Account Setup & Role Mapping Preview
Purpose
This preview explains the account and role boundaries that must be settled before any future protected pull-up or push-up workflow is allowed. It is a planning surface only.
No app accounts, resident profiles, identity storage, attendance tracking, participation tracking, or live submission permissions exist in this phase.
Why Account Setup Must Come Before Live Submissions
Future community drafts would need clear role boundaries before anything can be collected or reviewed. Without that boundary, the app cannot safely decide who may draft, who may review, what may be retained, or what must stay out of the system.
This phase does not create those permissions. It only names the gates that would be required later.
Future Role Model
Resident
Future participant role for a person who may draft repair or recognition items only after protected account and policy gates exist.
residentPeer Leader
Future trusted peer role that may help model accountable language, without becoming a staff decision maker.
peer-leaderStaff Reviewer
Future staff review role for checking privacy, safety, and morning-sheet readiness after institutional approval.
staff-reviewerProgram Admin
Future administrative role for policy configuration and role oversight after privacy approval and a small pilot decision.
program-adminWhat Cloudflare Access Protects
Cloudflare Access is the future outer gate for protected preview routes.
- Protected preview routes sit under
/protected-preview/. - Cloudflare Access is the outer gate for the sandbox path family.
- The app does not read identity headers or assign roles in this phase.
- The safe diagnostic endpoint returns booleans only and never identity details.
What The App Must Not Store Yet
- Cloudflare Access is the future outer gate for protected preview routes.
- App-level account creation is not implemented.
- No app accounts exist in this phase.
- No identity values are stored.
- No resident profiles exist.
- No attendance or participation tracking exists.
- No live submission permissions exist.
- Live launch requires staff approval, role mapping policy, retention policy, audit logging, privacy approval, a small pilot group, and a rollback plan.
Future Role Permissions
| Role | Future expectation | Blocked now | Required gates |
|---|---|---|---|
| Resident | May eventually access resident-safe draft screens after Cloudflare Access and app role mapping are approved. Must not receive staff review, retention, or role-management capabilities. | no app account exists today; no live submission permission exists today; no access to staff review lanes; no attendance or participation tracking | privacy check, safety check, staff review, retention rule |
| Peer Leader | May eventually see peer-leader guidance after Cloudflare Access and role mapping are approved. Must not approve, deny, delete, or archive community content. | no staff decision authority; no identity lookup; no resident profile access; no export or archive access | non-shaming language check, staff review, privacy approval |
| Staff Reviewer | May eventually access staff review queues only after approved protected account setup. Must operate within retention, audit-log, and privacy policies. | no live staff queue exists today; no staff decisions are recorded today; no resident profile database exists; no attendance or participation metrics exist | privacy check, safety check, specificity check, retention rule, audit logging |
| Program Admin | May eventually manage approved role mapping rules. Must not bypass staff review, retention, audit, or privacy boundaries. | no account-management screen exists today; no email list or identity store exists today; no resident roster exists today; no compliance scoring exists today | staff approval, role mapping policy, retention policy, audit logging, privacy approval |
Manual Onboarding Checklist
These are future planning questions only. No onboarding workflow exists in the app.
- confirm Access-protected route works
- confirm public routes remain public
- define role groups outside app code
- decide who may draft future pull-ups and push-ups
- decide who may perform staff review
- decide what is retained
- decide how not-appropriate drafts are handled
- decide whether residents may see their own future history
- decide whether staff may export anything
- decide deletion and retention windows
Staff Approval Gate
Future role mapping and submission permissions would need staff approval before any protected workflow can launch. This preview does not make staff decisions or create a staff queue.
Privacy And Retention Boundaries
- No identity values are stored in this phase.
- No resident profile, roster, attendance record, participation record, scoring model, ranking, discipline point, or compliance metric exists.
- No retention window exists for pull-up or push-up content because no live content is collected.
- Any future pilot would need deletion rules, audit logging, privacy approval, and rollback planning before live launch.
Synthetic Example Assignments
These are generic placeholders only: Resident A, Resident B, Peer Leader, Staff Reviewer, and Program Admin.
| Placeholder | Future role | Status | Boundary note |
|---|---|---|---|
| Resident A | resident | synthetic planning example | Would need protected access, role mapping, and staff-approved privacy policy before any future draft permission. |
| Resident B | resident | synthetic planning example | Would not create a resident profile or attendance record in this phase. |
| Peer Leader | peer-leader | synthetic planning example | Would support safer language only if a future staff policy allows that role. |
| Staff Reviewer | staff-reviewer | synthetic planning example | Would review future drafts only after approved retention, audit, and privacy gates exist. |
| Program Admin | program-admin | synthetic planning example | Would oversee approved role policy without storing identity values in source code. |
What Remains Blocked Before Live Launch
- Approved role mapping policy
- Staff approval procedure
- Retention and deletion policy
- Audit logging plan
- Privacy approval
- Small pilot group
- Rollback plan
- Decision on whether residents may see their own future history
This preview does not create accounts, collect identity details, enable resident profiles, or activate live submissions.