Ring & Knock
Operations workspaceCascade Stays — PNW
Manager preview activeManager route view selected locally. Full internal review surfaces are visible in this browser preview.
Draft work
Local work draftStage review work
Open Work

Local draft only. Nothing is dispatched or written outside this browser preview.

Admin Integrations

Internal workspaceManager reviewDraft mode
Summary viewDecision surface first

Settings Guardrails

Source-static proof

Integration Governance Console

No tokens / OAuth / webhooks
Integrations & AI governance

Scoped providers, AI validator posture, and audit-ready access in one admin console.

Integrations keeps provider scope, denied capabilities, developer surfaces, and AI/MCP access readable before any provider activation exists. Every card stays synthetic-only, review-only, and no-live.

Provider not configuredAirbnb

No guest PII, messages, access codes, payouts, or channel writebacks

Connected scopes6
AI / MCP actors4
Developer surfaces4
Audit events4
Provider not configured. No token exchange, OAuth flow, webhook delivery, MCP tool call, provider sync, external message, customer-data bridge, Supabase write, or production credential is present in this route.

Integration Guardrails

Provider not configured
Connected scopes6
AI / MCP actors4
Developer surfaces4
Audit events4
Account/workspace tenant boundary from day oneIntegration scope derives from active synthetic POC fixtures only; denial tenant integration rows render as zeroNo live tokensNo secretsNo production credentialsNo OAuth, API key creation, provider API calls, channel writeback, provider sync, or live AI model callsNo webhook deliveryNo webhook endpoints, signing secrets, external messages, MCP tool calls, autonomous actions, or repository/customer-data bridgeNo external writesNo real tenant, guest, owner, property, payment, or source-system recordsNo Supabase writes, database migrations, seed execution, storage writes, deployments, exports/downloads, payment/provider setup, or real-data migrationFuture owner real data must use a separate second tenant after migration, security, and tenant-isolation approvalEvery integration scope requires approval, audit, and revocation before activation

Connected App Scope Register

ProviderAreaStatusAllowed ScopeMapped RecordsLast SyncSafety BoundaryNext Action
AirbnbShort-Term channel contextProvider not configured6 synthetic occupancy rows, calendar context, payout matching candidateAccount -> workspace -> property -> listing -> reservationNever connectedNo guest PII, messages, access codes, payouts, or channel writebacksDefine read-only reservation and payout import scope
VrboShort-Term channel contextProvider not configuredCalendar hold context and payout matching candidateAccount -> workspace -> property -> listing -> reservationNever connectedNo external availability updates or guest messagesConfirm synthetic field map before connector work
Booking.comShort-Term channel contextProvider not configuredUnmatched import and reconciliation placeholderAccount -> workspace -> property -> listing -> reservation -> money eventNever connectedNo live booking, payout, or payment dataKeep as sample reconciliation source
Turnover / cleaner systemWork and cleaner paymentsDeferredTask import, assignment context, evidence, payment approval placeholderAccount -> workspace -> property -> work item -> cleaner/vendor payableNever connectedNo phone, address, pay rate, or live assignment deliveryUse synthetic cleaner/vendor queue only
Smart lock providerAccess and devicesDeferredDevice inventory and access-code status placeholderAccount -> workspace -> property -> unit/listing -> deviceNever connectedNo real lock codes, no code generation, no code deliveryDesign approval gate before any device connector
Direct booking payment providerMoney and direct bookingsProvider not configuredExternal collection status onlyAccount -> workspace -> property -> reservation -> money eventNever connectedStripe and live payment processing are deferredRepresent Imported, Pending, Received, Paid externally, and Reconciled only

AI / MCP Access Governance

ActorPurposeStatusAllowed ScopeDenied ScopeApproval RuleAudit Trail
Claude GitHub validatorReview plans, PRs, design prompts, and implementation deltasAvailable later by owner activationDocs repo, platform repo, synthetic fixtures, review commentsSecrets, production data, live customer records, external account changesOwner activates review; human approves any suggested code or design changeEvery review maps to repo, branch, issue/PR, and timestamp
Design ferry via Claude DesignProduce visual prototypes and return standalone HTML for reviewActive workflow, manual ferrySynthetic UI prompts, design directives, redacted wireframe feedbackReal tenant/guest/property/payment records and source-system private dataCodex validates usability, IA, data safety, and build impact before platform adoptionPrompt version, returned file version, assessment, and accepted changes
Operations AI assistantDraft messages, summarize work, suggest next actions, and flag riskDraft-only placeholderAccount-scoped synthetic records and approved knowledge snippetsAutonomous send, late fees, payment capture, lock-code release, vendor paymentHuman approval required before anything external or financially materialSource records, draft, reviewer, approval/decline, final visibility
MCP integration bridgeFuture scoped tool access for source-system and build validatorsDisabled placeholderExplicitly granted read-only tools inside the active account/workspaceUnscoped tenant access, production writes, secrets, and live payment actionsScope review required before enabling any MCP server or toolTool, scope, caller, input class, redaction result, and outcome

Developer Surface Placeholders

SurfaceStateCapabilityBlocked ActionsTenant BoundarySafe Next Action
API AccessDisabled placeholderFuture tenant-scoped API keys with account/workspace/property limitsNo key creation, no secret display, no production API callsKeys must bind to account_id, workspace_id, role, scopes, and expiryDocument key metadata and revocation requirements
MCP / AI Agent AccessReview-only placeholderFuture Claude/GitHub validator, design validator, and scoped ops assistantNo broad repository write, no customer data, no external messages, no payment actionsAgent reads only approved synthetic fixtures and scoped repo filesCreate approval checklist for validator activation
Email RoutingDisabled placeholderFuture inbound parsing and account-scoped communication routingNo mailbox connection, no outbound send, no resident/guest contact importMessages must map to account, workspace, property, source record, and visibilityModel internal draft and approval states first
WebhooksDisabled placeholderFuture event delivery for work, reservation, ledger, and payment status changesNo webhook endpoints, no signing secrets, no external deliveryEach event must include account_id and source record but no private payload by defaultDefine event types, redaction rules, retry policy, and audit log

Integration Audit Queue

EventSourceStatusEvidenceTenant SafetyNext Action
Review channel connector scopeAirbnb placeholderNeeds owner decision laterShort-Term calendar requires read-only reservation and payout import scopeNo live credentials or writebackHold until platform data model and account readiness are approved
Prepare Claude validator rulesGitHub review workflowReady for checklistOwner confirmed Claude can be activated for GitHub review once plan is readyRepo-only review; no production dataWrite validator checklist before first PR activation
Define webhook event classesDeveloper surface placeholderDeferredNeeded later for work, reservation, ledger, and payment workflow eventsNo webhook delivery; no signing secretDocument event names and redacted payload policy
Model email routing safetyMessaging and AI workflowDeferredMessaging AI is strategic, but external sending remains approval-gatedNo mailbox connection and no outbound messagesBuild internal draft queue before connecting any mailbox

Route Closure