Reports and data rights

Reports Data Rights Reviewer Workflow

This public reviewer board ties report exports, signed-in account-save gates, data-rights controls, permission previews, protected reviewer smoke, and owner activation review into one no-secret workflow. It publishes aggregate evidence only while report bodies, account payloads, private EVE data, provider calls, and database writes stay gated.

Reports And Export Evidence35

3 export formats and 6 checklist labels are ready.

Account Save Gates18/22

Account saves stay staged until owner, auth, database, and rollback evidence are recorded.

Data Rights Review5

Protected export, delete, disconnect, logout, and session routes keep private no-store boundaries.

Protected Reviewer Smoke10/14

Smoke packet labels are available while protected packet bodies remain admin-only.

Owner ActivationGated

10 owner smoke evidence fields still need review before activation.

No-Secret TextReady

Public text excludes private data, token material, protected packet bodies, and separate-project details.

OffDatabase writes
OffOAuth starts
OffWebhook delivery
1/10Owner smoke checklist
ExcludedPrivate EVE data
values excluded

Owner Evidence Fields

0/10 protected evidence fields are recorded; 10 still need owner review.

  • Smoke timestamprequired
  • Reviewerrequired
  • Tested Ops routerequired
  • Report-save resultrequired
  • Account-export resultrequired
  • Destructive-control resultrequired
  • Database runtime resultrequired
  • Webhook boundary resultrequired
  • Rollback decisionrequired
  • Tracker rowrequired
1/10 ready

Owner Smoke Checklist

20 public-safe owner checklist labels are mirrored.

  • Owner smoke evidence fields completereview
  • Owner smoke outcome passedreview
  • Owner activation decision readyreview
  • Report-save result recordedreview
  • Account-export result recordedreview
  • Destructive controls recordedreview
  • Database runtime recordedreview
  • Webhook boundary recordedreview
  • Side effects still offready
  • Tracker row recordedreview
ready

Reports And Export Evidence

35 report tools, 3 export formats, and 6 public checklist labels are ready.

Keep report bodies browser-local unless the user exports or later signs in for account saves.

owner-review

Account Save Gates

18/22 combined launch gates are ready while signed-in saves stay staged.

Enable account saves only after live auth, database, owner smoke, and rollback evidence are recorded.

ready

Data Rights Review

5 protected account-control routes and 5 private header targets are covered.

Keep export, delete, disconnect, logout, and browser-local clear actions user-led and private.

ready

Permission Preview Boundary

63 scopes and 8 feature consent plans are mapped without starting OAuth.

Ask for feature-specific consent only when a signed-in feature needs it.

protected-review

Protected Reviewer Smoke

10/14 reviewer smoke gates are ready, with protected packet exports held behind admin access.

Use the protected reviewer smoke packet for owner checks while public pages expose counts only.

owner-review

Owner Activation Decision

1/10 owner smoke checklist items are ready; 10 evidence fields still need owner review.

Keep account saves, exports, deletion, disconnect, logout, webhooks, provider calls, and database writes gated.

ready

Reports Data Rights Reviewer page

Public workflow page shows aggregate readiness and owner gates only.

ready

Reports Data Rights Reviewer JSON

Machine-readable feed exposes public-safe counts and links only.

ready

Reports And Export Evidence proof

35 report tools, 3 export formats, and 6 public checklist labels are ready.

ready

Account Save Gates proof

18/22 combined launch gates are ready while signed-in saves stay staged.

ready

Data Rights Review proof

5 protected account-control routes and 5 private header targets are covered.

ready

Permission Preview Boundary proof

63 scopes and 8 feature consent plans are mapped without starting OAuth.

ready

Protected Reviewer Smoke proof

10/14 reviewer smoke gates are ready, with protected packet exports held behind admin access.

ready

Owner Activation Decision proof

1/10 owner smoke checklist items are ready; 10 evidence fields still need owner review.

ready

Reports export manifest

Public export manifest describes export formats without report bodies.

ready

Public health JSON

Public health links the reviewer and readiness feeds without private payloads.

ready

Owner evidence checklist

Public page lists required owner evidence labels and states without exposing evidence values.

public-no-secret

Visibility

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

public-readiness-and-protected-route-labels-only

Source Data

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

excluded

Report Bodies

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

excluded

Raw Pasted Inputs

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

excluded

Account Reports

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

excluded

Account Exports

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

private-no-store-after-sign-in

Account Deletes

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

private-no-store-after-sign-in

Eve Disconnect

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

excluded

Private Eve Data

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

excluded

Token Values

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

excluded

Token Ciphertext

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

excluded

Provider Secrets

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

excluded

Owner Evidence Values

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

disabled

Provider Calls

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

disabled

Webhook Delivery

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

disabled

Database Writes

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

disabled

Account Writes

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

excluded

Separate Project Accounts

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

No-Secret Reports Data Rule

Public reports data-rights reviewer exposes aggregate reports, export, account-save, data-rights, permission-preview, protected-smoke, proof-link, owner evidence checklist labels, and owner-gate counts only; it does not expose report bodies, raw pasted inputs, account reports, account exports, account delete payloads, EVE disconnect payloads, owner evidence values, EVE token values, token ciphertext, private EVE data, provider secrets, raw visitor identifiers, raw browser agent strings, payment profile details, support messages, manual queue notes, protected admin packet bodies, or separate-project account details, and it does not start OAuth, write database rows, call EVE or CCP, call providers, deliver webhooks, export account data, delete accounts, disconnect EVE, log out sessions, clear browser storage, or mutate data.