrw_local_demo
- Blocked write
- hosted redirect publishing and QR record writes
1 invite draft(s) are visible without sending email or activating external users.
- Read route
- /v1/accounts/acct_local_qr_demo/invites
- Blocked write
- invite delivery and auth-provider grants
28 blocked action(s) remain routed through operator evidence.
- Read route
- /v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
- Blocked write
- approval decisions and production execution
The action workbench is the customer-product direction for the dev app: workflow controls, drafts, queues, and empty states first. Buttons stay disabled until their matching local draft API and approval boundary are proven; this app still does not create sessions, send invites, publish redirects, issue secrets, export usage, or run production jobs.
The session task board gives each selected tenant a customer-session queue backed by read-only routes only; it blocks signup sessions, invite delivery, auth-provider grants, hosted redirects, QR writes, approval decisions, billable exports, and production execution.
Workspace inbox
Next visible checks
-
Workspace ready
qrw_local_demo
read-only
1 QR code(s), 1 campaign(s), and 1 local scan event(s) are visible without hosted redirects.
/v1/qr/workspaces/qrw_local_demo -
Team access
editor@example.invalid
not_sent
1 invite draft(s) can be reviewed; delivery and auth-provider grants stay disabled.
/v1/accounts/acct_local_qr_demo/invites -
QR review
welcome
planned
Mutation rehearsal requirements are inspectable, but customer-visible QR writes remain blocked.
/v1/qr/workspaces/qrw_local_demo/mutation-requests/qrm_local_demo_welcome_destination_change/execution-rehearsal-requirements -
Operator queue
service_token
blocked_pending_matthew_approval
28 approval-gated action(s) stay out of the app surface.
/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements -
Launch blocker
Customer launch disabled
blocked
Signup, invite delivery, billing, hosted redirects, token secrets, QR writes, and production execution remain off.
/platform/admin/
The workspace inbox is assembled from account-scoped read state only; it links to existing GET routes and never creates sessions, invites, billing records, QR redirects, token secrets, customer-visible QR writes, or production jobs.
Launch readiness
What blocks customer launch
The selected tenant can be displayed in dev, but no customer account, password, magic link, provider user, or browser session is created.
- Read route
- /v1/accounts/acct_local_qr_demo
- Blocked launch action
- real signup session creation
QR workspace state is visible as read-only product data while redirects, destination writes, imports, and mutation execution stay blocked.
- Read route
- /v1/qr/workspaces/qrw_local_demo
- Blocked launch action
- hosted redirect publishing and customer QR writes
Members and draft invites are visible for tenant context, but email delivery, acceptance links, grants, and external sessions stay disabled.
- Read route
- /v1/accounts/acct_local_qr_demo/invites
- Blocked launch action
- invite delivery and auth-provider grants
Usage evidence remains local and non-billable; the app cannot create customers, invoices, paid usage, CSVs, or export jobs.
- Read route
- /v1/billing/export-requests
- Blocked launch action
- billing customers, subscriptions, and usage export jobs
Launch stays behind the operator path; this app only links requirements and never submits decisions, runs jobs, or changes production.
- Read route
- /v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
- Blocked launch action
- approval decisions and production execution
The launch readiness preview turns tenant setup into a customer-facing checklist while all customer effects remain blocked: signup sessions, invite delivery, auth-provider grants, billing customers, hosted redirects, QR writes, usage exports, approval submissions, and production execution stay disabled.
Service status center
Tenant services and runtime health
Services are visible as tenant dashboard context only; no customer access, production deployment, repo setting, or external service activation is changed.
/v1/accounts/acct_local_qr_demo/services
Entitlement state can be reviewed without creating billing customers, subscriptions, invoices, paid usage, or export jobs.
/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/entitlements
Activation remains an operator-read path; this app cannot submit approvals, run jobs, issue secrets, deploy production, or contact customers.
/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
Support state stays local to the dev app and operator evidence; no replies, ticket sync, customer outreach, or external notifications are sent.
/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/support-cases
Runtime health helps operators verify the dev build while production deploy jobs, DNS changes, customer redirects, and infrastructure changes remain manual and disabled here.
/health
The service status center gives each tenant a customer-like service health view and a guarded local activation draft plus local approval path; it does not enable services, create billing records, issue token secrets, run activation jobs, contact customers, change DNS, publish hosted redirects, write QR records, or deploy production.
Notification preferences
Delivery settings preview
Invite notifications can be previewed from draft recipient state, but no email, acceptance link, or auth-provider grant is sent.
/v1/accounts/acct_local_qr_demo/invites
QR alerts stay tied to read-only rehearsal requirements; hosted redirects, webhooks, import execution, and QR writes remain disabled.
/v1/qr/workspaces/qrw_local_demo/mutation-requests/qrm_local_demo_welcome_destination_change/execution-rehearsal-requirements
Usage summaries stay local and non-billable; no customer, subscription, invoice, or export job is created.
/v1/billing/export-requests
Support replies are local review evidence only; this app does not send outreach, submit approvals, or contact customers.
/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/support-cases
Audit notices show non-secret local evidence without sending SMS, exposing token values, or broadening account scope.
/v1/audit-events
The notification preferences preview gives each tenant visible delivery choices without enabling delivery: email, webhooks, SMS, billing exports, support contact, invite acceptance links, auth-provider grants, hosted redirects, QR writes, and production jobs stay disabled.
API console
Try read routes later
The future tenant API console can show account reads without creating signup sessions, browser tokens, customer accounts, or auth-provider users.
/v1/accounts/acct_local_qr_demo
QR workspace reads are visible, but hosted redirects, destination writes, imports, mutation execution, and customer-visible route changes stay blocked.
/v1/qr/workspaces/qrw_local_demo
Membership and invite context can be inspected without sending a browser token, invite email, magic link, password, or external access grant.
/v1/accounts/acct_local_qr_demo/memberships
Decision and rehearsal requirements stay behind operator read paths; this app does not submit approvals, run jobs, write QR records, or deploy production.
/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
API responses remain on-screen guardrail evidence only; CSV downloads, billing exports, token material, customer data exports, and customer contact stay disabled.
/platform/api/
The API console preview makes future read-route testing visible while keeping the browser inert: it does not send tokens, create sessions, deliver invites, export responses, write QR records, submit approvals, publish hosted redirects, contact customers, or run production jobs.
Export center
Download requests preview
Usage can be previewed from local scan evidence, but no billing customer, invoice, usage record, CSV, or export job is created.
/v1/billing/export-requests
QR code rows stay in the dev app preview only; hosted redirects, destination writes, import execution, and file downloads remain off.
/v1/qr/workspaces/qrw_local_demo
Team access can be reviewed from account-scoped reads without exporting PII, sending invites, or granting auth-provider membership.
/v1/accounts/acct_local_qr_demo/invites
Audit evidence remains non-secret and in-app; idempotency keys, request hashes, token values, and customer-facing downloads stay hidden.
/v1/audit-events
Support history and review evidence stay local; no customer contact, email thread export, approval submission, or external archive is produced.
/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/support-cases
The export center preview shows tenant usage, QR, access, audit, and support download requests without generating files: billing exports, CSV downloads, PII exports, customer contact, hosted redirects, QR writes, token material, approval submissions, and production jobs remain disabled.
Support workspace
Case and escalation preview
Support context is shown from local review state only; customer replies, email threads, public comments, and ticket sync stay disabled.
/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/support-cases
Escalations point to operator requirements but do not submit decisions, run production jobs, change DNS, or contact customers.
/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
Notes can reference QR workspace and route evidence without writing QR records, publishing hosted redirects, or changing destinations.
/v1/qr/workspaces/qrw_local_demo
Audit notes stay in the dev app preview and never expose idempotency keys, request hashes, token values, or customer data exports.
/v1/audit-events
The support workspace preview keeps customer help and operator escalation visible without external effects: replies, email delivery, public comments, ticket sync, customer contact, approval submissions, QR writes, hosted redirects, DNS changes, secret exposure, and production jobs remain disabled.
Help center
Tenant support articles preview
The first help article can explain the read-only workspace, code library, and launch blockers without enabling signup or QR writes.
/v1/qr/workspaces/qrw_local_demo
Access guidance can describe draft invites and roles, but invite delivery, acceptance links, auth-provider grants, and external sessions stay disabled.
/v1/accounts/acct_local_qr_demo/invites
QR help can point to rehearsal requirements while hosted redirects, imports, destination writes, mutation execution, and customer-visible changes remain blocked.
/v1/qr/workspaces/qrw_local_demo/mutation-requests/qrm_local_demo_welcome_destination_change/execution-rehearsal-requirements
Billing help stays local and non-billable; no customer, subscription, invoice, payment method, usage export, or support contact is created.
/v1/billing/export-requests
Help content can send operators to read-only decision requirements, but this app does not submit approvals, contact customers, or run production jobs.
/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
The help center preview gives tenants a customer-facing support surface from account-scoped read state only; it does not publish articles, run search, send help email, create tickets, contact customers, grant access, write QR records, export billing data, submit approvals, or run production jobs.
Launch operations
Go-live handoff preview
Operator evidence is visible for scheduling, but this app does not submit approvals, run jobs, or change production state.
/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
Membership and invite context can be checked before launch; invite delivery, acceptance links, provider grants, and real sessions stay off.
/v1/accounts/acct_local_qr_demo/invites
QR destinations and rehearsal requirements are readable, while hosted redirects, QR writes, imports, and mutation execution stay blocked.
/v1/qr/workspaces/qrw_local_demo/mutation-requests/qrm_local_demo_welcome_destination_change/execution-rehearsal-requirements
Support and audit notes stay local; there is no customer contact, ticket sync, external archive, secret exposure, or usage export.
/v1/accounts/acct_local_qr_demo/services/asvc_local_qr_demo/support-cases
The launch operations preview gives each tenant a go-live handoff checklist without enabling effects: approval decisions, customer access, invite delivery, auth-provider grants, hosted redirects, QR writes, imports, mutation execution, support contact, usage exports, and production jobs remain disabled.
QR editor
Draft tray preview
- Current destination
- https://example.invalid/welcome
- Draft destination
- https://example.invalid/welcome-updated
- Style
- round
- Campaign
- Launch packet
POST
/v1/qr/workspaces/qrw_local_demo/mutation-requests
Idempotency-Key required; persists planned review request
plus audit readback.
/v1/qr/workspaces/qrw_local_demo/mutation-requests/qrm_local_demo_welcome_destination_change/execution-rehearsal-requirements
The QR editor draft tray points at guarded dev-only POSTs for draft creation, local review approval, and local execution rehearsal with idempotency and audit readback. Browser controls stay disabled here; tenant QR record writes, hosted redirects, billable scan updates, customer-visible route changes, and production execution remain blocked until explicit approval exists.
QR campaign planner
Campaigns before launch
- Codes
- welcome
- Local scans
- 1
- QR reviews
- 1
- Draft destination
- https://example.invalid/welcome-updated
/v1/qr/workspaces/qrw_local_demo/mutation-requests/qrm_local_demo_welcome_destination_change/execution-rehearsal-requirements
The QR campaign planner groups code, scan, destination, and review state into a customer-like product view without enabling launch actions: campaign creation, code writes, hosted redirects, usage exports, invite notices, customer messages, and production execution remain disabled.
QR library
Codes ready for review
https://example.invalid/welcome
- Campaign
- Launch packet
- Status
- planned
- Local scans
- 1
- Hosted redirect
- blocked
/v1/qr/workspaces/qrw_local_demo
Billable usage false; QR writes and redirect publishing
remain disabled.
The QR workspace library is read-only customer-facing state: it shows code destinations, campaign grouping, local scan evidence, and route links without publishing hosted redirects, writing QR records, exporting billable usage, or changing customer access.
Local QR Demo
owner@example.invalid; external auth provider false.
Account service records are modeled before customer enablement.
Service-token requests are visible without secret material.
Scan evidence is local and non-billable until exports are approved.
Approval evidence is readable before local-only decisions execute.
Dashboard summary
What is visible now
Dev users can inspect workspace state, but signup, real sessions, invite delivery, hosted redirects, billing, token secrets, QR writes, and production jobs remain disabled.
#account-acct_local_qr_demo
1 campaign(s), 1 local scan event(s), and hosted redirects false.
/v1/qr/workspaces/qrw_local_demo
28 blocked action(s) stay in operator read paths; the app does not POST decisions.
/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
Membership and invite context is visible for account selection only; auth-provider grants, magic links, and external sessions are not created.
/v1/accounts/acct_local_qr_demo/memberships
The dashboard summary is a customer-like dev view assembled from account-scoped reads only; it does not create signup sessions, send invites, grant auth-provider access, issue token secrets, enable billing, publish hosted redirects, write QR records, export usage, or run production jobs.
Tenant health
Workspace status summary
Account context is visible in dev with external customer effects disabled.
/v1/accounts/acct_local_qr_demo
1 code(s), 1 campaign(s), and hosted redirects false.
/v1/qr/workspaces/qrw_local_demo
Membership and invite state is readable, but real login, invite delivery, and auth-provider grants stay disabled.
/v1/accounts/acct_local_qr_demo/memberships
Local usage evidence can be inspected without exporting billable usage or creating billing records.
/v1/qr/workspaces/qrw_local_demo
Decision and rehearsal requirements stay operator-gated; this app only submits local-only review approval and rehearsal POSTs after fresh fingerprint readback, never customer-visible execution.
/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
Signup, billing, invites, hosted redirects, QR writes, token secrets, and production execution require explicit approval.
/platform/admin/
The tenant health overview is generated from account-scoped read state and existing /v1 routes only; it does not create sessions, send invites, grant access, enable billing, publish hosted redirects, write QR records, issue token secrets, or run production jobs.
Login readiness
Session and workspace access
Email is displayed from seed data for dev session context; no password, magic link, or auth-provider credential is created.
Visible reads stay scoped to acct_local_qr_demo; cross-account access remains blocked by the protected /v1 routes.
Draft invites can be inspected here, but invite email delivery and external user access remain disabled.
Switching accounts changes the visible tenant context without enabling customer signup, hosted redirects, or QR writes.
Auth flow preview
From email to workspace
-
Enter email
prefilled
owner@example.invalid
/app/ -
Check membership
planned
owner access is read from account membership seed data; auth-provider grants are not created.
/v1/accounts/acct_local_qr_demo/memberships -
Select workspace
available
qrw_local_demo opens as the visible workspace for Local QR Demo.
/v1/qr/workspaces/qrw_local_demo -
Open dashboard
read-only
Account, QR, usage, access, review, and audit panels render without POST actions or customer effects.
#account-acct_local_qr_demo-qr -
Ask operator
approval required
Real signup, invite delivery, service-token secrets, billing, hosted redirects, QR writes, and production execution stay blocked.
/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
The dev auth flow preview is local and read-only: it does not create passwords, magic links, provider users, customer accounts, invites, token secrets, billing records, QR redirects, or production access.
Access review
Who can see this workspace
-
Member
owner@example.invalid
owner / planned
This identity can be inspected in dev account context, but no auth-provider grant, password, magic link, or external session is created.
/v1/accounts/acct_local_qr_demo/memberships -
Invite draft
editor@example.invalid
editor / not_sent
The invite is visible as a draft only; delivery, acceptance, external user access, and membership activation remain disabled.
/v1/accounts/acct_local_qr_demo/invites
The access review preview is account-scoped and read-only: it does not deliver invites, create customer sessions, grant auth-provider membership, activate external users, or expose token material.
Route readiness
Read paths behind this workspace
Backs selected-account context without exposing broad operator data or cross-account tenant state.
Feeds QR workspace, code, campaign, usage, and route panels while hosted redirects remain disabled.
Keeps approval evidence in the operator path; this app does not submit decisions or reveal idempotency values.
Signup, invite delivery, token issuance, hosted redirects, customer QR writes, import execution, billing exports, and production execution need explicit approval.
Workspace activity
Tenant activity timeline
-
QR code
Welcome packet
planned
Slug welcome; hosted redirect false.
/v1/qr/workspaces/qrw_local_demo -
Import review
open_qr_links_json
planned
1 planned / 1 rejected; import performed false.
/v1/qr/workspaces/qrw_local_demo -
Mutation rehearsal
welcome
planned
Approval required true; customer-visible write false.
/v1/qr/workspaces/qrw_local_demo/mutation-requests/qrm_local_demo_welcome_destination_change/execution-rehearsal-requirements -
Redirect check
welcome
external_redirects_not_approved
Redirect performed false; destination remains read-only in dev.
/v1/qr/workspaces/qrw_local_demo -
Audit evidence
account_service.seed_packet_prepared
skipped
account_service asvc_local_qr_demo; actor system/local.
/v1/audit-events -
Audit evidence
account_service.operator_decision_blocked
skipped
operator_approval_decision opd_local_qr_demo_001; actor system/local.
/v1/audit-events -
Audit evidence
qr_code.created
skipped
qr_code qrc_local_demo_welcome; actor usr_local_qr_owner.
/v1/audit-events
Activity is assembled from account-scoped seed and /v1 read routes only; it does not create login sessions, send invites, write QR records, publish redirects, export usage, or reveal token values.
Customer journey
First-run setup preview
-
1
Choose workspace ready
Local QR Demo opens qrw_local_demo with 1 read-only QR code(s).
-
2
Invite team drafted
1 invite draft(s) are visible; delivery and auth-provider access stay disabled.
-
3
Review QR changes approval-gated
1 QR change rehearsal(s) can be inspected without writing tenant records.
-
4
Launch blocked
Launch remains blocked: signup, billing, hosted redirects, invite delivery, token secrets, and production execution are off.
This journey is a dev-only preview assembled from account-scoped read state; it does not create accounts, send invites, grant access, enable billing, publish redirects, issue token secrets, or run production jobs.
Customer action map
What customers can see today
-
Workspace read
visible in dev
Customer effect false
Already GET-only; no approval needed for local reads.
/v1/qr/workspaces/qrw_local_demo -
Signup session
preview scaffold
Customer effect false
Matthew approval required before real accounts, credentials, or auth-provider users exist.
/app/ -
Invite delivery
drafts visible
Customer effect false
Operator approval required before email delivery, acceptance links, or external user access.
/v1/accounts/acct_local_qr_demo/invites -
Token secret issuance
requests visible
Customer effect false
Operator approval required before any secret value, hash storage, or external API access.
/v1/accounts/acct_local_qr_demo/service-tokens -
Hosted redirect publishing
blocked by workspace
Customer effect false
Approval required before hosted redirects, QR writes, import execution, or destination changes.
/v1/qr/workspaces/qrw_local_demo -
Billing usage export
request visible
Customer effect false
Matthew approval required before billing customers, subscriptions, billable usage, or export jobs.
/v1/billing/export-requests
The customer action map separates visible read-only app surfaces from future customer effects; signup sessions, invite delivery, token secrets, hosted redirects, QR writes, billing records, and production execution stay disabled.
Data source map
Read routes behind each app panel
-
Session and account
/v1/accounts/acct_local_qr_demo
seeded account context
Blocked write: customer signup and real session creation -
Workspace library
/v1/qr/workspaces/qrw_local_demo
bundled QR workspace, codes, campaigns, and scan evidence
Blocked write: hosted redirect publishing, QR writes, and import execution -
Team access
/v1/accounts/acct_local_qr_demo/memberships
planned members and invite drafts
Blocked write: invite delivery and auth-provider membership grants -
Billing and usage
/v1/billing/export-requests
local non-billable scan and export-request evidence
Blocked write: billing customers, subscriptions, and usage export jobs -
Operator review
/v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements
review packet and blocked-action evidence
Blocked write: customer-visible decisions, token secrets, and production execution -
Runtime health
/health and /v1/auth/diagnostics
static preview when runtime reads are unavailable
Blocked write: browser token submission and mutation retries
The data source map keeps the visible tenant app honest: every panel either reads an account-scoped GET route or falls back to bundled seed data, and it never retries with POST, sends browser tokens, creates sessions, delivers invites, exports usage, publishes redirects, writes QR records, or runs production jobs.
Setup readiness
Account launch checklist
owner@example.invalid can preview this account with local/dev read-only context.
qrw_local_demo has 1 code(s), 1 import review(s), and 1 mutation rehearsal(s).
1 invite(s) are drafted; real delivery and auth-provider grants require approval.
External signup, invites, billing, hosted redirects, token secrets, and usage exports remain disabled.
Access policy
Dev auth stays account-scoped
Scoped automation credentials for future QR import, read-only review, and billing-review helpers. Fixture records must never issue secret material before Matthew approval.
- Account route
- /v1/accounts/acct_local_qr_demo/auth/token-policy
- Tenant isolation
- cross-account reads fail closed with problem+json
- Secret material
- not issued, returned, hashed, or stored
Allowed read scopes
- qr:read Read QR workspace, campaign, code, route, usage, and audit fixture records.
- qr:plan_import Prepare Open QR import previews without writing hosted QR records.
- billing_export:read Read blocked billing-export review records without exporting usage.
Blocked until approval
- Admin-only token approval records exist.
- Secret material can be issued once and stored only as a hash.
- Every token action writes an audit event before customer or external automation access opens.
Operator handoff
Local-only decision path
Reviewers can inspect the current account-scoped requirements before any local-only decision or QR rehearsal. Idempotency-Key required; key values and request hashes stay hidden.
External signup, invites, billing, hosted redirects, token secrets, customer-visible QR writes, import execution, and production execution remain disabled.
Decision requirements
| Packet | Status | Read route | Blocked |
|---|---|---|---|
| service_token | blocked_pending_matthew_approval | /v1/review-packets/rev_service_token_stok_local_qr_demo_agent_preview/decision-requirements | 6 blocked action(s) |
| import | blocked_pending_matthew_approval | /v1/review-packets/rev_import_qrimp_local_demo_open_qr_links/decision-requirements | 9 blocked action(s) |
| qr_mutation | blocked_pending_matthew_approval | /v1/review-packets/rev_qr_mutation_qrm_local_demo_welcome_destination_change/decision-requirements | 5 blocked action(s) |
| activation | blocked_pending_matthew_approval | /v1/review-packets/rev_activation_local-qr-starter-demo/decision-requirements | 8 blocked action(s) |
| billing_export | blocked_pending_matthew_approval | /v1/review-packets/rev_billing_qrbill_local_demo_scan_review/decision-requirements | 4 blocked action(s) |
QR rehearsal requirements
| Code | Status | Read route | Reason |
|---|---|---|---|
| welcome | planned | /v1/qr/workspaces/qrw_local_demo/mutation-requests/qrm_local_demo_welcome_destination_change/execution-rehearsal-requirements | local_mutations_not_approved |
Services
Account service state
| Service | Plan | Status | External effects |
|---|---|---|---|
| QR Codes | starter | modeled | false |
Workspace
QR tenant preview
planned; hosted redirects false; 1 planned code(s); 1 import review(s); 1 mutation rehearsal(s).
QR codes
Codes and redirect status
| Slug | Label | Status | Redirect enabled |
|---|---|---|---|
| welcome | Welcome packet | planned | false |
Imports
Open QR import review
| Source | Status | Imported | External effect |
|---|---|---|---|
| open_qr_links_json | planned | false | false |
Changes
Mutation rehearsal status
| Code | Status | Approval | External effect |
|---|---|---|---|
| welcome | planned | true | false |
Routes
Hosted redirect readiness
| Slug | Workspace | Redirected | Reason |
|---|---|---|---|
| welcome | planned | false | external_redirects_not_approved |
Campaigns
QR campaign usage
| Campaign | Status | Codes | Scan events |
|---|---|---|---|
| Launch packet | planned | 1 | 1 |
Scan evidence
Usage stays non-billable
| Code | Quantity | Billable | Export |
|---|---|---|---|
| welcome | 1 | false | not_enabled |
Credentials
Service-token requests
| Name | Status | Secret issued | Scopes |
|---|---|---|---|
| Local QR agent preview | planned | false | qr:read, qr:plan_import, billing_export:read |
Plan
Entitlements and billing sync
| Entitlement | Kind | Value | Billing sync |
|---|---|---|---|
| active_qr_codes | limit | 25 | not_created |
| monthly_scans | metered-limit | 5000 | not_created |
| scan_retention_days | limit | 90 | not_created |
| custom_domains | feature | false | not_created |
| branded_exports | feature | true | not_created |
Activation
Account enablement packet
| Packet | Status | Billing customer | External effect |
|---|---|---|---|
| local-qr-starter-demo | blocked_pending_matthew_approval | null | false |
Usage
Billing export requests
| Request | Status | Billable | External export |
|---|---|---|---|
| qrbill_local_demo_scan_review | blocked | false | false |
Approval
Review packet evidence
| Packet | Status | Approval | External effect |
|---|---|---|---|
| service_token | blocked_pending_matthew_approval | matthew | false |
| import | blocked_pending_matthew_approval | matthew | false |
| qr_mutation | blocked_pending_matthew_approval | matthew | false |
| activation | blocked_pending_matthew_approval | matthew | false |
| billing_export | blocked_pending_matthew_approval | matthew | false |
| support | blocked_pending_matthew_approval | matthew | false |
Decisions
Operator approval state
| State | Result | Approved | Blocked |
|---|---|---|---|
| blocked | not_executed | 0 | 6 |
Access
Members and invites
- Local QR Owner owner / planned / invite not_sent
- editor@example.invalid editor / draft / delivery not_sent
History
Recent audit evidence
- account_service.seed_packet_prepared account_service asvc_local_qr_demo
- account_service.operator_decision_blocked operator_approval_decision opd_local_qr_demo_001
- qr_code.created qr_code qrc_local_demo_welcome
Support
Local review cases
- Review Starter Open QR import before tenant writes blocked / customer visible false / notification false
Safety
Disabled customer effects
Login is a preview scaffold, memberships are planned, and invite delivery remains not sent.
No billing customer, usage export, hosted redirect, or customer-visible support timeline is active.
acct_local_qr_growth_demo; status draft; external effects false.
growth-owner@example.invalid is owner / planned; auth-provider membership grants are disabled.
Service qr-codes on plan growth; hosted redirects false.
1 draft invite(s); no invite email, customer login, or external user access is sent from this app.
not_executed; customer activation, billing, DNS, production routes, and QR redirects stay blocked.
Tenant home
Command center preview
Start from selected tenant identity and owner context without creating a customer account, password, magic link, provider user, or browser session.
/v1/accounts/acct_local_qr_growth_demo
QR codes, campaigns, scans, imports, and draft changes stay readable while hosted redirects, QR writes, and import execution remain blocked.
/v1/qr/workspaces/qrw_local_growth_demo
Members and invite drafts are visible, but delivery, acceptance links, auth-provider grants, and external sessions stay disabled.
/v1/accounts/acct_local_qr_growth_demo/invites
Approval requirements are visible for operators, but this home screen cannot submit decisions, run production jobs, export usage, or contact customers.
/v1/review-packets/rev_service_token_stok_local_qr_growth_demo_agent_preview/decision-requirements
The tenant home command center makes the first selected-account screen useful from account-scoped reads only; it does not create signup sessions, passwords, magic links, auth-provider users, invite delivery, customer access, billing records, hosted redirects, QR writes, usage exports, approval decisions, customer contact, or production jobs.
Onboarding guide
First-run setup path
Shows the first-run account welcome state from local account and owner reads without creating a signup session, password, magic link, provider user, or customer account.
/v1/accounts/acct_local_qr_growth_demo
Lets the tenant see QR workspace setup progress while hosted redirects, destination changes, imports, customer QR writes, and mutation execution remain blocked.
/v1/qr/workspaces/qrw_local_growth_demo
Shows team invite and role context as setup progress only; invite delivery, acceptance links, membership activation, auth-provider grants, and external sessions stay disabled.
/v1/accounts/acct_local_qr_growth_demo/invites
Keeps launch completion behind operator requirements; this app does not submit approval decisions, create billing records, export usage, contact customers, or run production jobs.
/v1/review-packets/rev_service_token_stok_local_qr_growth_demo_agent_preview/decision-requirements
The onboarding guide gives the selected tenant a first-run setup path from account-scoped reads only; it does not create signup sessions, passwords, magic links, auth-provider users, customer accounts, invite delivery, membership activation, billing records, hosted redirects, QR writes, usage exports, approval decisions, customer contact, or production jobs.
Session center
Login context preview
Shows who the app would treat as the selected tenant actor without creating a password, magic link, provider session, browser token, or customer login.
/v1/accounts/acct_local_qr_growth_demo/auth/token-policy
Membership scope is visible for account context only; auth-provider grants, membership activation, external user access, and invite acceptance remain disabled.
/v1/accounts/acct_local_qr_growth_demo/memberships
Switching tenants changes the visible account panel and route context, but it never broadens read scope or enables cross-account writes.
/app/
Diagnostics can prove runtime auth posture without returning token values, token hashes, request hashes, or idempotency keys to the browser.
/v1/auth/diagnostics
Invite handoff stays as local read state; no invite email, acceptance link, provider user, customer session, or membership activation is created.
/v1/accounts/acct_local_qr_growth_demo/invites
The session center makes login context visible from account-scoped read state only; it does not create passwords, magic links, browser tokens, provider users, external sessions, invite delivery, membership activation, token secrets, hosted redirects, QR writes, customer contact, billing records, or production jobs.
Account settings
Tenant configuration preview
Name, owner, and account status can be reviewed in dev without creating customer login sessions or external account access.
/v1/accounts/acct_local_qr_growth_demo
QR workspace defaults stay read-only; hosted redirects, destination writes, imports, and QR record mutations remain disabled.
/v1/qr/workspaces/qrw_local_growth_demo
Role and invite settings are visible for account context only; invite delivery, acceptance links, and auth-provider grants stay off.
/v1/accounts/acct_local_qr_growth_demo/invites
Plan and usage settings show local read state without creating billing customers, subscriptions, invoices, or export jobs.
/v1/billing/export-requests
Security settings link to token policy diagnostics but never issue token secrets, store hashes, or broaden tenant scope.
/v1/accounts/acct_local_qr_growth_demo/auth/token-policy
Support preferences remain local preview state; replies, ticket sync, customer contact, and external archives are disabled.
/v1/accounts/acct_local_qr_growth_demo/services/asvc_local_qr_growth_demo/support-cases
The account settings preview makes tenant configuration visible from account-scoped read routes only; it does not save profile changes, connect domains, change plans, enable SSO, create signup sessions, send invites, grant auth-provider access, issue token secrets, publish hosted redirects, write QR records, contact customers, export usage, or run production jobs.
Integrations center
Connection setup preview
Future webhook setup can show the event source and support context, but this app does not create endpoints, send webhooks, or sync ticket systems.
/v1/accounts/acct_local_qr_growth_demo/services/asvc_local_qr_growth_demo/support-cases
API access is visible as non-secret request state only; token values, hashes, automation credentials, and external API calls stay disabled.
/v1/accounts/acct_local_qr_growth_demo/service-tokens
The QR adapter can point at rehearsal requirements without importing codes, writing destinations, publishing redirects, or executing mutations.
/v1/qr/workspaces/qrw_local_growth_demo/mutation-requests/qrm_local_growth_demo_menu_archive/execution-rehearsal-requirements
Billing connector setup stays local and non-billable; no Stripe customer, subscription, metered event, invoice, or CSV export is created.
/v1/accounts/acct_local_qr_growth_demo/services/asvc_local_qr_growth_demo/billing-export-requests
Operator sync remains a read-only handoff to decision requirements; this app does not submit approvals, run jobs, contact customers, or deploy production.
/v1/review-packets/rev_service_token_stok_local_qr_growth_demo_agent_preview/decision-requirements
The integrations center previews customer connection setup from account-scoped read state only; it does not create webhook endpoints, send webhooks, issue API keys or token secrets, sync third-party systems, create billing connectors, publish hosted redirects, write QR records, submit approvals, contact customers, or run production jobs.
Billing and plan center
Plan controls preview
Plan context is visible for tenant setup, but plan changes, paid subscriptions, invoices, and customer billing records are not created.
/v1/accounts/acct_local_qr_growth_demo/services
Entitlement reads can explain feature access in dev while billing sync, provider grants, and customer-visible upgrades stay disabled.
/v1/accounts/acct_local_qr_growth_demo/services/asvc_local_qr_growth_demo/entitlements
QR scan evidence remains local and non-billable; no usage record, invoice item, export, or customer charge is produced.
/v1/qr/workspaces/qrw_local_growth_demo
Export requests are inspectable as read-only state; CSV files, PII exports, billing jobs, and customer delivery remain off.
/v1/accounts/acct_local_qr_growth_demo/services/asvc_local_qr_growth_demo/billing-export-requests
Activation evidence stays in the operator path; customer activation, paid access, DNS, redirects, and production jobs remain blocked.
/v1/review-packets/rev_service_token_stok_local_qr_growth_demo_agent_preview/decision-requirements
The dev app can show the future upgrade path without enabling checkout, payment methods, subscription updates, usage exports, or customer contact.
/platform/admin/
The billing and plan center is a read-only tenant preview: it shows plan, entitlement, usage, export, and activation state without creating billing customers, payment methods, paid subscriptions, invoices, usage records, CSV exports, customer emails, hosted redirects, QR writes, or production jobs.
Customer profile center
Profile and contact preview
The app can show local profile and account identity from seed state, but profile writes, signup sessions, passwords, magic links, and auth-provider users are not created.
/v1/accounts/acct_local_qr_growth_demo
Email is displayed for dev account context only; no verification email, customer notification, acceptance link, or external contact is sent.
/v1/accounts/acct_local_qr_growth_demo/memberships
Role context stays account-scoped and read-only; this surface does not grant provider access, activate memberships, or broaden tenant scope.
/v1/accounts/acct_local_qr_growth_demo/memberships
Invite recipients can be previewed, but delivery, acceptance, external user creation, and membership activation remain disabled.
/v1/accounts/acct_local_qr_growth_demo/invites
Service contact preferences are visible as setup context only; support replies, customer contact, ticket sync, and external archives stay off.
/v1/accounts/acct_local_qr_growth_demo/services/asvc_local_qr_growth_demo/support-cases
The customer profile center is a customer-like dev preview assembled from account-scoped reads only; it does not save profile changes, verify emails, send customer notifications, deliver invites, create auth-provider users, grant membership, contact customers, issue token secrets, publish hosted redirects, write QR records, export usage, or run production jobs.
Security center
Access controls preview
The account can show a signed-in preview state, but no password, magic link, provider session, browser token, or external customer access is created.
/v1/accounts/acct_local_qr_growth_demo/auth/token-policy
Service-token requests are inspectable as non-secret records only; secret values, hashes, automation credentials, and external API access stay disabled.
/v1/accounts/acct_local_qr_growth_demo/service-tokens
Audit evidence gives operators a tenant-scoped trail without exposing idempotency keys, request hashes, token values, customer exports, or private notes.
/v1/audit-events
Member and invite context can be reviewed, but invite delivery, acceptance links, provider grants, account activation, and customer sessions remain blocked.
/v1/accounts/acct_local_qr_growth_demo/invites
QR destinations, imports, and rehearsal requirements are readable, while hosted redirects, customer QR writes, mutation execution, and route changes stay off.
/v1/qr/workspaces/qrw_local_growth_demo/mutation-requests/qrm_local_growth_demo_menu_archive/execution-rehearsal-requirements
The security center preview keeps tenant access, token posture, audit coverage, and QR write boundaries visible without enabling credentials: it does not create sessions, send magic links, grant auth-provider access, issue token secrets, expose hashes, publish hosted redirects, write QR records, execute mutations, export customer data, or run production jobs.
Audit history center
Tenant timeline preview
Shows account-scoped audit events as local product history while hiding idempotency keys, request hashes, token values, and private operator notes.
/v1/audit-events
Approval requirements stay visible as read-only history; this app does not submit decisions, execute actions, or publish customer effects.
/v1/review-packets/rev_service_token_stok_local_qr_growth_demo_agent_preview/decision-requirements
QR code and rehearsal history can be inspected without importing codes, changing destinations, publishing redirects, or writing customer-visible records.
/v1/qr/workspaces/qrw_local_growth_demo/mutation-requests/qrm_local_growth_demo_menu_archive/execution-rehearsal-requirements
Membership and invite history remains local evidence only; invite delivery, acceptance links, provider grants, and real sessions stay disabled.
/v1/accounts/acct_local_qr_growth_demo/invites
The audit history center makes account history visible to the dev app from read-only routes only; it does not export logs, reveal idempotency keys, reveal request hashes, expose token values, open private notes, replay actions, contact customers, write QR records, publish redirects, submit approvals, or run production jobs.
Action workbench
Draft the next tenant workflow
growth-owner@example.invalid
Shows the selected tenant and role without creating a password, magic link, auth-provider user, or browser token.
Local QR Growth Demo
Keeps account creation as a local draft and blocks activation, billing, DNS, production routes, and external customer access.
qrw_local_growth_demo
Lets the app frame QR code and destination edits as draft work before any hosted redirect or tenant QR write can run.
growth-admin@example.invalid
Captures who should get access while email delivery, acceptance links, and auth-provider membership grants stay off.
service_token
Moves external effects into the operator path; the app still does not submit approval decisions or production jobs.
| Task | Owner | State | Next move |
|---|---|---|---|
| Open tenant dashboard | Local QR Growth Owner | available | Use the account selector and read-only workspace panels. |
| Draft QR destination change | QR workspace | queued | Review rehearsal requirements before any write can run. |
| Invite teammate | Access | drafted | Keep delivery disabled until the invite acceptance flow is approved. |
| Enable customer launch | Operator | blocked | Requires explicit approval for signup, billing, redirects, QR writes, token secrets, and production execution. |
Session task board
Customer session task queue
The app can show Local QR Growth Demo as selected tenant context without creating credentials or customer access.
- Read route
- /v1/accounts/acct_local_qr_growth_demo
- Blocked write
- real signup session creation
qrw_local_growth_demo backs QR panels with 2 local code(s) and 1 non-billable scan event(s).
- Read route
- /v1/qr/workspaces/qrw_local_growth_demo
- Blocked write
- hosted redirect publishing and QR record writes
1 invite draft(s) are visible without sending email or activating external users.
- Read route
- /v1/accounts/acct_local_qr_growth_demo/invites
- Blocked write
- invite delivery and auth-provider grants
28 blocked action(s) remain routed through operator evidence.
- Read route
- /v1/review-packets/rev_service_token_stok_local_qr_growth_demo_agent_preview/decision-requirements
- Blocked write
- approval decisions and production execution
The action workbench is the customer-product direction for the dev app: workflow controls, drafts, queues, and empty states first. Buttons stay disabled until their matching local draft API and approval boundary are proven; this app still does not create sessions, send invites, publish redirects, issue secrets, export usage, or run production jobs.
The session task board gives each selected tenant a customer-session queue backed by read-only routes only; it blocks signup sessions, invite delivery, auth-provider grants, hosted redirects, QR writes, approval decisions, billable exports, and production execution.
Workspace inbox
Next visible checks
-
Workspace ready
qrw_local_growth_demo
read-only
2 QR code(s), 2 campaign(s), and 1 local scan event(s) are visible without hosted redirects.
/v1/qr/workspaces/qrw_local_growth_demo -
Team access
growth-admin@example.invalid
not_sent
1 invite draft(s) can be reviewed; delivery and auth-provider grants stay disabled.
/v1/accounts/acct_local_qr_growth_demo/invites -
QR review
menu
planned
Mutation rehearsal requirements are inspectable, but customer-visible QR writes remain blocked.
/v1/qr/workspaces/qrw_local_growth_demo/mutation-requests/qrm_local_growth_demo_menu_archive/execution-rehearsal-requirements -
Operator queue
service_token
blocked_pending_matthew_approval
28 approval-gated action(s) stay out of the app surface.
/v1/review-packets/rev_service_token_stok_local_qr_growth_demo_agent_preview/decision-requirements -
Launch blocker
Customer launch disabled
blocked
Signup, invite delivery, billing, hosted redirects, token secrets, QR writes, and production execution remain off.
/platform/admin/
The workspace inbox is assembled from account-scoped read state only; it links to existing GET routes and never creates sessions, invites, billing records, QR redirects, token secrets, customer-visible QR writes, or production jobs.
Launch readiness
What blocks customer launch
The selected tenant can be displayed in dev, but no customer account, password, magic link, provider user, or browser session is created.
- Read route
- /v1/accounts/acct_local_qr_growth_demo
- Blocked launch action
- real signup session creation
QR workspace state is visible as read-only product data while redirects, destination writes, imports, and mutation execution stay blocked.
- Read route
- /v1/qr/workspaces/qrw_local_growth_demo
- Blocked launch action
- hosted redirect publishing and customer QR writes
Members and draft invites are visible for tenant context, but email delivery, acceptance links, grants, and external sessions stay disabled.
- Read route
- /v1/accounts/acct_local_qr_growth_demo/invites
- Blocked launch action
- invite delivery and auth-provider grants
Usage evidence remains local and non-billable; the app cannot create customers, invoices, paid usage, CSVs, or export jobs.
- Read route
- /v1/billing/export-requests
- Blocked launch action
- billing customers, subscriptions, and usage export jobs
Launch stays behind the operator path; this app only links requirements and never submits decisions, runs jobs, or changes production.
- Read route
- /v1/review-packets/rev_service_token_stok_local_qr_growth_demo_agent_preview/decision-requirements
- Blocked launch action
- approval decisions and production execution
The launch readiness preview turns tenant setup into a customer-facing checklist while all customer effects remain blocked: signup sessions, invite delivery, auth-provider grants, billing customers, hosted redirects, QR writes, usage exports, approval submissions, and production execution stay disabled.
Service status center
Tenant services and runtime health
Services are visible as tenant dashboard context only; no customer access, production deployment, repo setting, or external service activation is changed.
/v1/accounts/acct_local_qr_growth_demo/services
Entitlement state can be reviewed without creating billing customers, subscriptions, invoices, paid usage, or export jobs.
/v1/accounts/acct_local_qr_growth_demo/services/asvc_local_qr_growth_demo/entitlements
Activation remains an operator-read path; this app cannot submit approvals, run jobs, issue secrets, deploy production, or contact customers.
/v1/review-packets/rev_service_token_stok_local_qr_growth_demo_agent_preview/decision-requirements
Support state stays local to the dev app and operator evidence; no replies, ticket sync, customer outreach, or external notifications are sent.
/v1/accounts/acct_local_qr_growth_demo/services/asvc_local_qr_growth_demo/support-cases
Runtime health helps operators verify the dev build while production deploy jobs, DNS changes, customer redirects, and infrastructure changes remain manual and disabled here.
/health
The service status center gives each tenant a customer-like service health view and a guarded local activation draft plus local approval path; it does not enable services, create billing records, issue token secrets, run activation jobs, contact customers, change DNS, publish hosted redirects, write QR records, or deploy production.
Notification preferences
Delivery settings preview
Invite notifications can be previewed from draft recipient state, but no email, acceptance link, or auth-provider grant is sent.
/v1/accounts/acct_local_qr_growth_demo/invites
QR alerts stay tied to read-only rehearsal requirements; hosted redirects, webhooks, import execution, and QR writes remain disabled.
/v1/qr/workspaces/qrw_local_growth_demo/mutation-requests/qrm_local_growth_demo_menu_archive/execution-rehearsal-requirements
Usage summaries stay local and non-billable; no customer, subscription, invoice, or export job is created.
/v1/billing/export-requests
Support replies are local review evidence only; this app does not send outreach, submit approvals, or contact customers.
/v1/accounts/acct_local_qr_growth_demo/services/asvc_local_qr_growth_demo/support-cases
Audit notices show non-secret local evidence without sending SMS, exposing token values, or broadening account scope.
/v1/audit-events
The notification preferences preview gives each tenant visible delivery choices without enabling delivery: email, webhooks, SMS, billing exports, support contact, invite acceptance links, auth-provider grants, hosted redirects, QR writes, and production jobs stay disabled.
API console
Try read routes later
The future tenant API console can show account reads without creating signup sessions, browser tokens, customer accounts, or auth-provider users.
/v1/accounts/acct_local_qr_growth_demo
QR workspace reads are visible, but hosted redirects, destination writes, imports, mutation execution, and customer-visible route changes stay blocked.
/v1/qr/workspaces/qrw_local_growth_demo
Membership and invite context can be inspected without sending a browser token, invite email, magic link, password, or external access grant.
/v1/accounts/acct_local_qr_growth_demo/memberships
Decision and rehearsal requirements stay behind operator read paths; this app does not submit approvals, run jobs, write QR records, or deploy production.
/v1/review-packets/rev_service_token_stok_local_qr_growth_demo_agent_preview/decision-requirements
API responses remain on-screen guardrail evidence only; CSV downloads, billing exports, token material, customer data exports, and customer contact stay disabled.
/platform/api/
The API console preview makes future read-route testing visible while keeping the browser inert: it does not send tokens, create sessions, deliver invites, export responses, write QR records, submit approvals, publish hosted redirects, contact customers, or run production jobs.
Export center
Download requests preview
Usage can be previewed from local scan evidence, but no billing customer, invoice, usage record, CSV, or export job is created.
/v1/billing/export-requests
QR code rows stay in the dev app preview only; hosted redirects, destination writes, import execution, and file downloads remain off.
/v1/qr/workspaces/qrw_local_growth_demo
Team access can be reviewed from account-scoped reads without exporting PII, sending invites, or granting auth-provider membership.
/v1/accounts/acct_local_qr_growth_demo/invites
Audit evidence remains non-secret and in-app; idempotency keys, request hashes, token values, and customer-facing downloads stay hidden.
/v1/audit-events
Support history and review evidence stay local; no customer contact, email thread export, approval submission, or external archive is produced.
/v1/accounts/acct_local_qr_growth_demo/services/asvc_local_qr_growth_demo/support-cases
The export center preview shows tenant usage, QR, access, audit, and support download requests without generating files: billing exports, CSV downloads, PII exports, customer contact, hosted redirects, QR writes, token material, approval submissions, and production jobs remain disabled.
Support workspace
Case and escalation preview
Support context is shown from local review state only; customer replies, email threads, public comments, and ticket sync stay disabled.
/v1/accounts/acct_local_qr_growth_demo/services/asvc_local_qr_growth_demo/support-cases
Escalations point to operator requirements but do not submit decisions, run production jobs, change DNS, or contact customers.
/v1/review-packets/rev_service_token_stok_local_qr_growth_demo_agent_preview/decision-requirements
Notes can reference QR workspace and route evidence without writing QR records, publishing hosted redirects, or changing destinations.
/v1/qr/workspaces/qrw_local_growth_demo
Audit notes stay in the dev app preview and never expose idempotency keys, request hashes, token values, or customer data exports.
/v1/audit-events
The support workspace preview keeps customer help and operator escalation visible without external effects: replies, email delivery, public comments, ticket sync, customer contact, approval submissions, QR writes, hosted redirects, DNS changes, secret exposure, and production jobs remain disabled.
Help center
Tenant support articles preview
The first help article can explain the read-only workspace, code library, and launch blockers without enabling signup or QR writes.
/v1/qr/workspaces/qrw_local_growth_demo
Access guidance can describe draft invites and roles, but invite delivery, acceptance links, auth-provider grants, and external sessions stay disabled.
/v1/accounts/acct_local_qr_growth_demo/invites
QR help can point to rehearsal requirements while hosted redirects, imports, destination writes, mutation execution, and customer-visible changes remain blocked.
/v1/qr/workspaces/qrw_local_growth_demo/mutation-requests/qrm_local_growth_demo_menu_archive/execution-rehearsal-requirements
Billing help stays local and non-billable; no customer, subscription, invoice, payment method, usage export, or support contact is created.
/v1/billing/export-requests
Help content can send operators to read-only decision requirements, but this app does not submit approvals, contact customers, or run production jobs.
/v1/review-packets/rev_service_token_stok_local_qr_growth_demo_agent_preview/decision-requirements
The help center preview gives tenants a customer-facing support surface from account-scoped read state only; it does not publish articles, run search, send help email, create tickets, contact customers, grant access, write QR records, export billing data, submit approvals, or run production jobs.
Launch operations
Go-live handoff preview
Operator evidence is visible for scheduling, but this app does not submit approvals, run jobs, or change production state.
/v1/review-packets/rev_service_token_stok_local_qr_growth_demo_agent_preview/decision-requirements
Membership and invite context can be checked before launch; invite delivery, acceptance links, provider grants, and real sessions stay off.
/v1/accounts/acct_local_qr_growth_demo/invites
QR destinations and rehearsal requirements are readable, while hosted redirects, QR writes, imports, and mutation execution stay blocked.
/v1/qr/workspaces/qrw_local_growth_demo/mutation-requests/qrm_local_growth_demo_menu_archive/execution-rehearsal-requirements
Support and audit notes stay local; there is no customer contact, ticket sync, external archive, secret exposure, or usage export.
/v1/accounts/acct_local_qr_growth_demo/services/asvc_local_qr_growth_demo/support-cases
The launch operations preview gives each tenant a go-live handoff checklist without enabling effects: approval decisions, customer access, invite delivery, auth-provider grants, hosted redirects, QR writes, imports, mutation execution, support contact, usage exports, and production jobs remain disabled.
QR editor
Draft tray preview
- Current destination
- https://example.invalid/fall-event
- Draft destination
- https://example.invalid/fall-event
- Style
- dots
- Campaign
- Event signage
POST
/v1/qr/workspaces/qrw_local_growth_demo/mutation-requests
Idempotency-Key required; persists planned review request
plus audit readback.
/v1/qr/workspaces/qrw_local_growth_demo
- Current destination
- https://example.invalid/menu
- Draft destination
- https://example.invalid/menu
- Style
- squares
- Campaign
- On-site menu
POST
/v1/qr/workspaces/qrw_local_growth_demo/mutation-requests
Idempotency-Key required; persists planned review request
plus audit readback.
/v1/qr/workspaces/qrw_local_growth_demo/mutation-requests/qrm_local_growth_demo_menu_archive/execution-rehearsal-requirements
The QR editor draft tray points at guarded dev-only POSTs for draft creation, local review approval, and local execution rehearsal with idempotency and audit readback. Browser controls stay disabled here; tenant QR record writes, hosted redirects, billable scan updates, customer-visible route changes, and production execution remain blocked until explicit approval exists.
QR campaign planner
Campaigns before launch
- Codes
- fall-event
- Local scans
- 1
- QR reviews
- 0
- Draft destination
- https://example.invalid/fall-event
/v1/qr/workspaces/qrw_local_growth_demo
- Codes
- menu
- Local scans
- 0
- QR reviews
- 1
- Draft destination
- https://example.invalid/menu
/v1/qr/workspaces/qrw_local_growth_demo/mutation-requests/qrm_local_growth_demo_menu_archive/execution-rehearsal-requirements
The QR campaign planner groups code, scan, destination, and review state into a customer-like product view without enabling launch actions: campaign creation, code writes, hosted redirects, usage exports, invite notices, customer messages, and production execution remain disabled.
QR library
Codes ready for review
https://example.invalid/fall-event
- Campaign
- Event signage
- Status
- planned
- Local scans
- 1
- Hosted redirect
- blocked
/v1/qr/workspaces/qrw_local_growth_demo
Billable usage false; QR writes and redirect publishing
remain disabled.
https://example.invalid/menu
- Campaign
- On-site menu
- Status
- planned
- Local scans
- 0
- Hosted redirect
- blocked
/v1/qr/workspaces/qrw_local_growth_demo
Billable usage false; QR writes and redirect publishing
remain disabled.
The QR workspace library is read-only customer-facing state: it shows code destinations, campaign grouping, local scan evidence, and route links without publishing hosted redirects, writing QR records, exporting billable usage, or changing customer access.
Local QR Growth Demo
growth-owner@example.invalid; external auth provider false.
Account service records are modeled before customer enablement.
Service-token requests are visible without secret material.
Scan evidence is local and non-billable until exports are approved.
Approval evidence is readable before local-only decisions execute.
Dashboard summary
What is visible now
Dev users can inspect workspace state, but signup, real sessions, invite delivery, hosted redirects, billing, token secrets, QR writes, and production jobs remain disabled.
#account-acct_local_qr_growth_demo
2 campaign(s), 1 local scan event(s), and hosted redirects false.
/v1/qr/workspaces/qrw_local_growth_demo
28 blocked action(s) stay in operator read paths; the app does not POST decisions.
/v1/review-packets/rev_service_token_stok_local_qr_growth_demo_agent_preview/decision-requirements
Membership and invite context is visible for account selection only; auth-provider grants, magic links, and external sessions are not created.
/v1/accounts/acct_local_qr_growth_demo/memberships
The dashboard summary is a customer-like dev view assembled from account-scoped reads only; it does not create signup sessions, send invites, grant auth-provider access, issue token secrets, enable billing, publish hosted redirects, write QR records, export usage, or run production jobs.
Tenant health
Workspace status summary
Account context is visible in dev with external customer effects disabled.
/v1/accounts/acct_local_qr_growth_demo
2 code(s), 2 campaign(s), and hosted redirects false.
/v1/qr/workspaces/qrw_local_growth_demo
Membership and invite state is readable, but real login, invite delivery, and auth-provider grants stay disabled.
/v1/accounts/acct_local_qr_growth_demo/memberships
Local usage evidence can be inspected without exporting billable usage or creating billing records.
/v1/qr/workspaces/qrw_local_growth_demo
Decision and rehearsal requirements stay operator-gated; this app only submits local-only review approval and rehearsal POSTs after fresh fingerprint readback, never customer-visible execution.
/v1/review-packets/rev_service_token_stok_local_qr_growth_demo_agent_preview/decision-requirements
Signup, billing, invites, hosted redirects, QR writes, token secrets, and production execution require explicit approval.
/platform/admin/
The tenant health overview is generated from account-scoped read state and existing /v1 routes only; it does not create sessions, send invites, grant access, enable billing, publish hosted redirects, write QR records, issue token secrets, or run production jobs.
Login readiness
Session and workspace access
Email is displayed from seed data for dev session context; no password, magic link, or auth-provider credential is created.
Visible reads stay scoped to acct_local_qr_growth_demo; cross-account access remains blocked by the protected /v1 routes.
Draft invites can be inspected here, but invite email delivery and external user access remain disabled.
Switching accounts changes the visible tenant context without enabling customer signup, hosted redirects, or QR writes.
Auth flow preview
From email to workspace
-
Enter email
prefilled
growth-owner@example.invalid
/app/ -
Check membership
planned
owner access is read from account membership seed data; auth-provider grants are not created.
/v1/accounts/acct_local_qr_growth_demo/memberships -
Select workspace
available
qrw_local_growth_demo opens as the visible workspace for Local QR Growth Demo.
/v1/qr/workspaces/qrw_local_growth_demo -
Open dashboard
read-only
Account, QR, usage, access, review, and audit panels render without POST actions or customer effects.
#account-acct_local_qr_growth_demo-qr -
Ask operator
approval required
Real signup, invite delivery, service-token secrets, billing, hosted redirects, QR writes, and production execution stay blocked.
/v1/review-packets/rev_service_token_stok_local_qr_growth_demo_agent_preview/decision-requirements
The dev auth flow preview is local and read-only: it does not create passwords, magic links, provider users, customer accounts, invites, token secrets, billing records, QR redirects, or production access.
Access review
Who can see this workspace
-
Member
growth-owner@example.invalid
owner / planned
This identity can be inspected in dev account context, but no auth-provider grant, password, magic link, or external session is created.
/v1/accounts/acct_local_qr_growth_demo/memberships -
Invite draft
growth-admin@example.invalid
admin / not_sent
The invite is visible as a draft only; delivery, acceptance, external user access, and membership activation remain disabled.
/v1/accounts/acct_local_qr_growth_demo/invites
The access review preview is account-scoped and read-only: it does not deliver invites, create customer sessions, grant auth-provider membership, activate external users, or expose token material.
Route readiness
Read paths behind this workspace
Backs selected-account context without exposing broad operator data or cross-account tenant state.
Feeds QR workspace, code, campaign, usage, and route panels while hosted redirects remain disabled.
Keeps approval evidence in the operator path; this app does not submit decisions or reveal idempotency values.
Signup, invite delivery, token issuance, hosted redirects, customer QR writes, import execution, billing exports, and production execution need explicit approval.
Workspace activity
Tenant activity timeline
-
QR code
Fall event
planned
Slug fall-event; hosted redirect false.
/v1/qr/workspaces/qrw_local_growth_demo -
QR code
Table menu
planned
Slug menu; hosted redirect false.
/v1/qr/workspaces/qrw_local_growth_demo -
Import review
open_qr_library_export
planned
2 planned / 1 rejected; import performed false.
/v1/qr/workspaces/qrw_local_growth_demo -
Mutation rehearsal
menu
planned
Approval required true; customer-visible write false.
/v1/qr/workspaces/qrw_local_growth_demo/mutation-requests/qrm_local_growth_demo_menu_archive/execution-rehearsal-requirements -
Redirect check
fall-event
external_redirects_not_approved
Redirect performed false; destination remains read-only in dev.
/v1/qr/workspaces/qrw_local_growth_demo -
Audit evidence
account_service.seed_packet_prepared
skipped
account_service asvc_local_qr_growth_demo; actor system/local.
/v1/audit-events -
Audit evidence
account_service.operator_decision_blocked
skipped
operator_approval_decision opd_local_qr_growth_demo_001; actor system/local.
/v1/audit-events -
Audit evidence
qr_code.created
skipped
qr_code qrc_local_growth_demo_event; actor usr_local_qr_growth_owner.
/v1/audit-events
Activity is assembled from account-scoped seed and /v1 read routes only; it does not create login sessions, send invites, write QR records, publish redirects, export usage, or reveal token values.
Customer journey
First-run setup preview
-
1
Choose workspace ready
Local QR Growth Demo opens qrw_local_growth_demo with 2 read-only QR code(s).
-
2
Invite team drafted
1 invite draft(s) are visible; delivery and auth-provider access stay disabled.
-
3
Review QR changes approval-gated
1 QR change rehearsal(s) can be inspected without writing tenant records.
-
4
Launch blocked
Launch remains blocked: signup, billing, hosted redirects, invite delivery, token secrets, and production execution are off.
This journey is a dev-only preview assembled from account-scoped read state; it does not create accounts, send invites, grant access, enable billing, publish redirects, issue token secrets, or run production jobs.
Customer action map
What customers can see today
-
Workspace read
visible in dev
Customer effect false
Already GET-only; no approval needed for local reads.
/v1/qr/workspaces/qrw_local_growth_demo -
Signup session
preview scaffold
Customer effect false
Matthew approval required before real accounts, credentials, or auth-provider users exist.
/app/ -
Invite delivery
drafts visible
Customer effect false
Operator approval required before email delivery, acceptance links, or external user access.
/v1/accounts/acct_local_qr_growth_demo/invites -
Token secret issuance
requests visible
Customer effect false
Operator approval required before any secret value, hash storage, or external API access.
/v1/accounts/acct_local_qr_growth_demo/service-tokens -
Hosted redirect publishing
blocked by workspace
Customer effect false
Approval required before hosted redirects, QR writes, import execution, or destination changes.
/v1/qr/workspaces/qrw_local_growth_demo -
Billing usage export
request visible
Customer effect false
Matthew approval required before billing customers, subscriptions, billable usage, or export jobs.
/v1/billing/export-requests
The customer action map separates visible read-only app surfaces from future customer effects; signup sessions, invite delivery, token secrets, hosted redirects, QR writes, billing records, and production execution stay disabled.
Data source map
Read routes behind each app panel
-
Session and account
/v1/accounts/acct_local_qr_growth_demo
seeded account context
Blocked write: customer signup and real session creation -
Workspace library
/v1/qr/workspaces/qrw_local_growth_demo
bundled QR workspace, codes, campaigns, and scan evidence
Blocked write: hosted redirect publishing, QR writes, and import execution -
Team access
/v1/accounts/acct_local_qr_growth_demo/memberships
planned members and invite drafts
Blocked write: invite delivery and auth-provider membership grants -
Billing and usage
/v1/billing/export-requests
local non-billable scan and export-request evidence
Blocked write: billing customers, subscriptions, and usage export jobs -
Operator review
/v1/review-packets/rev_service_token_stok_local_qr_growth_demo_agent_preview/decision-requirements
review packet and blocked-action evidence
Blocked write: customer-visible decisions, token secrets, and production execution -
Runtime health
/health and /v1/auth/diagnostics
static preview when runtime reads are unavailable
Blocked write: browser token submission and mutation retries
The data source map keeps the visible tenant app honest: every panel either reads an account-scoped GET route or falls back to bundled seed data, and it never retries with POST, sends browser tokens, creates sessions, delivers invites, exports usage, publishes redirects, writes QR records, or runs production jobs.
Setup readiness
Account launch checklist
growth-owner@example.invalid can preview this account with local/dev read-only context.
qrw_local_growth_demo has 2 code(s), 1 import review(s), and 1 mutation rehearsal(s).
1 invite(s) are drafted; real delivery and auth-provider grants require approval.
External signup, invites, billing, hosted redirects, token secrets, and usage exports remain disabled.
Access policy
Dev auth stays account-scoped
Scoped automation credentials for future QR import, read-only review, and billing-review helpers. Fixture records must never issue secret material before Matthew approval.
- Account route
- /v1/accounts/acct_local_qr_growth_demo/auth/token-policy
- Tenant isolation
- cross-account reads fail closed with problem+json
- Secret material
- not issued, returned, hashed, or stored
Allowed read scopes
- qr:read Read QR workspace, campaign, code, route, usage, and audit fixture records.
- qr:plan_import Prepare Open QR import previews without writing hosted QR records.
- billing_export:read Read blocked billing-export review records without exporting usage.
Blocked until approval
- Admin-only token approval records exist.
- Secret material can be issued once and stored only as a hash.
- Every token action writes an audit event before customer or external automation access opens.
Operator handoff
Local-only decision path
Reviewers can inspect the current account-scoped requirements before any local-only decision or QR rehearsal. Idempotency-Key required; key values and request hashes stay hidden.
External signup, invites, billing, hosted redirects, token secrets, customer-visible QR writes, import execution, and production execution remain disabled.
Decision requirements
| Packet | Status | Read route | Blocked |
|---|---|---|---|
| service_token | blocked_pending_matthew_approval | /v1/review-packets/rev_service_token_stok_local_qr_growth_demo_agent_preview/decision-requirements | 6 blocked action(s) |
| import | blocked_pending_matthew_approval | /v1/review-packets/rev_import_qrimp_local_growth_demo_open_qr_library/decision-requirements | 9 blocked action(s) |
| qr_mutation | blocked_pending_matthew_approval | /v1/review-packets/rev_qr_mutation_qrm_local_growth_demo_menu_archive/decision-requirements | 5 blocked action(s) |
| activation | blocked_pending_matthew_approval | /v1/review-packets/rev_activation_local-qr-growth-demo/decision-requirements | 8 blocked action(s) |
| billing_export | blocked_pending_matthew_approval | /v1/review-packets/rev_billing_qrbill_local_growth_demo_scan_review/decision-requirements | 4 blocked action(s) |
QR rehearsal requirements
| Code | Status | Read route | Reason |
|---|---|---|---|
| menu | planned | /v1/qr/workspaces/qrw_local_growth_demo/mutation-requests/qrm_local_growth_demo_menu_archive/execution-rehearsal-requirements | local_mutations_not_approved |
Services
Account service state
| Service | Plan | Status | External effects |
|---|---|---|---|
| QR Codes | growth | modeled | false |
Workspace
QR tenant preview
planned; hosted redirects false; 2 planned code(s); 1 import review(s); 1 mutation rehearsal(s).
QR codes
Codes and redirect status
| Slug | Label | Status | Redirect enabled |
|---|---|---|---|
| fall-event | Fall event | planned | false |
| menu | Table menu | planned | false |
Imports
Open QR import review
| Source | Status | Imported | External effect |
|---|---|---|---|
| open_qr_library_export | planned | false | false |
Changes
Mutation rehearsal status
| Code | Status | Approval | External effect |
|---|---|---|---|
| menu | planned | true | false |
Routes
Hosted redirect readiness
| Slug | Workspace | Redirected | Reason |
|---|---|---|---|
| fall-event | planned | false | external_redirects_not_approved |
Campaigns
QR campaign usage
| Campaign | Status | Codes | Scan events |
|---|---|---|---|
| Event signage | planned | 1 | 1 |
| On-site menu | planned | 1 | 0 |
Scan evidence
Usage stays non-billable
| Code | Quantity | Billable | Export |
|---|---|---|---|
| fall-event | 1 | false | not_enabled |
Credentials
Service-token requests
| Name | Status | Secret issued | Scopes |
|---|---|---|---|
| Local QR growth agent preview | planned | false | qr:read, qr:plan_import, billing_export:read |
Plan
Entitlements and billing sync
| Entitlement | Kind | Value | Billing sync |
|---|---|---|---|
| active_qr_codes | limit | 250 | not_created |
| monthly_scans | metered-limit | 50000 | not_created |
| scan_retention_days | limit | 365 | not_created |
| custom_domains | feature | false | not_created |
| branded_exports | feature | true | not_created |
Activation
Account enablement packet
| Packet | Status | Billing customer | External effect |
|---|---|---|---|
| local-qr-growth-demo | blocked_pending_matthew_approval | null | false |
Usage
Billing export requests
| Request | Status | Billable | External export |
|---|---|---|---|
| qrbill_local_growth_demo_scan_review | blocked | false | false |
Approval
Review packet evidence
| Packet | Status | Approval | External effect |
|---|---|---|---|
| service_token | blocked_pending_matthew_approval | matthew | false |
| import | blocked_pending_matthew_approval | matthew | false |
| qr_mutation | blocked_pending_matthew_approval | matthew | false |
| activation | blocked_pending_matthew_approval | matthew | false |
| billing_export | blocked_pending_matthew_approval | matthew | false |
| support | blocked_pending_matthew_approval | matthew | false |
Decisions
Operator approval state
| State | Result | Approved | Blocked |
|---|---|---|---|
| blocked | not_executed | 0 | 6 |
Access
Members and invites
- Local QR Growth Owner owner / planned / invite not_sent
- growth-admin@example.invalid admin / draft / delivery not_sent
History
Recent audit evidence
- account_service.seed_packet_prepared account_service asvc_local_qr_growth_demo
- account_service.operator_decision_blocked operator_approval_decision opd_local_qr_growth_demo_001
- qr_code.created qr_code qrc_local_growth_demo_event
Support
Local review cases
- Review Growth Open QR library import before tenant writes blocked / customer visible false / notification false
Safety
Disabled customer effects
Login is a preview scaffold, memberships are planned, and invite delivery remains not sent.
No billing customer, usage export, hosted redirect, or customer-visible support timeline is active.