Tenants (dev)
3
Provider Group Demo + 2 sandboxes flat
super_dev_admin · authenticated normally · dev-only impersonation under separate gate
No production credentials, accounts, or PHI surface here. Every action emits an audit entry; impersonation is dev-environment-only.
Tenants (dev)
3
Provider Group Demo + 2 sandboxes flat
Active roles
6
in the dev surface flat
PromptOps gates (lane)
17
commercial-architecture-v2 + deployment +1
Audit entries (24h)
68
across 4 ledgers +12
Active deployments
1
Cloudflare Pages dev preview stable
Production posture
Closed
no live PHI, no autonomous decisioning enforced
Default-deny across ledgers · cross-ledger references shown as controlled IDs only
Care documentation · review state · clinical workflow · provider review.
42 entries
last 24h · all human-reviewed
Commercial revenue scope · provider invoice surface · not clinical billing.
6 entries
last 24h · cross-ledger refs controlled
CHW activity time · supervision · no CPT generation.
11 entries
last 24h · isolated from clinical ledger
Identity · permission · consent state · audit emission.
9 entries
last 24h · audit envelope is global
All ledger counts are synthetic. No real clinical, commercial, workforce, or auth records appear here.
Default-deny · assignment-aware · audit-emitting
| Role | Scope | Surface | Audit |
|---|---|---|---|
| super_dev_admin | Dev tenant only | This console + audited impersonation | Always emit |
| super_admin | Tenant-scoped admin (future) | Admin portal (future gate) | Always emit |
| provider_user | Provider Group Demo | Provider command center | Always emit |
| chw_user | Assigned panel + visits | CHW field workflow | Always emit |
| biller_user | Commercial ledger only | Provider-invoice surface (future) | Always emit |
| beta_applicant | Read-only · pending approval | Registration sandbox | Limited |
Not production auth · gated by separate sealed authorization
The super_dev_admin role authenticated normally to reach this console. From here, they may temporarily walk a tenant's workspace under a non-production policy. Every impersonation step emits an audit-ledger entry and is disabled when the environment is production.
"Super admin bypasses login auth" is explicitly prohibited. The safe pattern is normal authentication + dev-only audited impersonation under a separately authorized non-production gate.
Commercial-architecture v2 + deployment lanes
Commercial architecture bounded authorization (a9b7a79)
Bounded implementation execution (29098a4) → visual review PASS (9058a53)
PR #12 merge (da55793) → post-merge mainline closure (dec9479)
Cloudflare Pages planning → bounded authorization → Wrangler amendment → account-custody amendment
Deployment execution + portal prototype v2
Custom-domain migration planning
Cloudflare Pages · static envelope
| Surface | Status | Updated |
|---|---|---|
| Public website + portalsjoypartnersos-public-website.pages.dev | Live | min ago |
| www.joypartners.healthexisting app · not in this lane | Workers app | — |
| app.joypartners.health | Reserved | — |
| admin.joypartners.health | Reserved | — |
| api.joypartners.health | Reserved | — |
Dev preview only · no live runtime gates
| Flag | Env | Status | Owner |
|---|---|---|---|
| telehealth.broadcast | dev | provider_user | |
| smart_visit.barrier_capture | dev | chw_user | |
| referral.partner_portal | dev | partner | |
| billing.commercial_ledger_writes | — | biller_user (future) | |
| admin.impersonate_in_production | — | locked · sealed gate required |
Live tail · 24h · ledger-tagged
| When | Actor | Action | Ledger | Evidence |
|---|---|---|---|---|
| 14:38Z | Operator Console | Hybrid note staged for sign-off | Clinical / CPT | REF-EV-0042 |
| 14:21Z | Audit emitter | Consent state updated | Platform / Auth / Audit | REF-EV-0043 |
| 14:14Z | Operator Console | CPT candidate staged | Clinical / CPT | REF-EV-0042 |
| 14:08Z | Provider Group Demo | Hybrid note opened | Clinical / CPT | REF-EV-0042 |
| 14:02Z | CHW Team Member 03 | Smart visit captured | Clinical / CPT | REF-EV-0042 |
| 13:42Z | CHW Team Member 03 | Vital-sign flag raised | Clinical / CPT | REF-EV-0045 |
| 13:24Z | Workforce ledger | Time block logged (3.4h smart visits) | Workforce / Payroll | — |
| 12:55Z | Network Partner A | Referral acknowledged · REF-0001 | Platform / Auth / Audit | — |
Super Admin Dev Console · simulated · audited impersonation requires its own sealed gate · super-admin-bypass-of-login is prohibited.