Authorization and scope
Tenant membership, roles, capabilities, Site grants, explicit record ownership, and subscription state are enforced server-side.
Know what is implemented, what must pass before customer production, and which connected-property capabilities remain private preview.
Implemented foundation
The current pre-production system has synchronized SQLite/PostgreSQL schemas, backend authorization, tenant/Site scoping, revision-aware writes, activity and audit records, externalized jobs, and automated browser/mobile/API verification.
Tenant membership, roles, capabilities, Site grants, explicit record ownership, and subscription state are enforced server-side.
Work-order aggregate saves, revisions, activity provenance, audit events, and user-applied assistant proposals.
Web requests, scheduled work, agent execution, file cleanup, email, push, and reconciliation have explicit process boundaries.
Release gates
The initial release still requires schema freeze and migrations, coordinated identity/client cutover, managed PostgreSQL restore evidence, production object storage, email/APNs/StoreKit operations, secrets and observability, load testing, and incident procedures.
Managed backups, point-in-time recovery policy, object lifecycle, restore drills, and retention.
HTTPS, secure cookies, shared rate limiting, credential rotation, dependency scanning, logs, alerts, and incident ownership.
Staged load tests for APIs, database pools, workers, AI concurrency, files, and mobile synchronization.
Bridge enrollment, telemetry storage, monitoring evaluation, and delivery operations are not initial-release promises.
Public architecture stays logical. Credentials, private hostnames and endpoints, recovery commands, incident contacts, and operator runbooks remain private.