Renata protected planning

User Admin Preview

Protected, read-only preview of future user roster boundaries, role mapping labels, identity rules, and launch blockers.

This is a protected, read-only user-admin preview. It does not create users, collect identities, assign real roles, store profiles, or mutate configuration.

Purpose

This preview shows how Renata may eventually describe people, communities, role labels, and visibility boundaries before any user admin CRUD, role assignment, identity capture, account creation, or configuration write exists.

It is not live user management. It is static planning metadata for staff/privacy review.

What User Admin Will Eventually Manage

User invitation policy

No invitations, account creation, or contact collection exist.

blocked-before-live

Role assignment

No real role assignment exists before identity policy approval.

blocked-before-live

Community membership

No membership records or customer roster exist.

blocked-before-live

Staff reviewer designation

No staff reviewer permissions or staff decisions exist.

blocked-before-live

Peer-leader designation

No peer-leader assignment can trigger workflow behavior.

blocked-before-live

Account disabling

No account exists to disable.

blocked-before-live

Pseudonymous display labels

Display-label policy requires privacy approval.

planning-only

Access visibility boundaries

Visibility rules require role, retention, and privacy approval.

planning-only

Synthetic User Roster

Resident A

ID
synthetic-resident-a
Role label
resident
State
not-created
Status
preview-only

6th Street field-lab planning example

Synthetic placeholder only. No account, identity record, resident profile, or history exists.

Resident B

ID
synthetic-resident-b
Role label
resident
State
role-mapping-planning
Status
preview-only

6th Street field-lab planning example

Synthetic placeholder only. No account, identity record, resident profile, or history exists.

Peer Leader

ID
synthetic-peer-leader
Role label
peer-leader
State
privacy-review-required
Status
preview-only

6th Street field-lab planning example

Synthetic placeholder only. Peer leadership cannot grant staff approval or public placement.

Staff Reviewer

ID
synthetic-staff-reviewer
Role label
staff-reviewer
State
pilot-ready
Status
preview-only

6th Street field-lab planning example

Synthetic placeholder only. No staff reviewer account, staff profile, or review authority exists.

Program Admin

ID
synthetic-program-admin
Role label
program-admin
State
invitation-planning
Status
preview-only

6th Street field-lab planning example

Synthetic placeholder only. No admin account, configuration write access, or live permission exists.

All examples are synthetic labels. No person, account, identity value, profile, or history is created.

Future Role Assignments

Synthetic label Role Planning state Preview behavior
Resident A Resident
resident
role-mapping-planning Preview-only assignment label. It does not grant access or workflow permission.
Resident B Resident
resident
role-mapping-planning Preview-only assignment label. It does not grant access or workflow permission.
Peer Leader Peer Leader
peer-leader
staff-review-required Preview-only assignment label. It cannot finalize staff review or Morning Sheet placement.
Staff Reviewer Staff Reviewer
staff-reviewer
staff-review-required Preview-only assignment label. It cannot create staff decisions in this phase.
Program Admin Program Admin
program-admin
privacy-review-required Preview-only assignment label. It cannot change configuration or manage users.

These are labels only. No assignment grants access, permissions, workflow action, or staff authority.

Future Permission Visibility

Resident

resident

Future participant role for approved community workflows after identity and privacy policy approval.

Peer Leader

peer-leader

Future peer support role that may help identify drafts but cannot approve public reading.

Staff Reviewer

staff-reviewer

Future protected review role for staff-approved workflow checks after role policy approval.

Program Admin

program-admin

Future configuration role for approved staff operators after account, audit, and privacy gates.

Permission visibility is planning-only. It does not create accounts, role assignment, review authority, or workflow access.

Future Identity Boundaries

  • Cloudflare Access is the outer gate.
  • App-level user accounts are not implemented.
  • No identity values are stored.
  • No resident profiles exist.
  • No staff profiles exist.
  • No email addresses are stored.
  • No resident history view exists.
  • No attendance tracking exists.
  • No participation tracking exists.
  • No participation analytics exists.
  • No scoring/ranking/compliance metrics exist.

What User Admin Must Never Track

no attendance tracking no participation tracking no participation analytics no scoring/ranking/compliance metrics no resident performance dashboards no discipline points

What Remains Blocked

no live user CRUDno role assignmentno account creationno identity storageno resident profilesno live submissionsno attendance trackingno participation trackingno participation analyticsno scoring/ranking/compliance metricsno configuration writesno active migrations

Safety And Privacy Boundaries

Blocked capability Status Reason
Live user CRUD
live_user_crud
blocked-before-live Requires account model, identity policy, privacy approval, retention rules, and audit design.
Role assignment
role_assignment
blocked-before-live No real role assignment can exist before identity policy approval.
Account creation
account_creation
blocked-before-live No app-level account model is approved or implemented.
Identity storage
identity_storage
blocked-before-live No identity values, contact values, or Access header values are stored.
Resident profiles
resident_profiles
blocked-before-live Resident profile creation requires privacy approval and retention policy.
Staff profiles
staff_profiles
blocked-before-live Staff profile creation requires role policy, access policy, and privacy approval.
Live submissions
live_submissions
blocked-before-live No live workflow or submission collection exists.
Record exports
exports
blocked-before-live Exports require staff/privacy approval and data-minimization policy.

Future User States

User state Status Preview behavior
Not Created
not-created
preview-only No account or user record exists.
Invitation Planning
invitation-planning
preview-only Future invitation policy label only; no invitation can be sent.
Role Mapping Planning
role-mapping-planning
preview-only Future role mapping label only; no role assignment can trigger behavior.
Privacy Review Required
privacy-review-required
preview-only Future privacy gate label only.
Pilot Ready
pilot-ready
preview-only Future state label only; no user may be active in this phase.
Disabled Preview
disabled-preview
preview-only Synthetic disabled label only; no account exists to disable.
Archived Preview
archived-preview
preview-only Synthetic archive label only; no profile or history exists.

No synthetic user is active, and no user state can trigger behavior.

Future Validation Rules

  • No live user assignment without identity policy approval.
  • No resident profile creation without privacy approval.
  • No staff reviewer assignment without staff approval.
  • No app account creation without account model approval.
  • No email storage without privacy/legal approval.
  • No resident history view without retention/visibility policy.
  • No export permission without staff/privacy approval.
  • No AI permission for real submissions without separate AI-use policy.
  • No attendance or participation tracking permissions exist.
  • No scoring/ranking/compliance permissions exist.

Recommended Next Phase

Phase 7.5 - Config-Only Role Set CRUD Design, Planning Only

Phase 7.4 now adds the Admin CRUD Readiness Review. User Admin remains blocked; the next planning step is a narrow role-set template CRUD design without accounts, identities, role assignment, workflow activation, submissions, or writes.

planning-only