Founder / Admin Control
STAGING
Session not connected
Protected role required
NSGRADIUS staging command surface

Release oversight, without guesswork.

A restricted workspace for Daniel Musinguzi and authorized Admin staff to review, approve, and publish platform changes through the protected staging API.

Founder / Admin staff onlyIdentity verified server-side, not by this interface.
Security boundary: ADMIN_SECRET stays server-side

ADMIN_SECRET must never be placed in HTML, JavaScript, localStorage, sessionStorage, URL parameters, or screenshots. Authentication belongs to Cloudflare Access / identity plus server-side role verification.

API connection · Not connected
Protected staging API required. Demo values are visible for preview only; no action can be performed.
Not checked
Overview
Pending Review
02
Sample / demo value
Security Review
01
Sample / demo value
Founder Approved
01
Sample / demo value
Published
01
Sample / demo value
Blocked
01
Sample / demo value
Live data requires the protected staging API

The queue below is populated with labeled sample/demo records until the protected session and JSON item feed are confirmed. Failed API calls never become simulated success.

Release Queue

Review the next changes moving through the NSGRADIUS control path.

Preview data
Publish is server-gated.It is disabled unless a live item is founder_approved and the protected session authorizes the action.
ItemTypeOwnerCurrent statusUpdatedActions
Change control

Release Queue

Every privileged transition must be recorded by the staging API.

Demo rows until live feed
Action rule:Founder Approve can only request the founder_approved transition. Publish is disabled until the server reports founder_approved.
ItemTypeOwnerCurrent statusUpdatedActions

Live release queue unavailable

No live records are being fabricated. Reconnect to the protected staging API to review actual release items.

Traceability

Audit History

Immutable action evidence should come from the server, never from the browser.

Audit events

Select a release item to load its server audit trail.

Live only
ActorActionItem IDPrevious statusNew statusTimestampRequest IDResult

Live audit history unavailable

There is no fabricated audit data in this preview. A protected item selection and a successful JSON audit response are required.

Least privilege

Staff Access

Role descriptions are informational. The server must authorize every request.

UI permissions are not security

Buttons and disabled states are convenience signals only. Cloudflare Access / identity and server-side role verification must enforce these permissions.

Founder
Daniel Musinguzi
  • Review release items and evidence
  • Founder-approve a release
  • Publish only a founder-approved item
  • Read server audit history

The server decides whether the authenticated identity carries this role.

Admin
Operations
  • Review release items and evidence
  • Prepare test and security notes
  • Cannot founder-approve without server authorization
  • Cannot publish without server authorization

Admin actions remain bounded even if a UI control is manipulated.

Runtime visibility

System Health

Unknown is the honest state until the health endpoint provides evidence.

Pages Proxy
Future root-level _worker.js routing layer
Unknown
Staging Worker
Protected API and mutation boundary
Not connected
D1 Persistence
Release and role persistence
Unknown
Approval Service
Founder approval authorization
Unknown
Audit Persistence
Append-only audit event storage
Not connected
Connection contract

Last checked

Not checked

No service is marked healthy without API evidence. Health responses must be JSON from the protected staging endpoint.