The Sixth Sense at 6th Street

Live Workflow Readiness Matrix

Protected planning-only matrix for the future pull-up and push-up workflow stack.

This is a protected, read-only readiness review. It does not create accounts, collect submissions, store resident data, create staff decisions, or mutate community content.

Purpose

This page summarizes what the protected preview stack has already modeled, what remains synthetic only, and what must be approved before any live pull-up, push-up, account, staff review, storage, or Morning Sheet workflow is built.

It is planning-only. No launch control exists here.

Current Protected Preview Stack

Readiness Matrix

Category Status Evidence Live-launch requirement Safety note
Access control
Cloudflare Access is already configured around the protected preview path family, including this readiness route.
complete-preview /protected-preview/ Confirm final Cloudflare Access policy, allowed groups, and protected destinations before any live workflow exists. Access preview does not create app accounts, store identities, or grant app-level roles.
Account roles
Future resident, peer-leader, staff-reviewer, and program-admin roles are described as planning records only.
synthetic-only /protected-preview/account-setup/ Approve role mapping policy and design an app-level account model before live permissions exist. No app accounts, resident profiles, identity storage, attendance tracking, or participation tracking exist.
Submission policy
Deterministic pull-up and push-up safety rules are modeled with synthetic examples and preview-only policy results.
complete-preview /protected-preview/pullup-pushup-workflow/ Staff and privacy reviewers must approve the final policy before any resident-facing workflow is enabled. Policy preview does not collect, score, rank, discipline, or store community content.
Draft preview
Static draft cards show how future guidance could look after account setup exists.
synthetic-only /protected-preview/pullup-pushup-draft-preview/ Live draft collection remains blocked until account roles, privacy rules, retention, and review policy are approved. No forms, inputs, textareas, saves, submissions, or database writes exist.
Staff review
Static queue cards show preview-only review states without creating real staff decisions.
synthetic-only /protected-preview/staff-review-queue/ Define staff reviewer permissions, review workflow, rejected-submission handling, and audit requirements. No approve, reject, save, delete, or staff-decision action exists.
Morning Sheet placement
The end-to-end preview shows one synthetic approved item as a possible future Morning Sheet placement.
synthetic-only /protected-preview/end-to-end-workflow/ Approve public-display rules and staff review boundaries before any real Morning Sheet placement can happen. No real Morning Sheet placement is created.
Data storage
No active submission, review, account, or profile tables exist for live pull-up or push-up workflows.
requires-technical-design docs/architecture/submission-privacy-and-access-control.md Design D1 schema for submissions and review events before implementation, then review it for privacy and retention risk. No D1 submission writes or review writes are enabled.
Retention policy
Retention and deletion windows are documented as future decisions, not active app behavior.
requires-staff-decision docs/architecture/synthetic-end-to-end-workflow.md Decide retention, deletion, archive, rejected-content handling, and resident visibility windows. No archive timer, deletion workflow, export workflow, or retained submission record exists.
Audit logging
Future audit logging is required before live staff review, but no audit table or event writer exists.
requires-technical-design docs/architecture/pullup-pushup-workflow.md Design audit events for draft creation, review, revision, display, archive, deletion, and export before launch. No audit log writes or staff action records are produced.
Privacy approval
Privacy approval is still required for account identity, resident visibility, staff access, retention, and exports.
requires-privacy-approval docs/architecture/submission-privacy-and-access-control.md Privacy owner must approve identity storage, content retention, access boundaries, export policy, and rollback plan. No identity values, resident profiles, private content, or sensitive community records are stored.
Pilot readiness
A live pilot is not ready because accounts, schema, review policy, retention, audit logging, and privacy approval are not complete.
blocked docs/handoff/future-roadmap.md Define a small pilot group, staff reviewer coverage, rollback plan, and go/no-go checklist after all privacy and technical gates pass. No pilot collection, resident enrollment, attendance tracking, participation tracking, or compliance metric exists.

What Is Complete

Access control

Cloudflare Access is already configured around the protected preview path family, including this readiness route.

complete-preview

Submission policy

Deterministic pull-up and push-up safety rules are modeled with synthetic examples and preview-only policy results.

complete-preview

What Is Synthetic Only

  • Account roles: Future resident, peer-leader, staff-reviewer, and program-admin roles are described as planning records only.
  • Draft preview: Static draft cards show how future guidance could look after account setup exists.
  • Staff review: Static queue cards show preview-only review states without creating real staff decisions.
  • Morning Sheet placement: The end-to-end preview shows one synthetic approved item as a possible future Morning Sheet placement.

What Remains Blocked

  • Data storage: Design D1 schema for submissions and review events before implementation, then review it for privacy and retention risk.
  • Retention policy: Decide retention, deletion, archive, rejected-content handling, and resident visibility windows.
  • Audit logging: Design audit events for draft creation, review, revision, display, archive, deletion, and export before launch.
  • Privacy approval: Privacy owner must approve identity storage, content retention, access boundaries, export policy, and rollback plan.
  • Pilot readiness: Define a small pilot group, staff reviewer coverage, rollback plan, and go/no-go checklist after all privacy and technical gates pass.

Required Live-Launch Prerequisites

Prerequisite Status
Cloudflare Access policy confirmed requires-staff-decision
Role mapping approved requires-staff-decision
App-level account model designed requires-technical-design
Resident identity storage decision requires-privacy-approval
Staff reviewer permissions requires-staff-decision
D1 schema for submissions requires-technical-design
D1 schema for review events requires-technical-design
Retention policy requires-staff-decision
Deletion policy requires-staff-decision
Audit logging requires-technical-design
Export policy requires-privacy-approval
Rejected submission handling requires-staff-decision
Resident visibility rules requires-privacy-approval
Staff approval workflow requires-staff-decision
Privacy approval requires-privacy-approval
Small pilot plan blocked
Rollback plan blocked

Required staff/privacy decisions

  • who may submit future pull-ups and push-ups
  • who may review future drafts
  • what content must never be collected
  • what rejected drafts mean operationally
  • whether residents may see their own history
  • whether any export is allowed
  • what retention and deletion windows apply

Required technical decisions

  • account model and role mapping
  • D1 submission schema
  • D1 review-event schema
  • audit event schema
  • rollback and disable-switch plan
  • source of truth for staff permissions

Required retention/audit decisions

  • retention window for drafts
  • retention window for approved display text
  • deletion process for blocked drafts
  • audit events for review actions
  • export restrictions
  • privacy review before pilot

Recommended Next Phase

Phase 5.7 — Staff Privacy Review Checklist, Planning Only

Review staff, privacy, retention, audit, visibility, export, AI-use, and no-tracking decisions before any live schema, migration, account, submission, or storage work begins.

  • no live approvals yet
  • no writes enabled yet
  • no live forms created yet
planning-only