Morning Sheet Visibility Policy Planning
Purpose
This page defines the future policy that would determine whether a reviewed pull-up or push-up draft may become visible on the Morning Sheet.
It is planning-only. It creates no placements, approvals, rejections, publication controls, staff decisions, drafts, submissions, write endpoints, database writes, tables, migrations, or stored community content.
Current Draft/Review/Morning Sheet Boundary
Product
Renata
The Sixth Sense at 6th StreetLive placement
false
not implementedStaff decisions
false
not implementedDatabase writes
false
not implementedMorning Sheet visibility policy is planning-only; no drafts, submissions, review decisions, staff approvals, rejections, Morning Sheet placements, tables, migrations, or writes exist.
Why Visibility Policy Comes After Staff Review Procedure
Future Morning Sheet visibility depends on staff review boundaries first. A reviewed draft should never become public unless the visibility policy, privacy boundary, retention and deletion policy, audit policy, and consent/identity decisions are resolved.
No live placement, approvals, rejections, publish controls, draft collection, staff decisions, database writes, active migrations, or executable SQL files are added.
Visibility Principles
- Morning Sheet visibility is not automatic.
- Staff review is required before any future public visibility.
- Pull-ups must be framed around repair, accountability, specificity, and safety.
- Push-ups must be framed around recognition and sincerity, not popularity or ranking.
- No draft should become public if it shames, retaliates, coerces, exposes private information, or identifies sensitive details.
- Morning Sheet content must not become attendance tracking, participation tracking, scoring, ranking, discipline, compliance, or resident performance analytics.
- Private feedback may be appropriate even when public visibility is blocked.
- Public visibility must require staff/privacy policy, retention policy, and consent/identity boundary decisions.
Planned Visibility Outcomes
| Outcome | Purpose | Status | Active | Behavior |
|---|---|---|---|---|
not-reviewed | Default future state before staff review. | planning-only | false | does not trigger behavior |
private-feedback-only | May be discussed privately but not placed publicly. | planning-only | false | does not trigger placement |
revision-required | Draft needs safer language or clearer accountability/recognition. | planning-only | false | does not trigger behavior |
blocked-from-public-view | Draft cannot appear on Morning Sheet due to safety/privacy concerns. | planning-only | false | does not trigger placement |
eligible-for-morning-sheet-consideration | May be considered for placement only after staff review and required gates. | planning-only | false | does not trigger placement |
held-for-staff-policy | Unclear case requiring staff policy decision. | planning-only | false | does not trigger behavior |
deleted-under-retention-policy | Future deletion state under approved retention/deletion policy. | planning-only | false | does not trigger behavior |
Eligibility Rules
- staff review procedure is active and approved
- draft type is allowed
- author actor ref is valid under approved actor policy
- subject actor ref is valid or intentionally absent
- no real identity values are present
- no sensitive personal details are present
- no threats, retaliation, coercion, harassment, or shaming are present
- no clinical, legal, trauma, medical, medication, or diagnosis details are exposed
- pull-up is specific, repair-oriented, and non-punitive
- push-up is sincere, bounded, and non-ranking
- retention and deletion policy is approved
- audit policy is approved
- Morning Sheet visibility policy is approved
- privacy approval is complete
Private-Only Rules
- they involve sensitive relationship content
- they risk embarrassment or humiliation
- they require staff conversation before public sharing
- they are too vague for public use
- they contain conflict that is better handled directly
- they include details that could identify someone indirectly
- they are constructive but not appropriate for the full room
Blocked Public Content
Redaction Rules
- never expose real names
- never expose emails
- never expose initials
- never expose Cloudflare claims
- never expose room numbers
- never expose case/legal/medical identifiers
- never expose profile details
- never convert private content into public content without approved policy
- preserve meaning only when safe
- block rather than over-redact if context becomes misleading or unsafe
Pull-Up and Push-Up Visibility Differences
Pull-up visibility rules
- must focus on behavior, repair, and accountability
- must avoid character attacks
- must avoid public humiliation
- must avoid accusations that require staff/private handling
- must not function as discipline
Push-up visibility rules
- must focus on recognition, effort, contribution, or repair
- must avoid popularity contests
- must avoid ranking residents
- must avoid manipulative praise
- must avoid coded relationship content
- must not become participation scoring
Staff Review Dependency
- staff review procedure must be approved before public visibility exists
- review lanes must remain planning-only until live review is explicitly approved
- Morning Sheet visibility must not create automatic approval or automatic rejection
- staff review metadata must not become staff decisions in this phase
- no reviewed draft is moved, published, or stored in this phase
Consent and Privacy Boundaries
- public visibility requires staff/privacy policy approval
- identity and consent boundaries must be decided before any public reading
- content that identifies a resident directly or indirectly remains blocked without approved policy and consent boundary
- private feedback may not be converted into public visibility without approved policy
- Cloudflare Access email, name, group, token, JWT, headers, and raw claims must never be displayed or stored
Audit Requirements
- audit policy must exist before Morning Sheet visibility workflow exists
- audit metadata must use pseudonymous actor refs only after actor storage is approved
- audit metadata must distinguish private-only, revision, public-view block, staff-policy hold, eligibility, archive, and deletion outcomes
- audit metadata must not store email, name, Cloudflare claims, JWT, token, group, resident profile, staff profile, or sensitive content fields
- audit metadata must not become attendance tracking, participation analytics, scoring, compliance reporting, or staff surveillance
Retention And Deletion Considerations
- Morning Sheet visibility requires retention rules before public use
- private-only outcomes require deletion rules before draft collection
- blocked-from-public-view outcomes must not become permanent behavior files
- deleted-under-retention-policy must not preserve sensitive content in a visible workflow
- visibility metadata must have deletion and audit boundaries before writes exist
Required Gates Before Public Visibility
- Cloudflare Access boundary approved
- identity policy approved
- pseudonymous actor policy approved
- account role mapping policy approved
- draft content policy approved
- pull-up safety policy approved
- push-up recognition policy approved
- staff review procedure approved
- reviewer permission policy approved
- Morning Sheet visibility policy approved
- consent and identity boundary approved
- retention policy approved
- deletion policy approved
- audit policy approved
- escalation policy approved
- AI-use policy resolved
- D1 schema reviewed
- privacy approval complete
- rollback plan approved
- small pilot approved
What Remains Blocked
- live Morning Sheet placement
- approve buttons
- reject buttons
- publish buttons
- save buttons
- edit controls
- staff decision records
- live staff review behavior
- live pull-up forms
- live push-up forms
- input fields
- textareas
- submit/save controls
- draft creation
- draft editing
- draft deletion
- draft collection
- draft storage
- live submissions
- submission collection
- staff approval/rejection
- staff decisions
- Morning Sheet public placement
- app-level login
- account creation
- password fields
- email capture
- real user names
- real resident names
- real staff names
- real emails
- Cloudflare Access email display
- Cloudflare Access name display
- Cloudflare Access group display
- Cloudflare Access JWT display
- Cloudflare Access token display
- Cloudflare Access header display
- Cloudflare Access claim storage
- actor records
- actor storage
- account records
- account storage
- identity mapping
- role assignment
- live role assignment
- resident profiles
- staff profiles
- user admin CRUD
- database writes
- write endpoints
- active migrations
- executable SQL files
- D1 account/user/actor/submission/draft/review/morning-sheet tables
- attendance tracking
- participation tracking
- participation analytics
- scoring, ranking, discipline points, or compliance metrics
- billing, lead capture, CRM, Stripe, or sales forms
- AI for real submissions
- sensitive community content storage
Recommended Next Phase
Phase 8.8 - Retention and Deletion Policy Planning
After Morning Sheet visibility boundaries are planned, the next safe step is planning retention and deletion policy before any draft or visibility storage exists.
Boundaries: no live placement in Phase 8.7; no draft collection; no live submissions; no staff approvals; no rejections; no publish controls; no staff decisions; no database writes; no active migrations; no tracking; no analytics; no scoring.
recommended-next