Operator control plane

Sign in with an operator address. Everything past this point is recorded against your name.

password — no email involved

Operators need a route that does not depend on the mail system, because the first thing you will want the console for is a morning when the mail system is the problem. Buyers keep magic links; this is for the people who fix things.

This address is not an operator.

Nothing here is available to it, and the attempt has been recorded. If that is wrong, add the address to app_admins.

NDIScompliant / ops
/ checks proven

Ops Board

Every row is green because something proved it, with a timestamp and a count attached — never because it is configured. A check that stops reporting goes stale on its own, then fails: a dead job has to look dead rather than quiet.

Alerts

An alert re-fires every run while its condition holds, and closes by itself the moment the evidence goes green. Acknowledging puts your name and your reason on it and silences the notification — it does not close the row, because an alert you can dismiss once is an alert you will dismiss always.

Revenue

Sessions and payments come from Stripe, refreshed by the reconciliation job. Recurring revenue is reported beside one-off kit sales, never inside them.

Checkout, by day

By product, last 90 days

Payments we cannot tie to an entitlement

Unmapped queue

Customers

Listed by the address that paid, not by account: most buyers have paid and never signed in, and an account-first list would simply not show them. Opening a record is itself an audited action, and it renders their data read-only — we never issue a session as them.

Access attempts

Who tried to sign in, what they hit, and — when the address they typed holds nothing — which address on their domain actually holds the entitlement. So a reply can name the right address instead of asking the customer to guess again.

The people who email us to say they are stuck are a small fraction of the people who are stuck. This is the rest of them.

Activity

What customers have actually done, newest first. Every row is an event a person caused — a sign-in, a download, a self-check, a vote. Nothing here is inferred.

Votes

What people are asking us to build next, and who asked. Seven people want a thing is a statistic; these seven providers want it is a phone call.

Support

The one-business-day promise, measured rather than remembered. Weekends are excluded; public holidays are not modelled, so on a holiday this clock runs slightly fast — it errs toward answering sooner.

Outbound queue

Replies the console has written and the host has not yet sent. This page holds no mail key — it queues, and a worker delivers. An empty queue means everything typed here has actually left the building.

Compliance Ops

Our own supply chain. An instrument counts as verified only when the authorised version has been opened at the primary source and the extract kept beside the work — a summarised fetch has invented statutory text three times, and each fabrication was internally coherent.

Broadcast

Compose, preview against suppression, canary, then release in batches. The console cannot express an unbatched send: batch size and interval are required, because one successful send proves the mechanism and never the capacity.

Actions

Gated actions are staged, never executed here. This page writes a proposal; a worker on the host holding the actual keys picks it up once confirmed. The browser has no Stripe key and no mail key, so a one-click price change is not a rule we follow — it is a thing this system cannot do.

Stage a gated action

Audit

Append-only, and it includes reading — every customer record opened is a row here. The panel gets the same evidence discipline we sell.