Platform Administration
What needs attention to keep CityRisers reliable and secure?
Devon Park · Platform Engineer & Security Lead
Application
CityRisers
Environment
production
Active data mode
seeded demo
City scope
Wilmington (configured)
Release
Not exposed to in-app code — see Version History in the editor
Sources: workspace_state snapshot, App Settings, code inspection. Derived from trusted configuration, not editable labels alone.
Findings requiring attention
"Unknown" and "Not configured" are not healthy states. "Ready to scale" is not shown — no readiness criteria have been evaluated.
Authorization denials recorded
degradedEvidence: 2 denial event(s) in AuditLog. Codes: ERR_INSUFFICIENT_ROLE.
Category: Authorization
Affected: Role-gated actions
Environment: production
Owner: Platform Engineer
First occurrence: 9/27/2026, 10:51:24 AM
Last occurrence: 9/27/2026, 10:51:24 AM
Next action: Investigate each denial; confirm whether intended or a probing attempt.
Related: Security & Access → Authorization tests
No integrations configured
not configuredEvidence: No IntegrationConnection records found.
Category: Integrations
Affected: External integrations
Environment: production
Owner: Platform Engineer
First occurrence: Not recorded
Last occurrence: Not recorded
Next action: Configure required integrations through supported platform controls.
Related: Integrations
Application health monitoring not configured
not configuredEvidence: No in-app metrics surface exists. Runtime Logs Explorer is a dashboard surface only.
Category: Reliability
Affected: Reliability
Environment: production
Owner: Platform Engineer
First occurrence: Not recorded
Last occurrence: Not recorded
Next action: Define a monitoring setup using supported signals (logs, workflow runs, integration sync).
Related: Reliability
Privileged-user MFA not enforced
unknownEvidence: No platform-exposed MFA enforcement toggle. Google social login is not MFA.
Category: Authentication
Affected: Privileged sign-in
Environment: production
Owner: Platform Engineer
First occurrence: Not recorded
Last occurrence: Not recorded
Next action: Restrict high-risk functions to MFA-verified paths where supported; document the gap.
Related: Security & Access
Pre-release verification not recorded
unknownEvidence: No automated pre-release gate. Manual verification required before publish.
Category: Releases
Affected: Release process
Environment: production
Owner: Workspace owner
First occurrence: Not recorded
Last occurrence: Not recorded
Next action: Run the pre-release checklist and record results before publishing this update.
Related: Releases & Recovery
Recovery verification overdue
not configuredEvidence: No restore test recorded. Automatic backup not available on Builder plan.
Category: Recovery
Affected: Backup & recovery
Environment: production
Owner: Platform Engineer
First occurrence: Not recorded
Last occurrence: Not recorded
Next action: Record a manual CSV export and a restore test in a safe destination; document limitations.
Related: Releases & Recovery → Backup
Row-Level Security not enforced
degradedEvidence: All CityRisers entities have rls: false. Service-layer guards exist but are not platform-enforced.
Category: Authorization
Affected: Data isolation
Environment: production
Owner: Platform Engineer
First occurrence: Not recorded
Last occurrence: Not recorded
Next action: Stage 2: configure RLS on entities carrying private participant data.
Related: Security & Access
Role and boundaries
Platform Administration · Devon Park, Platform Engineer & Security Lead
Responsibilities
- Monitor technical health.
- Diagnose failures.
- Maintain authorization enforcement.
- Manage integrations and secrets through supported platform controls.
- Coordinate releases and recovery.
- Verify environment and tenant isolation.
- Manage technical incidents.
- Track capacity and usage.
- Provide technical evidence to the privacy officer.
This role does NOT automatically grant
- Program delivery authority.
- Project approval authority.
- Private reflection access.
- Safeguarding case-content access.
- Consent override authority.
- Permission to approve its own privilege escalation.
Capability inventory summary
Authentication & privileged access
Email/password
src/pages/Login.jsx
Google social login
Not MFA
Workspace SSO
Enterprise only
Privileged MFA enforcement
No platform toggle
Reliability & recovery
Runtime logs explorer
Dashboard surface
In-app metrics
Monitoring setup required
Automatic backup & restore
Builder plan
CSV export
Manual data copy
Code rollback
Version History (manual)
Full detail in each tab. Each capability is marked Available / Configured / Verified / Unsupported / Unknown — never invented.
Plan: Builder. Integration credits 30 of 60000 (resets 2026-10-11). No control is marked complete unless it is actually supported and configured.
