01
Minimal public context
The pilot design gives each Action Point an access mode and an allowlisted projection. Public pages must omit internal IDs, staff identity, prices, suppliers, and internal notes.
Planned security architecture
A QR label is a public entry point into a private operating context. The planned architecture treats token leakage, tenant isolation, uploads, and recovery as product behavior—not deployment footnotes.
01
The pilot design gives each Action Point an access mode and an allowlisted projection. Public pages must omit internal IDs, staff identity, prices, suppliers, and internal notes.
02
QR and status URLs are designed to use separate high-entropy bearer capabilities stored only as keyed digests. Labels must be rotatable and revocable.
03
The paid-pilot launch gate requires organization scope in application authorization, composite relationships, and forced PostgreSQL row-level security.
04
Operational commands must validate the workflow version and append audit and outbox events in the same database transaction.
05
When photo uploads are enabled for a paid pilot, they must pass the bounded quarantine, malware scan, metadata-removal, safe re-encoding, encryption, and authorized-read launch gate.
06
Backup, restore, deploy, and rollback rehearsals are required before paid-pilot production data is accepted.
Safety boundary
Critical maintenance, spill, or facilities pages display the customer’s emergency instructions. The product does not dispatch emergency services, certify an area safe, or replace alarms, evacuation, or mandated reporting.
Security and availability statements on this site describe planned architecture and launch gates, not capabilities available in this fictional browser demo.
Fictional product walkthrough
Walk through a fictional point-of-use replenishment signal from scan to resolution. Nothing is submitted or stored.