Controlled login remains gated.

EVE SSO Account Reviewer Workflow
Public proof for the controlled-login review path: account launch, permission consent, auth-flow, token health, owner acceptance, and data-rights packets are staged for review while OAuth starts, token exchanges, private EVE reads, session mutation, database writes, and account-control actions stay disabled.
0 gate(s) block account launch.
Protected packets are linked as labels for owner review.
0 owner checklist item(s) still block activation.
0 controlled-login pilot gate(s) remain blocked.
10 protected evidence field(s) still need owner results.
Public login remains hidden.
Feature-specific consent stays preview-only until the user asks for that feature.
JSON and Markdown owner packets stay admin-gated.
EVE SSO launch gate review
owner-review-required; 3/5 launch checks ready.
EVE SSO activation packet
waiting-on-feature-flag; 6/8 owner checks ready.
EVE auth flow review
gated-by-feature-flag; 5/6 route checks ready.
EVE permission review
8/8 consent preview plans ready.
EVE token-health review
0 token risk signals; 6/6 token checks ready.
Data rights launch
9/12 data-rights launch gates ready.
publicData first-login boundary
Public-safe evidence is ready for this account launch gate.
- Evidence Route
- /api/auth/eve/consent-preview?scopes=publicData&returnTo=/dashboard
Auth-flow handoff
Auth routes, state handling, callback guard, and account controls stay under protected review.
- Evidence Route
- /api/admin/eve/auth-flow
Launch-gate owner review
This gate is staged but still needs owner review before activation.
- Evidence Route
- /api/admin/eve/launch-gate
Token-health handoff
Public-safe evidence is ready for this account launch gate.
- Evidence Route
- /api/admin/eve/token-health
Account data-rights and controls
Public-safe evidence is ready for this account launch gate.
- Evidence Route
- /api/admin/data-rights/launch-packet
Private-scope feature consent
Private and write/action scopes stay feature-specific and preview-only until a user asks for them.
- Evidence Route
- /api/admin/eve/permissions-review-packet
Owner acceptance run
This gate is staged but still needs owner review before activation.
- Evidence Route
- /api/admin/eve/activation-packet
Rollback and live-smoke proof
Public-safe evidence is ready for this account launch gate.
- Evidence Route
- /api/health
No-Secret EVE SSO Account Reviewer Rule
This protected account launch packet summarizes EVE SSO launch-gate status, auth-flow readiness, permission consent coverage, token-health counts, data-rights controls, owner review gates, proof targets, and safety booleans only. It does not expose client credential values, EVE tokens, token ciphertext, cookie values, session payloads, raw scopes, private EVE data, account payloads, provider credentials, raw logs, or separate-project account data, and it never starts OAuth, exchanges tokens, mutates sessions, contacts EVE/CCP, reads private EVE data, writes database rows, or runs account-control actions.