The Sixth Sense at 6th Street
Live Workflow Readiness Matrix
Purpose
This page summarizes what the protected preview stack has already modeled, what remains synthetic only, and what must be approved before any live pull-up, push-up, account, staff review, storage, or Morning Sheet workflow is built.
It is planning-only. No launch control exists here.
Current Protected Preview Stack
Protected Access SandboxPull-Up / Push-Up Workflow PreviewAccount Setup PreviewAccount Workflow Gate ReviewAccess Claim Boundary ReviewPseudonymous Actor ModelActor Reference SchemaAccount Role Mapping SchemaPull-Up / Push-Up Draft SchemaStaff Review ProcedureMorning Sheet Visibility PolicyRetention and Deletion PolicyAudit Logging PolicyLive Draft Pilot ReadinessDraft Pilot Architecture PackageSynthetic Draft PreviewStaff Review Queue PreviewEnd-to-End Workflow PreviewData Schema Design PreviewStaff Privacy ReviewStaff Demo WalkthroughAdmin Configuration FoundationRole Set Admin PreviewWorkflow Set Admin PreviewUser Admin PreviewAdmin CRUD Readiness
Readiness Matrix
| Category | Status | Evidence | Live-launch requirement | Safety note |
|---|---|---|---|---|
| Access control Cloudflare Access is already configured around the protected preview path family, including this readiness route. | complete-preview | /protected-preview/ | Confirm final Cloudflare Access policy, allowed groups, and protected destinations before any live workflow exists. | Access preview does not create app accounts, store identities, or grant app-level roles. |
| Account roles Future resident, peer-leader, staff-reviewer, and program-admin roles are described as planning records only. | synthetic-only | /protected-preview/account-setup/ | Approve role mapping policy and design an app-level account model before live permissions exist. | No app accounts, resident profiles, identity storage, attendance tracking, or participation tracking exist. |
| Submission policy Deterministic pull-up and push-up safety rules are modeled with synthetic examples and preview-only policy results. | complete-preview | /protected-preview/pullup-pushup-workflow/ | Staff and privacy reviewers must approve the final policy before any resident-facing workflow is enabled. | Policy preview does not collect, score, rank, discipline, or store community content. |
| Draft preview Static draft cards show how future guidance could look after account setup exists. | synthetic-only | /protected-preview/pullup-pushup-draft-preview/ | Live draft collection remains blocked until account roles, privacy rules, retention, and review policy are approved. | No forms, inputs, textareas, saves, submissions, or database writes exist. |
| Staff review Static queue cards show preview-only review states without creating real staff decisions. | synthetic-only | /protected-preview/staff-review-queue/ | Define staff reviewer permissions, review workflow, rejected-submission handling, and audit requirements. | No approve, reject, save, delete, or staff-decision action exists. |
| Morning Sheet placement The end-to-end preview shows one synthetic approved item as a possible future Morning Sheet placement. | synthetic-only | /protected-preview/end-to-end-workflow/ | Approve public-display rules and staff review boundaries before any real Morning Sheet placement can happen. | No real Morning Sheet placement is created. |
| Data storage No active submission, review, account, or profile tables exist for live pull-up or push-up workflows. | requires-technical-design | docs/architecture/submission-privacy-and-access-control.md | Design D1 schema for submissions and review events before implementation, then review it for privacy and retention risk. | No D1 submission writes or review writes are enabled. |
| Retention policy Retention and deletion windows are documented as future decisions, not active app behavior. | requires-staff-decision | docs/architecture/synthetic-end-to-end-workflow.md | Decide retention, deletion, archive, rejected-content handling, and resident visibility windows. | No archive timer, deletion workflow, export workflow, or retained submission record exists. |
| Audit logging Future audit logging is required before live staff review, but no audit table or event writer exists. | requires-technical-design | docs/architecture/pullup-pushup-workflow.md | Design audit events for draft creation, review, revision, display, archive, deletion, and export before launch. | No audit log writes or staff action records are produced. |
| Privacy approval Privacy approval is still required for account identity, resident visibility, staff access, retention, and exports. | requires-privacy-approval | docs/architecture/submission-privacy-and-access-control.md | Privacy owner must approve identity storage, content retention, access boundaries, export policy, and rollback plan. | No identity values, resident profiles, private content, or sensitive community records are stored. |
| Pilot readiness A live pilot is not ready because accounts, schema, review policy, retention, audit logging, and privacy approval are not complete. | blocked | docs/handoff/future-roadmap.md | Define a small pilot group, staff reviewer coverage, rollback plan, and go/no-go checklist after all privacy and technical gates pass. | No pilot collection, resident enrollment, attendance tracking, participation tracking, or compliance metric exists. |
What Is Complete
Access control
Cloudflare Access is already configured around the protected preview path family, including this readiness route.
complete-previewSubmission policy
Deterministic pull-up and push-up safety rules are modeled with synthetic examples and preview-only policy results.
complete-previewWhat Is Synthetic Only
- Account roles: Future resident, peer-leader, staff-reviewer, and program-admin roles are described as planning records only.
- Draft preview: Static draft cards show how future guidance could look after account setup exists.
- Staff review: Static queue cards show preview-only review states without creating real staff decisions.
- Morning Sheet placement: The end-to-end preview shows one synthetic approved item as a possible future Morning Sheet placement.
What Remains Blocked
- Data storage: Design D1 schema for submissions and review events before implementation, then review it for privacy and retention risk.
- Retention policy: Decide retention, deletion, archive, rejected-content handling, and resident visibility windows.
- Audit logging: Design audit events for draft creation, review, revision, display, archive, deletion, and export before launch.
- Privacy approval: Privacy owner must approve identity storage, content retention, access boundaries, export policy, and rollback plan.
- Pilot readiness: Define a small pilot group, staff reviewer coverage, rollback plan, and go/no-go checklist after all privacy and technical gates pass.
Required Live-Launch Prerequisites
| Prerequisite | Status |
|---|---|
| Cloudflare Access policy confirmed | requires-staff-decision |
| Role mapping approved | requires-staff-decision |
| App-level account model designed | requires-technical-design |
| Resident identity storage decision | requires-privacy-approval |
| Staff reviewer permissions | requires-staff-decision |
| D1 schema for submissions | requires-technical-design |
| D1 schema for review events | requires-technical-design |
| Retention policy | requires-staff-decision |
| Deletion policy | requires-staff-decision |
| Audit logging | requires-technical-design |
| Export policy | requires-privacy-approval |
| Rejected submission handling | requires-staff-decision |
| Resident visibility rules | requires-privacy-approval |
| Staff approval workflow | requires-staff-decision |
| Privacy approval | requires-privacy-approval |
| Small pilot plan | blocked |
| Rollback plan | blocked |
Required staff/privacy decisions
- who may submit future pull-ups and push-ups
- who may review future drafts
- what content must never be collected
- what rejected drafts mean operationally
- whether residents may see their own history
- whether any export is allowed
- what retention and deletion windows apply
Required technical decisions
- account model and role mapping
- D1 submission schema
- D1 review-event schema
- audit event schema
- rollback and disable-switch plan
- source of truth for staff permissions
Required retention/audit decisions
- retention window for drafts
- retention window for approved display text
- deletion process for blocked drafts
- audit events for review actions
- export restrictions
- privacy review before pilot
Recommended Next Phase
Phase 5.7 — Staff Privacy Review Checklist, Planning Only
Review staff, privacy, retention, audit, visibility, export, AI-use, and no-tracking decisions before any live schema, migration, account, submission, or storage work begins.
- no live approvals yet
- no writes enabled yet
- no live forms created yet