Operational Architecture & Governance Matrix
Detailed specification of AppLedger's 5-tier role authorizations, 11 named workflow templates, "Request to Action" escalation engine, and RLS guest access security model.
Workflow Template Pipeline Visualizer
Configurable multi-stage gate pipelines with automated stage progression, PostgreSQL Row-Level Security checks, and live task card dispatching.
5-Tier Granular Role Hierarchy
Strict authorization rules prevent unauthorized task deletion, unapproved date extensions, or scope creep. Filter permissions live by clicking any role below:
"Request to Action" Escalation Engine
When operators hit external blockers, a single click dispatches an auto-routed escalation packet directly to their supervisor with immutable audit logs.
Staging API Secret Key Expiration
"Blocked waiting for DevOps Lead sign-off following scheduled key rotation across automated CI/CD staging pipelines."
Row-Level Security Guest Access Console
Grant external clients and auditors read-only milestone visibility. PostgreSQL Row-Level Security policies evaluate is_guest flags at the database layer to prevent zero-knowledge data bleed.
Explicit Scope Comparison: Internal Member View vs Guest Sandbox View
Guest access is governed by the is_guest profile flag + explicit task-grant mappings in PostgreSQL Row-Level Security, not a separate role tier.
| Workstation Data Field | Internal Member View (is_guest = false) | Guest Sandbox View (is_guest = true) |
|---|---|---|
| Deliverable Milestone Status | Full Edit & Stage Update Access | ✓ Visible (Read-Only Milestone Status) |
| Internal Squad Budget / Hourly Cost | Visible ($140/hr) | 🔒 Redacted ([PROTECTED BY RLS]) |
| Internal Squad Discussion Logs | Full Comment & Upload Access | 🔒 Redacted ([ZERO-KNOWLEDGE]) |
| Employee Workload Metrics | Visible (96% Velocity) | 🔒 Redacted ([SCOPE RESTRICTED]) |
| Escalation Blocker Controls | Single-Click Blocker Dispatched | Disabled (Read-Only Visitor Scope) |