Renata Admin Configuration Foundation
Purpose
This page defines the configuration foundation Renata will need before future deployments can have community settings, role sets, workflow sets, permission definitions, or retention policy controls.
It is not user admin, role admin, account setup, tenant setup, or a staff decision surface. It is metadata and planning only.
Current Field-Lab Community
6th Street
- ID
- field-lab-6th-street
- Status
- field-lab
- Instance
- The Sixth Sense at 6th Street
- Platform
- Renata
Current field-lab community only. This is not a real customer list and does not include facility details beyond the existing 6th Street context.
Future Community Configuration Model
Future community configuration may describe a deployment label, active workflow set, role set, and retention policy. This phase only names the configuration categories; it does not store customer records or facility details.
There is no real customer list and no live tenant database in this phase.
Default Role Set
Default Renata role set
Resident
resident
Future participant role for approved community workflows after identity and privacy policy approval.
Peer Leader
peer-leader
Future peer support role that may help identify drafts but cannot approve public reading.
Staff Reviewer
staff-reviewer
Future protected review role for staff-approved workflow checks after role policy approval.
Program Admin
program-admin
Future configuration role for approved staff operators after account, audit, and privacy gates.
Permission Set Map
| Permission | Status | Risk | Boundary |
|---|---|---|---|
| view_daily_packet View Daily Packet | available-static | low | Read-only public/source-backed packet view. |
| view_presenter_script View Presenter Script | available-static | low | Read-only presenter script generated from packet data. |
| view_operator_summary View Operator Summary | available-static | low | Read-only packet diagnostics; not staff admin. |
| view_protected_previews View Protected Previews | protected-preview | low | Protected read-only planning surfaces only. |
| draft_pullup Draft Pull-Up | future-only / blocked-before-live | high | No live pull-up drafts exist until account, identity, review, retention, and privacy gates are approved. |
| draft_pushup Draft Push-Up | future-only / blocked-before-live | high | No live push-up drafts exist until account, identity, review, retention, and privacy gates are approved. |
| review_drafts Review Drafts | future-only / blocked-before-live | high | No staff review decisions, notes, approvals, or rejections exist in this phase. |
| approve_for_morning_sheet Approve For Morning Sheet | future-only / blocked-before-live | high | No real Morning Sheet placement or approval workflow exists. |
| manage_role_sets Manage Role Sets | future-only / blocked-before-live | medium | No role admin CRUD or configuration writes exist. |
| manage_workflow_sets Manage Workflow Sets | future-only / blocked-before-live | medium | No workflow admin CRUD or configuration writes exist. |
| manage_retention_policy Manage Retention Policy | future-only / blocked-before-live | high | Retention policy is planning-only and cannot be changed by the app. |
Dangerous permissions are marked future-only, blocked-before-live, and requiring staff/privacy approval.
Workflow Set Map
Morning Meeting Packet
Source-backed Daily Packet, Presenter Script, and Operator diagnostics.
morning-meeting-packet
live-staticPull-Up / Push-Up Accountability
Future community accountability workflow; synthetic and planning-only in this phase.
pullup-pushup-accountability
protected-preview / blocked-before-liveStaff Review
Future staff review queue and review gates; no decisions or notes are stored.
staff-review
protected-preview / blocked-before-liveMorning Sheet Placement
Future reviewed display placement; no real Morning Sheet placements are created.
morning-sheet-placement
synthetic-only / blocked-before-liveRetention And Audit
Future retention and audit model; no audit logs or deletion jobs exist.
retention-and-audit
planning-only / blocked-before-liveWhat Future Role Admin Will Manage
Future role admin may manage role labels, permission mappings, and role-set versions after staff/privacy review. This page does not include role-admin CRUD, permission changes, or configuration writes.
What Future User Admin Will Manage
Future user admin may assign approved people to approved roles only after identity policy, account model, audit logging, retention rules, and privacy approval. This phase has no users, profiles, account records, or identity storage.
Future Admin Module Roadmap
Role Set Admin
Future ability to define roles and permissions.
No CRUD yet.
blocked until staff/privacy reviewWorkflow Set Admin
Future ability to configure workflow modules for a community.
No CRUD yet.
blocked until staff/privacy reviewUser Admin
Future ability to assign people to roles.
No users yet.
blocked until identity policy and privacy approvalCommunity Admin
Future ability to configure instance settings.
No customer data yet.
blocked until tenant/community model approvalPlanning-Only Config Schema Metadata
This is planning-only admin configuration schema metadata. It does not create active tables, migrations, write endpoints, user records, role-admin CRUD, or configuration storage.
| Planned table | Status | Purpose | Classification | Launch blocker |
|---|---|---|---|---|
| future_communities | planned-only | Planning placeholder for future community or tenant configuration records. | configuration metadata planning | Requires tenant/community model approval, privacy review, audit policy, and rollback plan. |
| future_role_sets | planned-only | Planning placeholder for named role sets assigned to a community. | configuration metadata planning | Requires staff-approved role policy and audit logging. |
| future_roles | planned-only | Planning placeholder for role definitions such as resident, peer-leader, staff-reviewer, and program-admin. | configuration metadata planning | Requires role naming, permission review, staff approval, and privacy approval. |
| future_permissions | planned-only | Planning placeholder for global permission definitions and safety categories. | configuration metadata planning | Requires permission taxonomy and dangerous-permission review. |
| future_role_permissions | planned-only | Planning placeholder for mapping approved roles to approved permissions. | restricted configuration metadata planning | Requires staff approval, privacy approval, and admin audit events. |
| future_workflow_sets | planned-only | Planning placeholder for community workflow module configuration. | configuration metadata planning | Requires workflow policy, staff review boundaries, privacy approval, and rollback plan. |
| future_workflow_permissions | planned-only | Planning placeholder for mapping workflow modules to required permissions. | restricted configuration metadata planning | Requires role/permission policy, workflow policy, and admin audit logging. |
| future_admin_config_audit_events | planned-only | Planning placeholder for audit events around future configuration changes. | restricted operational audit planning | Requires audit event policy, retention policy, export policy, staff approval, and privacy approval. |
What Remains Blocked
Recommended Next Phase
Phase 7.5 - Config-Only Role Set CRUD Design, Planning Only
Phase 7.4 now adds the Admin CRUD Readiness Review. The next planning step is a narrow role-set template CRUD design without implementation, migrations, writes, user assignment, identity capture, or submissions.
planning-only