Renata protected draft pilot architecture

Protected Draft Pilot Architecture Package

Protected, read-only package that consolidates account, actor, role, draft, review, visibility, retention, and audit planning for a future pilot.

This is a protected, read-only architecture package. It does not collect pull-ups or push-ups, create drafts, create accounts, assign users, create staff decisions, write data, activate migrations, or enable live workflows.

Purpose

This architecture package turns the Phase 8 planning stack into an implementation-oriented map for a possible future protected pull-up/push-up draft pilot.

It is a planning package only. It creates no drafts, accounts, actor records, staff decisions, write endpoints, tables, SQL migrations, retention jobs, audit logs, or live workflows.

Current No-Go Status

Package status

planning-only

planning-only

Implementation readiness

not-ready-for-live-implementation

not-ready-for-live-implementation

Go / no-go

no-go

no-go

Prior planning layers are planning-complete, but no approved identity policy, actor storage, role mapping storage, draft storage, staff review storage, retention/deletion implementation, audit logging implementation, D1 schema, active migrations, write endpoints, or staff/privacy approval exists.

The prior planning stack is consolidated for architecture review only. Live draft collection, account storage, actor storage, staff decisions, Morning Sheet placement, writes, migrations, tracking, analytics, and scoring remain inactive.

Planning Stack Map

Layer Route Planning Implementation Next dependency Remaining blocker
Cloudflare Access Claim Boundary Review /protected-preview/access-claim-boundary/ planning-complete not-implemented identity policy approval Access claims are not exposed, stored, logged, or mapped to roles.
Actor Reference Schema Planning /protected-preview/actor-reference-schema/ planning-complete not-implemented actor storage policy and local-only migration draft No actor records, identity mapping, or active table exists.
Account Role Mapping Schema Planning /protected-preview/account-role-mapping-schema/ planning-complete not-implemented role mapping policy and local-only migration draft No live role assignment, account record, or role mapping storage exists.
Pull-Up / Push-Up Draft Schema Planning /protected-preview/pullup-pushup-draft-schema/ planning-complete not-implemented draft content policy and local-only draft storage schema No draft collection, draft storage, submission intake, or content write path exists.
Staff Review Procedure Planning /protected-preview/staff-review-procedure/ planning-complete not-implemented staff review schema draft and reviewer permission policy No staff review queue behavior, approvals, rejections, or staff decision storage exists.
Morning Sheet Visibility Policy Planning /protected-preview/morning-sheet-visibility-policy/ planning-complete not-implemented visibility policy approval and staff review dependency No live Morning Sheet placement, publishing, or public visibility workflow exists.
Retention and Deletion Policy Planning /protected-preview/retention-deletion-policy/ planning-complete not-implemented retention/deletion implementation plan No retention jobs, deletion jobs, archive controls, restore controls, or storage exists.
Audit Logging Policy Planning /protected-preview/audit-logging-policy/ planning-complete not-implemented audit schema draft and audit visibility policy No audit tables, audit events, audit writes, or audit log retention exists.
Live Draft Pilot Readiness Review /protected-preview/live-draft-pilot-readiness/ planning-complete not-implemented protected draft pilot implementation plan Live pilot remains blocked until evidence, policies, schemas, migrations, and staff/privacy approval are complete.

Future Implementation Phases

Phase Purpose Boundary Status
Phase 9.0 - Protected Draft Pilot Implementation Plan Planning package for actual implementation. Still no writes, active migrations, accounts, actor storage, draft collection, staff decisions, or live workflows. planning-only
Phase 9.1 - Actor Reference Schema Migration Draft, Local Only Local-only schema draft for future actor references. No active migration and no runtime actor table. planning-only
Phase 9.2 - Account Role Mapping Schema Migration Draft, Local Only Local-only schema draft for future actor-to-role mappings. No active migration and no live role assignment. planning-only
Phase 9.3 - Draft Storage Schema Migration Draft, Local Only Local-only schema draft for future pull-up/push-up draft storage. No active migration, no draft collection, and no draft writes. planning-only
Phase 9.4 - Staff Review Schema Migration Draft, Local Only Local-only schema draft for future review lanes and review references. No active migration and no staff decision storage. planning-only
Phase 9.5 - Retention/Audit Schema Migration Draft, Local Only Local-only schema draft for future retention markers and minimal audit metadata. No active migration, no retention jobs, no deletion jobs, and no audit writes. planning-only
Phase 9.6 - Protected Read-Only Runtime Boundary Runtime boundary design before any write path exists. Read-only only; no mutations, endpoints, tables, or storage. planning-only
Phase 9.7 - Draft Intake UI Preview With Disabled Controls Preview of draft intake shape with disabled controls. Preview only with no submit, save, collection, or storage. planning-only
Phase 9.8 - Live Draft Pilot Readiness Recheck Go/no-go review before any live write path. No live implementation unless all evidence and approvals are complete. planning-only

These are future phases only. No live implementation starts in Phase 8.11.

Module Dependency Map

Module Required predecessor Status Blocker Safety boundary
Cloudflare Access boundary protected preview boundary planning-reviewed identity policy not approved outer access boundary only; no claim display or storage
pseudonymous actor refs identity policy and actor policy planned-only actor storage not approved opaque refs only; no real identity values
account role mapping pseudonymous actor refs and role-set policy planned-only role mapping storage not approved no live assignment or user admin CRUD
draft schema actor refs, role mapping, draft content policy, retention policy, and audit policy planned-only draft storage not approved no draft collection or sensitive content storage
staff review policy draft schema, reviewer permissions, and audit policy planned-only review storage not approved no approvals, rejections, or staff decision records
Morning Sheet visibility policy staff review policy and visibility policy planned-only public visibility not approved no live placement or publishing
retention/deletion policy draft, review, and visibility policy planned-only retention/deletion jobs not approved no archive, restore, or deletion behavior
audit logging policy all future write paths and minimization policy planned-only audit implementation not approved no audit logs or event writes
protected draft intake read-only runtime boundary and pilot approval blocked write path not approved no live forms, inputs, textareas, submit, or save controls
staff review queue staff review schema and reviewer permission policy blocked staff decision path not approved no live review queue behavior
Morning Sheet placement review approval, visibility policy, retention policy, and privacy approval blocked public placement not approved no live Morning Sheet placement

Data Dependency Map

  • actor refs depend on identity policy and pseudonymous actor policy
  • role mappings depend on actor refs and role-set policy
  • drafts depend on actor refs, role mapping, draft content policy, retention policy, and audit policy
  • staff review depends on drafts, reviewer permissions, staff review procedure, and audit policy
  • Morning Sheet placement depends on staff review and visibility policy
  • retention/deletion depends on draft/review/visibility policy
  • audit logging depends on all write paths but must remain minimal

Route Dependency Map

Route Status Implementation route Storage enabled
/protected-preview/account-workflow-gate-review/ planning-route-existing false false
/protected-preview/access-claim-boundary/ planning-route-existing false false
/protected-preview/actor-reference-schema/ planning-route-existing false false
/protected-preview/account-role-mapping-schema/ planning-route-existing false false
/protected-preview/pullup-pushup-draft-schema/ planning-route-existing false false
/protected-preview/staff-review-procedure/ planning-route-existing false false
/protected-preview/morning-sheet-visibility-policy/ planning-route-existing false false
/protected-preview/retention-deletion-policy/ planning-route-existing false false
/protected-preview/audit-logging-policy/ planning-route-existing false false
/protected-preview/live-draft-pilot-readiness/ planning-route-existing false false
/protected/drafts/ blocked false false
/protected/drafts/new/ blocked false false
/protected/review/ blocked false false
/protected/morning-sheet-candidates/ blocked false false

Proposed implementation routes are blocked and are not created in this phase.

Minimum Safe Pilot Architecture

  • protected access only
  • small approved pilot group
  • pseudonymous actor refs only
  • no real names in app UI
  • no email/name/token/JWT exposure
  • no public Morning Sheet placement at first
  • private draft review only at first
  • staff-reviewed drafts only
  • no AI processing of real drafts
  • short retention window
  • minimal audit metadata
  • manual staff override
  • rollback plan
  • incident escalation path
  • future architecture only
  • not active in Phase 8.11

Prohibited Pilot Architecture

open resident-wide launchlive public Morning Sheet placement on day oneAI review of real draftsautomatic approvalautomatic rejectionautomatic escalationattendance trackingparticipation trackingparticipation analyticsscoring/ranking/compliance metricsresident performance dashboardsexportsstaff surveillance dashboardsclinical claimsidentity exposure in public viewspermanent behavior dossierssearchable gossip archives

Required Evidence Before Implementation

  • Cloudflare Access boundary approved
  • identity policy approved
  • pseudonymous actor policy approved
  • account role mapping policy approved
  • draft content policy approved
  • pull-up safety policy approved
  • push-up recognition policy approved
  • staff review procedure approved
  • reviewer permission policy approved
  • Morning Sheet visibility policy approved
  • retention policy approved
  • deletion policy approved
  • audit policy approved
  • audit visibility policy approved
  • escalation policy approved
  • AI-use policy resolved
  • D1 schema reviewed
  • migration plan approved
  • rollback plan approved
  • staff/privacy approval complete
  • small pilot group approved
  • support/incident procedure defined

Recommended Next Phase

Phase 9.0 - Protected Draft Pilot Implementation Plan, Planning Only

The next safe step is an implementation plan that still keeps live draft collection, accounts, actor storage, staff decisions, write endpoints, active migrations, tracking, analytics, and scoring blocked.

Boundaries: planning only; no live draft collection; no accounts; no identity capture; no actor storage; no role assignment; no staff decisions; no Morning Sheet placement; no database writes; no active migrations; no tracking; no analytics; no scoring.

Blocked capabilities remain: live draft collection; live submissions; account storage; actor storage; identity capture; identity storage; role assignment; staff decisions; Morning Sheet placement; retention/deletion jobs; audit logging writes; database writes; active migrations; D1 account/user/actor/submission/draft/review/morning-sheet/audit tables; live user admin; live role admin CRUD; live workflow admin CRUD; attendance tracking; participation tracking; participation analytics; scoring/ranking/compliance metrics; OpenAI processing of real submissions; clinical claims; sensitive storage.

recommended-next