GraceWorks Reentry · System

Administration

Access, profile library, deployment, and maintenance oversight.

Admin workspace

Cloudflare Access and the admin API enforce this workspace in production. Profile and roster changes are recorded server-side. Policy-bearing simulation defaults remain release-controlled and cannot be changed here.

Identity

Authenticated roster

Users appear after their first successful Access sign-in. Access policies control admission; this roster controls explicit per-application role memberships.

Permissions

Role and access configuration

ResidentOwn assignment and progress only
FacilitatorOperational assignments and session settings
AdminProfile library and system configuration

Access policies and server authorization must enforce these roles for every request.

Pilot content

Predefined fictional profile library

Ten fictional seed profiles ship in the migration. Select one to review or create a revision. Unsupported simulation settings are rejected by the server.

Scioto County package

Location names and exterior photos

Select a stable engine location, enter the real public-facing name and address, and paste the approved public R2 image URL. Applying the entry updates the selected profile’s settings JSON; saving the profile creates the audited revision.

  • Use a daylight exterior showing the public entrance.
  • Do not include identifiable residents, clients, license plates, or restricted security areas.
  • Record permission/source information with the original image before publishing.
Configuration

Global defaults

Versioned simulation defaults are defined by the approved application. Changing policy, county assumptions, sanctions, employment thresholds, or eligibility requires Henry's decision and a tested release.

Diagnostics

Application and audit

Check the deployed API/database and load the latest audited management events.

Maintenance

Reset and recovery

Ordinary assignment reset is an audited facilitator action. System-wide deletion or restore requires a reviewed D1 recovery procedure; no browser button here can erase pilot data.

Release control

Deployment and system references

Static roles: play, facilitator, and admin. Apply separate Cloudflare Access policies to every custom and default hostname. One D1 binding stores identities, profiles, assignments, progress revisions, and audit events.

  • Application engine: v0.28.5 checkpoint
  • Build: node tools/build-role-apps.cjs
  • Deployment guide: deployment/cloudflare/DEPLOYMENT_CHECKLIST.md
  • Assignment design: deployment/cloudflare/PROFILE_ASSIGNMENT.md