Protected Draft Pilot Architecture Package
Purpose
This architecture package turns the Phase 8 planning stack into an implementation-oriented map for a possible future protected pull-up/push-up draft pilot.
It is a planning package only. It creates no drafts, accounts, actor records, staff decisions, write endpoints, tables, SQL migrations, retention jobs, audit logs, or live workflows.
Current No-Go Status
Package status
planning-only
Implementation readiness
not-ready-for-live-implementation
Go / no-go
no-go
Prior planning layers are planning-complete, but no approved identity policy, actor storage, role mapping storage, draft storage, staff review storage, retention/deletion implementation, audit logging implementation, D1 schema, active migrations, write endpoints, or staff/privacy approval exists.
The prior planning stack is consolidated for architecture review only. Live draft collection, account storage, actor storage, staff decisions, Morning Sheet placement, writes, migrations, tracking, analytics, and scoring remain inactive.
Planning Stack Map
| Layer | Route | Planning | Implementation | Next dependency | Remaining blocker |
|---|---|---|---|---|---|
| Cloudflare Access Claim Boundary Review | /protected-preview/access-claim-boundary/ | planning-complete | not-implemented | identity policy approval | Access claims are not exposed, stored, logged, or mapped to roles. |
| Actor Reference Schema Planning | /protected-preview/actor-reference-schema/ | planning-complete | not-implemented | actor storage policy and local-only migration draft | No actor records, identity mapping, or active table exists. |
| Account Role Mapping Schema Planning | /protected-preview/account-role-mapping-schema/ | planning-complete | not-implemented | role mapping policy and local-only migration draft | No live role assignment, account record, or role mapping storage exists. |
| Pull-Up / Push-Up Draft Schema Planning | /protected-preview/pullup-pushup-draft-schema/ | planning-complete | not-implemented | draft content policy and local-only draft storage schema | No draft collection, draft storage, submission intake, or content write path exists. |
| Staff Review Procedure Planning | /protected-preview/staff-review-procedure/ | planning-complete | not-implemented | staff review schema draft and reviewer permission policy | No staff review queue behavior, approvals, rejections, or staff decision storage exists. |
| Morning Sheet Visibility Policy Planning | /protected-preview/morning-sheet-visibility-policy/ | planning-complete | not-implemented | visibility policy approval and staff review dependency | No live Morning Sheet placement, publishing, or public visibility workflow exists. |
| Retention and Deletion Policy Planning | /protected-preview/retention-deletion-policy/ | planning-complete | not-implemented | retention/deletion implementation plan | No retention jobs, deletion jobs, archive controls, restore controls, or storage exists. |
| Audit Logging Policy Planning | /protected-preview/audit-logging-policy/ | planning-complete | not-implemented | audit schema draft and audit visibility policy | No audit tables, audit events, audit writes, or audit log retention exists. |
| Live Draft Pilot Readiness Review | /protected-preview/live-draft-pilot-readiness/ | planning-complete | not-implemented | protected draft pilot implementation plan | Live pilot remains blocked until evidence, policies, schemas, migrations, and staff/privacy approval are complete. |
Future Implementation Phases
| Phase | Purpose | Boundary | Status |
|---|---|---|---|
| Phase 9.0 - Protected Draft Pilot Implementation Plan | Planning package for actual implementation. | Still no writes, active migrations, accounts, actor storage, draft collection, staff decisions, or live workflows. | planning-only |
| Phase 9.1 - Actor Reference Schema Migration Draft, Local Only | Local-only schema draft for future actor references. | No active migration and no runtime actor table. | planning-only |
| Phase 9.2 - Account Role Mapping Schema Migration Draft, Local Only | Local-only schema draft for future actor-to-role mappings. | No active migration and no live role assignment. | planning-only |
| Phase 9.3 - Draft Storage Schema Migration Draft, Local Only | Local-only schema draft for future pull-up/push-up draft storage. | No active migration, no draft collection, and no draft writes. | planning-only |
| Phase 9.4 - Staff Review Schema Migration Draft, Local Only | Local-only schema draft for future review lanes and review references. | No active migration and no staff decision storage. | planning-only |
| Phase 9.5 - Retention/Audit Schema Migration Draft, Local Only | Local-only schema draft for future retention markers and minimal audit metadata. | No active migration, no retention jobs, no deletion jobs, and no audit writes. | planning-only |
| Phase 9.6 - Protected Read-Only Runtime Boundary | Runtime boundary design before any write path exists. | Read-only only; no mutations, endpoints, tables, or storage. | planning-only |
| Phase 9.7 - Draft Intake UI Preview With Disabled Controls | Preview of draft intake shape with disabled controls. | Preview only with no submit, save, collection, or storage. | planning-only |
| Phase 9.8 - Live Draft Pilot Readiness Recheck | Go/no-go review before any live write path. | No live implementation unless all evidence and approvals are complete. | planning-only |
These are future phases only. No live implementation starts in Phase 8.11.
Module Dependency Map
| Module | Required predecessor | Status | Blocker | Safety boundary |
|---|---|---|---|---|
| Cloudflare Access boundary | protected preview boundary | planning-reviewed | identity policy not approved | outer access boundary only; no claim display or storage |
| pseudonymous actor refs | identity policy and actor policy | planned-only | actor storage not approved | opaque refs only; no real identity values |
| account role mapping | pseudonymous actor refs and role-set policy | planned-only | role mapping storage not approved | no live assignment or user admin CRUD |
| draft schema | actor refs, role mapping, draft content policy, retention policy, and audit policy | planned-only | draft storage not approved | no draft collection or sensitive content storage |
| staff review policy | draft schema, reviewer permissions, and audit policy | planned-only | review storage not approved | no approvals, rejections, or staff decision records |
| Morning Sheet visibility policy | staff review policy and visibility policy | planned-only | public visibility not approved | no live placement or publishing |
| retention/deletion policy | draft, review, and visibility policy | planned-only | retention/deletion jobs not approved | no archive, restore, or deletion behavior |
| audit logging policy | all future write paths and minimization policy | planned-only | audit implementation not approved | no audit logs or event writes |
| protected draft intake | read-only runtime boundary and pilot approval | blocked | write path not approved | no live forms, inputs, textareas, submit, or save controls |
| staff review queue | staff review schema and reviewer permission policy | blocked | staff decision path not approved | no live review queue behavior |
| Morning Sheet placement | review approval, visibility policy, retention policy, and privacy approval | blocked | public placement not approved | no live Morning Sheet placement |
Data Dependency Map
- actor refs depend on identity policy and pseudonymous actor policy
- role mappings depend on actor refs and role-set policy
- drafts depend on actor refs, role mapping, draft content policy, retention policy, and audit policy
- staff review depends on drafts, reviewer permissions, staff review procedure, and audit policy
- Morning Sheet placement depends on staff review and visibility policy
- retention/deletion depends on draft/review/visibility policy
- audit logging depends on all write paths but must remain minimal
Route Dependency Map
| Route | Status | Implementation route | Storage enabled |
|---|---|---|---|
/protected-preview/account-workflow-gate-review/ | planning-route-existing | false | false |
/protected-preview/access-claim-boundary/ | planning-route-existing | false | false |
/protected-preview/actor-reference-schema/ | planning-route-existing | false | false |
/protected-preview/account-role-mapping-schema/ | planning-route-existing | false | false |
/protected-preview/pullup-pushup-draft-schema/ | planning-route-existing | false | false |
/protected-preview/staff-review-procedure/ | planning-route-existing | false | false |
/protected-preview/morning-sheet-visibility-policy/ | planning-route-existing | false | false |
/protected-preview/retention-deletion-policy/ | planning-route-existing | false | false |
/protected-preview/audit-logging-policy/ | planning-route-existing | false | false |
/protected-preview/live-draft-pilot-readiness/ | planning-route-existing | false | false |
/protected/drafts/ | blocked | false | false |
/protected/drafts/new/ | blocked | false | false |
/protected/review/ | blocked | false | false |
/protected/morning-sheet-candidates/ | blocked | false | false |
Proposed implementation routes are blocked and are not created in this phase.
Minimum Safe Pilot Architecture
- protected access only
- small approved pilot group
- pseudonymous actor refs only
- no real names in app UI
- no email/name/token/JWT exposure
- no public Morning Sheet placement at first
- private draft review only at first
- staff-reviewed drafts only
- no AI processing of real drafts
- short retention window
- minimal audit metadata
- manual staff override
- rollback plan
- incident escalation path
- future architecture only
- not active in Phase 8.11
Prohibited Pilot Architecture
Required Evidence Before Implementation
- Cloudflare Access boundary approved
- identity policy approved
- pseudonymous actor policy approved
- account role mapping policy approved
- draft content policy approved
- pull-up safety policy approved
- push-up recognition policy approved
- staff review procedure approved
- reviewer permission policy approved
- Morning Sheet visibility policy approved
- retention policy approved
- deletion policy approved
- audit policy approved
- audit visibility policy approved
- escalation policy approved
- AI-use policy resolved
- D1 schema reviewed
- migration plan approved
- rollback plan approved
- staff/privacy approval complete
- small pilot group approved
- support/incident procedure defined
Recommended Next Phase
Phase 9.0 - Protected Draft Pilot Implementation Plan, Planning Only
The next safe step is an implementation plan that still keeps live draft collection, accounts, actor storage, staff decisions, write endpoints, active migrations, tracking, analytics, and scoring blocked.
Boundaries: planning only; no live draft collection; no accounts; no identity capture; no actor storage; no role assignment; no staff decisions; no Morning Sheet placement; no database writes; no active migrations; no tracking; no analytics; no scoring.
Blocked capabilities remain: live draft collection; live submissions; account storage; actor storage; identity capture; identity storage; role assignment; staff decisions; Morning Sheet placement; retention/deletion jobs; audit logging writes; database writes; active migrations; D1 account/user/actor/submission/draft/review/morning-sheet/audit tables; live user admin; live role admin CRUD; live workflow admin CRUD; attendance tracking; participation tracking; participation analytics; scoring/ranking/compliance metrics; OpenAI processing of real submissions; clinical claims; sensitive storage.
recommended-next