CityRisers emblem
DP
All personas

Platform Administration

Devon Park · Platform Engineer & Security Lead

Platform Administration

What needs attention to keep CityRisers reliable and secure?

Devon Park · Platform Engineer & Security Lead

Application

CityRisers

Environment

production

Active data mode

seeded demo

City scope

Wilmington (configured)

Release

Not exposed to in-app code — see Version History in the editor

Sources: workspace_state snapshot, App Settings, code inspection. Derived from trusted configuration, not editable labels alone.

Findings requiring attention

operational: 0degraded: 2unavailable: 0unknown: 2not configured: 3

"Unknown" and "Not configured" are not healthy states. "Ready to scale" is not shown — no readiness criteria have been evaluated.

Authorization denials recorded

degraded

Evidence: 2 denial event(s) in AuditLog. Codes: ERR_INSUFFICIENT_ROLE.

Category: Authorization

Affected: Role-gated actions

Environment: production

Owner: Platform Engineer

First occurrence: 9/27/2026, 10:51:24 AM

Last occurrence: 9/27/2026, 10:51:24 AM

Next action: Investigate each denial; confirm whether intended or a probing attempt.

Related: Security & Access → Authorization tests

No integrations configured

not configured

Evidence: No IntegrationConnection records found.

Category: Integrations

Affected: External integrations

Environment: production

Owner: Platform Engineer

First occurrence: Not recorded

Last occurrence: Not recorded

Next action: Configure required integrations through supported platform controls.

Related: Integrations

Application health monitoring not configured

not configured

Evidence: No in-app metrics surface exists. Runtime Logs Explorer is a dashboard surface only.

Category: Reliability

Affected: Reliability

Environment: production

Owner: Platform Engineer

First occurrence: Not recorded

Last occurrence: Not recorded

Next action: Define a monitoring setup using supported signals (logs, workflow runs, integration sync).

Related: Reliability

Privileged-user MFA not enforced

unknown

Evidence: No platform-exposed MFA enforcement toggle. Google social login is not MFA.

Category: Authentication

Affected: Privileged sign-in

Environment: production

Owner: Platform Engineer

First occurrence: Not recorded

Last occurrence: Not recorded

Next action: Restrict high-risk functions to MFA-verified paths where supported; document the gap.

Related: Security & Access

Pre-release verification not recorded

unknown

Evidence: No automated pre-release gate. Manual verification required before publish.

Category: Releases

Affected: Release process

Environment: production

Owner: Workspace owner

First occurrence: Not recorded

Last occurrence: Not recorded

Next action: Run the pre-release checklist and record results before publishing this update.

Related: Releases & Recovery

Recovery verification overdue

not configured

Evidence: No restore test recorded. Automatic backup not available on Builder plan.

Category: Recovery

Affected: Backup & recovery

Environment: production

Owner: Platform Engineer

First occurrence: Not recorded

Last occurrence: Not recorded

Next action: Record a manual CSV export and a restore test in a safe destination; document limitations.

Related: Releases & Recovery → Backup

Row-Level Security not enforced

degraded

Evidence: All CityRisers entities have rls: false. Service-layer guards exist but are not platform-enforced.

Category: Authorization

Affected: Data isolation

Environment: production

Owner: Platform Engineer

First occurrence: Not recorded

Last occurrence: Not recorded

Next action: Stage 2: configure RLS on entities carrying private participant data.

Related: Security & Access

Role and boundaries

Platform Administration · Devon Park, Platform Engineer & Security Lead

Responsibilities

  • Monitor technical health.
  • Diagnose failures.
  • Maintain authorization enforcement.
  • Manage integrations and secrets through supported platform controls.
  • Coordinate releases and recovery.
  • Verify environment and tenant isolation.
  • Manage technical incidents.
  • Track capacity and usage.
  • Provide technical evidence to the privacy officer.

This role does NOT automatically grant

  • Program delivery authority.
  • Project approval authority.
  • Private reflection access.
  • Safeguarding case-content access.
  • Consent override authority.
  • Permission to approve its own privilege escalation.
The in-app Platform Administrator (Devon Park) is distinct from the actual Base44 workspace owner, builder, service account, and infrastructure operator. The application cannot prevent workspace owners from accessing data if the platform does not enforce that boundary.

Capability inventory summary

Authentication & privileged access

Email/password

src/pages/Login.jsx

configured

Google social login

Not MFA

configured

Workspace SSO

Enterprise only

unsupported

Privileged MFA enforcement

No platform toggle

unknown

Reliability & recovery

Runtime logs explorer

Dashboard surface

available

In-app metrics

Monitoring setup required

not configured

Automatic backup & restore

Builder plan

unsupported

CSV export

Manual data copy

available

Code rollback

Version History (manual)

available

Full detail in each tab. Each capability is marked Available / Configured / Verified / Unsupported / Unknown — never invented.

Plan: Builder. Integration credits 30 of 60000 (resets 2026-10-11). No control is marked complete unless it is actually supported and configured.

See It. Build It. Rise Together. · Demo data — not real Wilmington outcomes.