Cloudflare Access and the admin API enforce this workspace in production. Profile and roster changes are recorded server-side. Policy-bearing simulation defaults remain release-controlled and cannot be changed here.
Authenticated roster
Users appear after their first successful Access sign-in. Access policies control admission; this roster controls explicit per-application role memberships.
Role and access configuration
Access policies and server authorization must enforce these roles for every request.
Predefined fictional profile library
Ten fictional seed profiles ship in the migration. Select one to review or create a revision. Unsupported simulation settings are rejected by the server.
Global defaults
Versioned simulation defaults are defined by the approved application. Changing policy, county assumptions, sanctions, employment thresholds, or eligibility requires Henry's decision and a tested release.
Application and audit
Check the deployed API/database and load the latest audited management events.
Reset and recovery
Ordinary assignment reset is an audited facilitator action. System-wide deletion or restore requires a reviewed D1 recovery procedure; no browser button here can erase pilot data.
Deployment and system references
Static roles: play, facilitator, and admin. Apply separate Cloudflare Access policies to every custom and default hostname. One D1 binding stores identities, profiles, assignments, progress revisions, and audit events.
- Application engine: v0.27.6 stable baseline
- Build:
node tools/build-role-apps.cjs - Deployment guide:
deployment/cloudflare/DEPLOYMENT_CHECKLIST.md - Assignment design:
deployment/cloudflare/PROFILE_ASSIGNMENT.md