PROTOTYPEClickable mockup · simulates the finished app◃ Product overview
Operator Console
ProductionOP
Audit, security & governance
The append-only audit log (7-year WORM retention), platform security operations and legal governance. Role catalog and grants live on Access control; DSAR case handling on DSAR & compliance.
Search & filter · actor, target, action, tenant, time, reason · saved searches per operator · F21.11.03
Time
Action
Actor
Target · tenant
Reason / metadata
10:41:22
sys.impersonate.start
maria.ek
user u-8812 (Astrid S) · Nordvik
grant SG-2214 · #4471
10:38:04
sys.payments.refund
jonas.holm
payment PAY-77066 · Provence
450 SEK · #4462
10:32:19
tenant.flag.override
maria.ek
tenant sjostad · league_play
targeted testing
09:58:41
sys.user.lock
lena.vik
user u-7741 (Håkan L) · Granholm
brute-force triage
09:12:03
sys.impersonate.end
maria.ek
user u-8812 · session imp-4410
14 reads · 0 writes
≤ 100 k rows streams sync; larger sets queue an export job → signed URL, 7 d expiry (F21.11.04). Cursor pagination. Full schema per row: actor, actual_user (impersonation), action, target, tenant, impersonation_id, reason, ip, ua, request_id, session, metadata, seal columns (F21.11.02).
Impersonation sub-view · aggregated by impersonation_id · F21.11.05
Freeze a tenant completely. Single-use approval code (10 min TTL) from a second sys_security admin; every non-sys request answers 503 until disarmed.
Sign-in policy · F21.01.01–02 · F21.01.05–06
Providers: Microsoft OAuth or Google OAuth — no password, no OTP; JWKS-verified per provider
Allowlist gate: off-allowlist e-mails rejected even with a valid token · optional per-e-mail provider pin
Session: 60 min sliding · 8 h hard ceiling (immutable across reauth)
Fresh-auth gate: sensitive ops require re-auth < 5 min via WebAuthn (401 → transparent resolve)
Allowlist editor (SYS_ADMIN_EMAILS) · F21.01.02
sys_securityfresh-auth
My passkeys · mandatory second factor · F21.01.03
🔑 YubiKey 5C (maria.ek)registered 12 May · last used today 07:58
🔑 MacBook Touch ID (maria.ek)registered 3 Apr · last used yesterday
Sealed YubiKey envelope + runbook. Use only when both OAuth providers are down. Every use opens a mandatory post-incident review. Roles catalog + four-eyes grants live on Access control (F21.01.04).
CIS benchmark: 94% pass · 3 warnings
SBOM: regenerated 8 d ago (target ≤ 30 d)
Pentest (May 2026): 0 critical · 2 medium — 1 remediated, 1 in progress
DPIA register · flags features needing review · F21.13.06
Session replay (rrweb)approved w/ conditionsreview due 2026-09
AI plane (RAG)in assessmentblocker for GA
Fraud scoring on signupsapproved—
Retention policy overview · configured TTL vs observed age · F21.13.09
Collection
TTL
Observed
Status
sys_audit_entries
7 years (WORM)
oldest 412 d
ok
session replays
30 d
oldest 29 d
ok
ApiUsageEvent
90 d
oldest 121 d
anomaly
sandbox users
30 d
oldest 11 d
ok
GDPR request tracker + execution with SLA timers (F21.13.01–02) render on DSAR & compliance; the read-only GDPR snapshot (F21.13.10) sits on the user detail in User directory.
Esc
↵ opens the first hit · Esc closes · 🔒 = locked function (still shown — with an explanation)