Live workspace. Durable storage schema active — live connectors, billing, and AI automation are activation-gated.View Activation Status
Signed out
Sign in as the approved QA user before running RLS-bound QA.
Sign in

Pilot Activation Control Room

CUSTOMER IMPACT BLOCKED
TENANT CREATION BLOCKED

Go/No-Go Decision Model

  • Current ReadinessGO_NO_GO_DECISION_BLOCKED
  • Production PilotSIMULATED_AND_BLOCKED
  • Internal Demo TenantSIMULATED_AND_BLOCKED

Customer Impact Boundary

  • Data ClassCUSTOMER_PII_OR_CONFIG
  • Allowed ScopeMOCK_DATA_ONLY
  • Forbidden ScopeANY_REAL_CUSTOMER_DATA

Isolation & RLS Proof

  • Tenant BoundaryREQUIRED_BEFORE_PILOT
  • RLS PolicyREQUIRED_BEFORE_PILOT
  • Owner ApprovalPENDING_OWNER_REVIEW

Failure Stop Conditions

  • Tenant Boundary AmbiguitySTOP_ACTIVATION
  • Unexpected ExposureSTOP_ACTIVATION
  • Rollback AvailabilitySTOP_ACTIVATION

Live Gates: Parked

All tenant activation paths are currently completely simulated. Owner action and strict proof of isolation are required before any live customer onboarding.

Microsoft 365 Canary Activation Package
BLOCKED - CREDENTIALS REQUIRED

This activation package is generated in LOCAL DRY-RUN mode. No live OAuth, Microsoft Graph, or provider connections have...

LOCAL DRY RUN NOT LIVE CONNECTED

Display-only. No live OAuth, Microsoft Graph, or provider connections executed.

Readiness Gates3/8 passed
orchestrator readiness console intelligence export credential descriptor scope lock token persistence tenant workspace boundary live execution flag secret leak check
Blocked Reasons(12)
  • CREDENTIAL_DESCRIPTOR_MISSING
  • CANNOT_VALIDATE_SCOPES_WITHOUT_CREDENTIAL_DESCRIPTOR
  • CANNOT_VALIDATE_TOKEN_PERSISTENCE_WITHOUT_CREDENTIAL_DESCRIPTOR
  • CANNOT_VALIDATE_BOUNDARY_WITHOUT_CREDENTIAL_DESCRIPTOR
  • SECRET_OR_RAW_ID_LEAK_DETECTED_IN_INPUT
  • SECRET_PATTERN_DETECTED_AT:orchestratorReadiness.liveGateImplication
  • SECRET_OR_RAW_ID_LEAK_DETECTED_IN_OUTPUT
  • SECRET_PATTERN_DETECTED_AT:gateResults[2].gate
  • SECRET_PATTERN_DETECTED_AT:gateResults[2].blockedReasons[0]
  • SECRET_PATTERN_DETECTED_AT:gateResults[3].blockedReasons[0]
  • ...and 2 more
Zero-Write: No-Live-Action:
Package ID: 22138-5w4i8r
Google WorkspaceControlled Live Canary Activation Package
Fail Closed - Invalid Configuration

Connector: google_workspace | Generated: 8/3/2026, 10:47:02 PM

LOCAL_DRY_RUN_NOT_LIVE_CONNECTED
|✓ No Live Execution
Gate Results12/13 passed
orchestrator readiness
Pass
console intelligence export
Pass
credential descriptor
Blocked
scope lock
Pass
forbidden scope check
Pass
token persistence
Pass
credential source
Pass
environment boundary
Pass
domain workspace boundary
Pass
live execution flag
Pass
abort criteria present
Pass
rollback path present
Pass
secret leak check
Pass

Blocked Reasons (7)

  • CLIENT_ID_NOT_CONFIGURED
  • CLIENT_SECRET_NOT_CONFIGURED
  • REDIRECT_URI_NOT_CONFIGURED
  • CONSENT_SCREEN_NOT_CONFIGURED
  • TEST_USER_NOT_PREPARED
  • SECRET_OR_RAW_ID_LEAK_DETECTED_IN_OUTPUT
  • REAL_DOMAIN_ID_DETECTED_AT:gateResults[8].gate

Scope Lock (openid + profile only)

openid
profile

Forbidden: Gmail, Drive, Calendar, Admin Directory, Cloud Platform, offline_access

Required Secure Credential Checklist
  • Google Cloud Console Project created
  • OAuth 2.0 Client ID (Web application type)
  • OAuth 2.0 Client Secret (stored in secure vault, NOT in env)
  • Authorized redirect URI configured in Google Cloud Console
  • OAuth consent screen configured (internal or external with test users)
  • API permissions configured: openid, profile (minimal)
  • Test user added to consent screen if using external app
Abort Criteria (8)
  • critical
    Any scope beyond openid and profile is detected in token response
  • critical
    Token persistence or refresh token is received when not expected
  • critical
    Domain/workspace boundary mismatch detected in response
  • critical
    Any write operation is attempted or detected
  • critical
    Gmail, Drive, Calendar, or Admin data is accessed
  • critical
    Secret or credential leak detected in logs or response
  • high
    Authentication error indicates over-privileged request
  • medium
    Rate limiting or throttling indicates unexpected load
Rollback/Disable Path (6 steps)
  1. Immediately revoke OAuth token via Google Cloud Console
  2. Disable OAuth client in Google Cloud Console
  3. Clear any cached tokens from local storage
  4. Document incident in operator evidence log
  5. Review Google Workspace audit logs for any unauthorized access
  6. Notify security team if data exposure detected
Zero Write Asserted
No Live Action Asserted
Live Executed: No
Credentials Never Displayed

This activation package is generated in LOCAL DRY-RUN mode. No live OAuth, Google APIs, or provider connections have been executed. Secure credentials must be supplied through the secure runtime path before any controlled live canary activation can proceed. This package is display-only and blocked_until_credentials_and_runtime_authorization.

No Google OAuth or Google Workspace API call has been executed. This is a local dry-run readiness package only.

Credential values are NEVER displayed or persisted by this surface. Supply credentials only through the secure runtime path (.env.local or vault).

Secure Credential Descriptor & Runtime Authorization

LOCAL DRY RUN NOT LIVE CONNECTED
BLOCKED FAIL CLOSED
Blocked Reasons:
  • CLIENT ID NOT CONFIGURED
  • CLIENT SECRET NOT CONFIGURED
  • TENANT ID NOT CONFIGURED
  • REDIRECT URI NOT CONFIGURED
  • TEST USER NOT PREPARED
  • ACTIVATION PACKAGE MISSING
  • CONSOLE INTELLIGENCE MISSING
  • ORCHESTRATOR MISSING
  • SECRET LEAK DETECTED IN OUTPUT

Configuration Checklist

Shows whether items are configured. Values belong only in .env.local and are NEVER displayed here.

Client ID*
Not Configured🔒
Client Secret*
Not Configured🔒
Tenant ID*
Not Configured🔒
Redirect URI*
Not Configured🔒
Test User Prepared*
Not Configured
MFA Session Prepared
Not Configured

Scope Lock Status

Valid: User.Read only

Token Persistence Status

Safe: Token persistence is false

Runtime Authorization Gates

credential descriptor
activation package
console intelligence
orchestrator readiness
scope lock
token persistence
live execution flag
environment boundary

Operator Steps (Credential Setup)

Credentials must be supplied through the secure runtime path. This surface does not accept or display credential values.

  1. Supply MICROSOFT_CLIENT_ID in .env.local (value NEVER displayed here)
  2. Supply MICROSOFT_CLIENT_SECRET in .env.local (value NEVER displayed here)
  3. Supply MICROSOFT_TENANT_ID in .env.local (value NEVER displayed here)
  4. Configure redirect URI in Microsoft Entra portal
  5. Prepare a test user account in sandbox/non-production tenant
  6. Ensure MFA is configured if required by tenant policy
  7. Request only User.Read scope for initial canary
  8. Set token persistence to false
  9. Verify environment boundary is sandbox or non_production

Safety Assertions

Live Executed: No
Zero Write Asserted: Yes
No Live Action Asserted: Yes
Local Dry-Run Statement:

LOCAL DRY-RUN ONLY: This runtime authorization package is generated in local dry-run mode. No live OAuth, Microsoft Graph, or provider connections have been executed. No credentials have been read, stored, transmitted, or validated by this surface. Values belong only in the secure runtime path (.env.local) and are NEVER displayed or persisted by this surface.

No Live Canary Executed:

No live Microsoft 365 canary has been executed. This is a display-only, read-only runtime authorization readiness surface.

This surface is display-only. Credentials are NEVER entered or displayed here.

Unified Activation Readiness Dashboard

Aggregates all gates for controlled live activation decision

LOCAL DRY RUN NOT LIVE CONNECTED
CONFIGURATION INCOMPLETE
Configuration Incomplete - Credential descriptor validation failed
Gate Summary4/12 passed

Activation Gates

Secure Credential Descriptor
Runtime Authorization Package
Microsoft 365 Canary Activation Package
User.Read Scope Lock
Token Persistence Disabled
Live Execution Disabled
Sandbox/Non-Production Environment
Dry-Run Readiness Orchestrator
Console Intelligence Report
Evidence/Report Export Readiness
Abort Criteria Defined
Rollback/Disable Path Defined

Blocked Reasons (12)

  • CLIENT ID NOT CONFIGURED
  • CLIENT SECRET NOT CONFIGURED
  • TENANT ID NOT CONFIGURED
  • REDIRECT URI NOT CONFIGURED
  • TEST USER NOT PREPARED
  • RUNTIME AUTHORIZATION PACKAGE MISSING
  • CANARY ACTIVATION PACKAGE MISSING
  • ORCHESTRATOR MISSING
  • +4 more...

Next Safe Operator Action

Fix credential descriptor issues: CLIENT ID NOT CONFIGURED

Priority: configuration

Rollback/Abort Readiness

Abort Criteria: 0
Rollback Steps: 0

No rollback path defined - activation blocked

Safety Assertions

Live Executed: No
Zero Write: Yes
No Live Action: Yes
Credentials Hidden: Yes
Local Dry-Run: LOCAL DRY-RUN ONLY: This unified activation readiness dashboard is generated in local dry-run mode. No live OAuth, Microsoft Graph, or provider connections have been executed. No credentials have been read, stored, transmitted, or validated by this surface. Values belong only in the secure runtime path (.env.local) and are NEVER displayed or persisted by this surface.
No Live Canary: No live Microsoft 365 canary has been executed. This is a display-only, read-only activation readiness surface for operator decision support.
Credential Security: Credential values are NEVER displayed or persisted by this surface. Supply credentials only through the secure runtime path (.env.local).

This surface is display-only. Credentials are NEVER entered or displayed here.