Core API
Locked Protected Worker request boundaryBordoh OS · private administration
One governed engine.
Three isolated surfaces.
Bordoh OS coordinates platform operations while Auto Tech and Cleaning keep their own code, data access and business workflows.
Authorised users only. Access is identity-gated and audited.
Protected control plane
Verify the live platform boundary.
Unlock with the enrolled application passkey to verify the Core API, identity store and Hyperdrive connection to the isolated Neon platform schema. This read-only check does not activate business workflows.
Identity store
Locked D1 session and role boundaryNeon PostgreSQL
Locked Connected through Cloudflare HyperdrivePlatform schema
Locked Isolatedbordoh_platform namespace
Governed company register
One verified record for every Bordoh organisation.
This protected register reads only platform-owned records from Neon. It cannot edit, activate or retire a company, and every successful read is written to the immutable D1 audit trail.
Controlled onboarding
Prepare a company record for verification.
Saving this form creates a pending request in the audited control plane. It does not publish a Neon company record, enable a business app or assert that legal, ASIC, ABN, GST or tax details have been verified.
Provider routing control plane
Prepare connections without enabling traffic.
This Engine-only workspace records which published business may later receive a Twilio or Meta capability. It never asks for provider account identifiers, phone numbers, credentials, callback secrets or webhook routes. Every record remains pending verification, unbound and non-operational.
Immutable platform evidence
Review the latest privacy-minimized audit events.
This Engine-only view shows the action, resource class, actor class, request reference and occurrence time for up to 100 recent events. It never returns stored metadata, emails, actor identifiers, organization identifiers, resource identifiers, credentials, provider payloads or customer content. Audit events cannot be edited or deleted.
Privacy-safe operational monitoring
See the platform boundary without seeing customer data.
This read-only Engine view reports coarse service readiness, whether non-operational provider markers exist, whether protected write permissions remain withheld, and privacy-safe job-delivery totals for the latest 24 UTC hour buckets. It never returns tenant, provider, job or message identifiers, replay keys, payloads, contacts, phone numbers, emails or customer records. Every successful read is audited.
Overall boundary
Locked Pre-launch, non-operational stateCore API
Locked Protected Worker request boundaryD1 identity store
Locked Coarse query readiness onlyNeon platform schema
Locked Hyperdrive-backed platform namespaceProvider ingress
Locked No live provider callback routeConnection drafts
Locked Presence only; no provider detailsReplay receipts
Locked Presence only; no event keysWrite permissions
Locked Integrations and monitoring controlsJob delivery activity
Locked Latest 24 UTC hour bucketsDelivery total
Locked Aggregate count onlyDelivery retries
Locked No job or provider detailQuarantined or rejected
Locked Aggregate count onlyPrivacy-safe identity assurance
Verify identity and recovery readiness without exposing personal data.
This read-only Engine view confirms only coarse protection states: the active owner principal, Access binding, primary application passkey and independent backup-key readiness. It never returns emails, phone numbers, personal identifiers, credential identifiers, passkey names, sessions, secrets or recovery destinations. Every successful read is audited.
Overall protection
Locked Engine identity boundary onlyOwner principal
Locked Exactly one active Engine operatorAccess binding
Locked Active, owner-scoped identity bindingPrimary passkey
Locked Active application authenticationIndependent backup
Locked Hardware key remains deferred until purchasedRecovery ownership
Locked External identity provider retains recoveryReset controls
Locked No credential or contact reset actionWrite permissions
Locked Identity and recovery mutation controlsImmutable production evidence
Verify what is live and how it can be recovered.
This read-only Engine view records the production component, exact main-branch source commit, Cloudflare deployment reference and the previously verified rollback reference. GitHub main remains the source of record. No deploy, approve or rollback control is available here, and business operations remain disabled.
Architecture
Clear ownership replaces the old mixed repository.
Every app crosses the same versioned, tenant-scoped engine boundary.
Platform only
Engine Admin
Organisations, integrations, audit, identity and system health.
Business isolated
Auto Tech Admin
Jobs, vehicles, customers and communications through versioned contracts.
Business isolated
Cleaning Admin
Jobs, properties, customers and communications through versioned contracts.
Security boundary
Identity before application.
Cloudflare Access protects the administration surface with email sign-in and an enrolled second factor. Bordoh OS then independently verifies the application passkey, signed identity and tenant binding before privileged workflows launch.
- Business-email identities are allowlisted per administration app.
- Touch ID and the hardware security key provide phishing-resistant Cloudflare MFA.
- The authenticator app remains an allowed alternate factor and controlled recovery path.
- Cloudflare MFA never replaces the separate Bordoh OS application passkey.
- Tenant selection is server-owned and cannot come from request input.
- Provider traffic enters through a signed, replay-resistant gateway.
- Secrets stay in Cloudflare or the approved secret manager, never GitHub.
Application authentication
Enrol application passkeys.
Create a Touch ID passkey for daily administration and a separate hardware security key for recovery. Cloudflare Access identity verification remains required first.
Primary
Touch ID on this Mac
Phishing-resistant application authentication for the normal admin workflow.
Independent backup
Hardware security key
Keep this separate from the Mac and use it only when the primary passkey is unavailable.
Controlled migration
Every capability opens only after its evidence is complete.
- 01Architecture foundation
Sole repository, contracts, identity and tenant boundaries established.
- 02Control-plane verification
Live passkey, D1 and Hyperdrive-to-Neon evidence verified.
- 03Company and business suites
The governed register and pending-verification onboarding queue are the first office-suite release gates.
- 04Operational launch
Prove the 90/10 workday standard before accepting business activity.