Architecture Brief

3,962 words · 618 lines · Markdown

# Struxel Dynamics — Architecture & Workflow Brief

**Prepared for:** Eficens (AWS Technology Partner) — production readiness & AWS optimization
**Last verified:** 2026-09-24 · **Revision 5**
**App URL:** https://struxel.base44.app
**Runtime today:** Base44 BaaS on AWS · **Target:** dedicated, hardened AWS account

---

## How to read this document

This brief mixes two things that must never be confused. Every capability is labelled:

| Label | Means |
|-------|-------|
| **Built** | Exists in the application today; a code path is given. |
| **Eficens** | An AWS service the partner provisions. The app-side hook may exist; the infrastructure does not. |
| **Built + Eficens** | The application half exists; the AWS half is outstanding. |

Counts are measured against the repository and dated. See [`EFICENS_README.md`](./EFICENS_README.md)
for the doc map, the full verified inventory, and the "where does X live?" index.

**Companion documents**

- [`EFICENS_README.md`](./EFICENS_README.md) — index, conventions, verified inventory
- [`EFICENS_PRODUCT_FUNCTION_MAPPING.md`](./EFICENS_PRODUCT_FUNCTION_MAPPING.md) — product view → backend function
- [`EFICENS_SECRETS_REFERENCE.md`](./EFICENS_SECRETS_REFERENCE.md) — secret inventory & consolidation
- [`EFICENS_WORKFLOW_SCHEDULES.md`](./EFICENS_WORKFLOW_SCHEDULES.md) — workflow cadences & triggers
- [`EFICENS_PHASE_1_2_ARCHITECTURE.md`](./EFICENS_PHASE_1_2_ARCHITECTURE.md) — Phase 1 POC / Phase 2 target architecture and the gap register

**Contents**

1. [Executive summary](#1-executive-summary)
2. [Platform architecture](#2-platform-architecture)
3. [Tenant workspace (CCC)](#3-tenant-workspace-ccc)
4. [Alert & incident routing](#4-alert--incident-routing)
5. [Human-in-the-Loop (HITL)](#5-human-in-the-loop-hitl)
6. [Workflows](#6-workflows)
7. [Backend functions](#7-backend-functions)
8. [Row-Level Security](#8-row-level-security)
9. [User types](#9-user-types)
10. [Current AWS infrastructure](#10-current-aws-infrastructure)
11. [Feature flags](#11-feature-flags)
12. [Eficens engagement scope](#12-eficens-engagement-scope)
13. [Roadmap](#13-roadmap)

---

## 1. Executive summary

Struxel Dynamics is an **audit-grade AI governance and compliance platform** delivered as a
multi-tenant SaaS. It gives enterprise customers AI risk management, compliance automation,
incident response, and contributor marketplace capability through a unified tenant workspace —
the **Customer Command Center (CCC)**.

The application is built on the **Base44 platform** (authentication, PostgreSQL/Supabase
database, serverless functions, workflow automation, integrations). The frontend is
React + Tailwind CSS + Vite. It runs on Base44-managed AWS infrastructure today and is
ready to migrate to a dedicated AWS account for production hardening, cost optimization,
and SOC 2 Type II / ISO 27001 certification.

### Verified inventory (2026-09-24)

| What | Where | Count |
|------|-------|-------|
| Entity schemas | `base44/entities/*.jsonc` | 476 |
| Workflow definitions | `base44/workflows/*.jsonc` | 99 |
| Backend function directories | `base44/functions/*` | 999 |
| Product data functions | `base44/functions/products/*` | 76 |
| Page components | `src/pages/*.jsx` | 485 |
| In-app agents | `base44/agents/*.jsonc` | 1 |

### Highlights

- **148 product views** across 60 vertical bundles (catalog figure).
- **Struxel Security Suite** — 5 security products (Sentinel, Shield, Probe, Comply, Pulse)
  with dedicated backend functions and workspace pages.
- **What-If Simulator** — LLM threshold-impact prediction on every product view's Analyze tab.
- **Human-in-the-Loop review** — tenant-facing and staff review queues (Section 5).
- **5 delivery modes** — cloud SaaS (shared/dedicated), self-hosted (ECR/DockerHub), air gap,
  embedded SDK.
- **7 user types** with distinct onboarding, pricing, and access patterns (Section 9).
- **Target ACV** $423K · **Seed raise** $5M · **18-month GTM** to $8M ARR.

---

## 2. Platform architecture

### 2.1 Technology stack

| Layer | Technology |
|-------|-----------|
| **Frontend** | React 18, Tailwind CSS, Vite, shadcn/ui, Recharts, Framer Motion |
| **Backend** | Base44 serverless functions (TypeScript/Deno) |
| **Database** | PostgreSQL (Supabase-managed), Redis (cache / rate limiting) |
| **Auth** | Base44 Auth — email/password, Google OAuth, OTP, SAML/SSO |
| **Payments** | Stripe (primary), PayPal (alternative) |
| **AI/LLM** | OpenAI GPT-5, Anthropic Claude, Google Gemini (via Base44 `InvokeLLM`) |
| **Integrations** | Zoho CRM/Projects/Desk, ClickUp, GitHub, Google Calendar, Slack, LinkedIn, Calendly, ShipStation, Zoom, Affinda, Google Ads |
| **Infrastructure** | AWS ECS Fargate, ALB, RDS PostgreSQL, ElastiCache Redis, S3, Route 53, ACM |
| **CI/CD** | GitHub Actions, GHCR/ECR registry |

### 2.2 High-level architecture

```
┌──────────────────────────────────────────────────────────────┐
│                          USER LAYER                           │
│  Tenant Admins · Contributors · Reviewers · Coaches · Public  │
│  Partners · W2 Employees · Professional Plan · Client Members │
└────────────┬────────────────────────────┬────────────────────┘
             │                            │
   ┌─────────▼─────────┐        ┌─────────▼──────────┐
   │  Marketing site   │        │  Tenant workspace  │
   │  (public pages,   │        │  (CCC — product    │
   │   blog, pricing)  │        │   views, alerts)   │
   └─────────┬─────────┘        └─────────┬──────────┘
             │                            │
   ┌─────────▼────────────────────────────▼──────────┐
   │              Base44 application layer            │
   │  ┌───────────┐ ┌───────────┐ ┌────────────────┐ │
   │  │ Auth &    │ │ Entities  │ │ Functions      │ │
   │  │ RLS       │ │ + schemas │ │ (999 dirs)     │ │
   │  └───────────┘ └───────────┘ └────────────────┘ │
   │  ┌───────────┐ ┌───────────┐ ┌────────────────┐ │
   │  │ Workflows │ │ AI        │ │ Integrations   │ │
   │  │ (99)      │ │ InvokeLLM │ │ (Zoho, Slack…) │ │
   │  └───────────┘ └───────────┘ └────────────────┘ │
   └─────────┬────────────────────────────┬──────────┘
             │                            │
   ┌─────────▼──────────┐      ┌──────────▼─────────┐
   │ PostgreSQL (RDS)   │      │ Redis (ElastiCache)│
   │ 476 entity schemas │      │ cache + rate limits│
   └────────────────────┘      └────────────────────┘
```

### 2.3 Multi-tenancy model

Shared database, tenant-isolated:

- Every record carries a scoping field — `tenant_id`, `workspace_id`, `user_email`, or
  `created_by_id` depending on the entity.
- **Row-Level Security (RLS)** enforces that a user reads and writes only their own scope
  (Section 8).
- Provisioning creates isolated workspace config, product entitlements, data-source
  connections, and alert routing rules.
- Enterprise tenants can take **dedicated infrastructure** (own ALB, RDS, ECS cluster) for
  data-isolation compliance (HIPAA, GxP, SOX).

### 2.4 Service domains

The backend is organised into logical service domains. Each maps to a `*_SERVICE_URL` secret
and is deployed as an ECS Fargate service in the target architecture.

| Service | Responsibility | Secret |
|---------|---------------|--------|
| AI | LLM invocation, model monitoring, bias detection, explainability | `AI_SERVICE_URL` |
| Governance | Policy management, compliance tracking, audit evidence | `GOVERNANCE_SERVICE_URL` |
| Data | Data lineage, quality monitoring, dataset cataloging | `DATA_SERVICE_URL` |
| MLOps | Model registry, drift monitoring, change control | `MLOPS_SERVICE_URL` |
| Security | Identity management, key rotation, vulnerability scanning | `SECURITY_SERVICE_URL` |
| Monitoring | Alert routing, SLA tracking, incident management | `MONITORING_SERVICE_URL` |
| Automation | Workflow engine, scheduled tasks, webhooks | `AUTOMATION_SERVICE_URL` |
| Integration | External connectors (Zoho, Slack, GitHub, …) | `INTEGRATION_SERVICE_URL` |
| Analytics | Usage metering, billing, reporting | `ANALYTICS_SERVICE_URL` |
| Operational | Deployment orchestration, provisioning, health checks | `OPERATIONAL_SERVICE_URL` |
| Worker | Background job processing | `WORKER_SERVICE_URL` |

---

## 3. Tenant workspace (CCC)

The **Customer Command Center** (`src/pages/CustomerCommandCenter.jsx`) is the primary
tenant-facing interface — a governed workspace containing the tenant's purchased products,
compliance tools, and operational dashboards.

### 3.1 Tabs

```
Overview · Products & Views · Alerts & Incidents · Projects & Tasks
Data Sources · Security & Compliance · Billing & Seats · Reports & Exports
Integrations · Audit Prep · Presentations · Team & Settings
```

The same incident surface is reused by the **Service Control Plane**
(`src/pages/ServiceControlPlane.jsx`) in sandbox mode, so tenant and demo users see
identical behaviour.

### 3.2 Product view system

A tenant sees only the views they purchased. Enforcement happens at three layers:

1. **Entitlement** — `ServiceEntitlement` and `TenantMembership` define product/bundle access.
2. **Department mapping** — `DepartmentAccessMapper` maps purchased products to departments.
3. **RLS** — backend functions filter every query by `tenant_id` and verify entitlement.

Views are resolved by `MockupDrivenView` (`src/components/workspace/products/MockupDrivenView.jsx`),
which calls `resolveFunctionName(productId, tabId)` from `src/lib/productViewMetadata.js`.
The per-view function is `products/get<Name>Data`; the full mapping is in
[`EFICENS_PRODUCT_FUNCTION_MAPPING.md`](./EFICENS_PRODUCT_FUNCTION_MAPPING.md).

Categories: AI Risk & Governance · Compliance · Emerging Risk · Data Intelligence ·
Operations · Security · Struxel Security Suite · Analytics.

### 3.3 Data flow

```
Tenant data sources (AWS, Snowflake, APIs)
        │
        ▼
  Data source connector (proxy + cache)
        │
        ▼
  Product view backend function
    · resolves caller's tenant
    · applies RLS
    · runs analytics
        │
        ├──────────────┬──────────────┐
        ▼              ▼              ▼
    KPI cards      Charts         Data tables
        └──────────────┴──────────────┘
                       │
                       ▼
              InsightBar — LLM narrative:
              compliance gaps, remediation actions
```

---

## 4. Alert & incident routing

Three-tier routing, driven by per-tenant rules in `AlertRoutingConfig`:

```
Alert source (product · bundle · infrastructure · security)
        │
        ▼
  Alert routing config (per-tenant rules)
        │
   ┌────┴─────────────────┬─────────────────────┐
   ▼                      ▼                     ▼
Tenant-owned         Managed service      Platform backbone
(compliance,         (infrastructure      (always Struxel)
 model, data)         when managed)
   │                      │                     │
   ▼                      ▼                     ▼
Tenant team          Struxel SE team      Internal SRE
   │                      │
   ▼                      ▼
Zoho Desk / Jira     Slack / PagerDuty
```

**Built:** `Alert`, `AlertRoutingConfig`, `AIIncident`, `createAlertTicket`,
`escalateAlertToIncident`, `autoCreateAlertTicket`, `syncAlertsToNotifications`.

Incidents carry an `audience` field (`tenant`, `internal`, `both`) that governs whether a
tenant sees them — the same split that governs the review queues in Section 5.

---

## 5. Human-in-the-Loop (HITL)

High-risk AI events route to a human for a documented decision. This is the mechanism the
EU AI Act, NIST AI RMF, SOC 2, and enterprise procurement reviews all ask about.

### 5.1 Two surfaces, one entity

All review work lives in the `ReviewQueueItem` entity and is split by `department`:

| Audience | Departments | UI | Purpose |
|----------|-------------|----|---------|
| **Tenant (customer)** | `legal`, `compliance`, `customer_success` | Incidents tab → **Review Queue** sub-tab | The tenant's own high-risk AI events awaiting a documented decision |
| **Struxel staff** | `engineering`, `platform_ops` (+ all) | `/ReviewQueue` page | Internal governance gates and platform incidents |

`engineering` and `platform_ops` items are Struxel-internal — infrastructure incidents,
managed-service work, product code changes. They are **excluded from the tenant surface**:
a tenant must never see internal platform incidents such as database connection-pool
exhaustion or service latency spikes.

### 5.2 Where it lives

| Piece | File |
|-------|------|
| Queue, filters, tenant scoping | `src/components/ccc/hitl/HITLReviewQueue.jsx` |
| Queue row | `src/components/ccc/hitl/HITLReviewCard.jsx` |
| Task detail + decision form | `src/components/ccc/hitl/HITLDecisionPanel.jsx` |
| Tenant host | `src/components/console/SCPIncidentsTab.jsx` (sub-tab id `hitl`) |
| Staff host | `src/pages/ReviewQueue.jsx` |
| Event-context renderer | `src/components/ccc/hitl/HITLContentRenderer.jsx` |
| Reviewer capacity metrics | `src/components/ccc/hitl/HITLQueueMetrics.jsx` |
| Evidence attachments | `src/components/ccc/hitl/HITLAttachments.jsx` |
| Auditor evidence export | `src/components/ccc/hitl/HITLEvidenceExport.js` |
| SLA escalation job | `base44/functions/escalateOverdueHitlItems/entry.ts` |

### 5.3 Decision gate

A decision cannot be recorded until **every** `resolution_checklist` item is completed, and
a rationale (`reviewer_notes`) is **mandatory** for `high` and `critical` risk. Each decision
writes `status`, `reviewer_decision`, `reviewer_notes`, `reviewed_by`, `reviewed_at`, and
`resolution_checklist`, then appends to `audit_trail` — that array **is** the audit record
(actor, timestamp, action, detail).

Checklist ticks persist immediately, written **cumulatively and in order**: each tick sends
the full list, so two rapid clicks cannot overwrite the first.

**Two-person approval.** A `high` or `critical` item cannot be released by one person. The
first approval records `reviewer_decision` and parks the item in `in_review` with
`second_reviewer_decision: 'pending'`; only a *different* signed-in reviewer can close the
gate, and the first reviewer sees the item read-only. Both decisions append to `audit_trail`
(`first_review_approved`, then `second_review_approved` / `second_review_rejected`).

**Evidence.** Reviewers attach files through `attachments` (the uploaded URL only — never the
bytes) and export an auditor-ready JSON bundle containing the item, decision, checklist,
attachments, and full audit trail.

### 5.4 Built vs outstanding

**Built:** review queue with filters (Needs review / Escalated / Closed / All), task detail
with event context, resolution checklist, contact roster, decision gate, audit trail,
tenant/staff scoping.

**Nothing outstanding.** The five gaps tracked through Rev 5 — two-person approval, SLA
auto-escalation, evidence-bundle export, decision attachments, and reviewer capacity metrics —
are all described in 5.3 and all built. The escalation job is
`escalateOverdueHitlItems`, swept hourly by the *HITL SLA Auto-Escalation* workflow.

**Known constraint (open):** `ReviewQueueItem` RLS is admin-only (Section 8), so the tenant
queue is usable only by tenant admins until an explicit reviewer role is defined. Tracked as
G10 in [`EFICENS_PHASE_1_2_ARCHITECTURE.md`](./EFICENS_PHASE_1_2_ARCHITECTURE.md).

---

## 6. Workflows

A **workflow** is a repeatable, governed process that moves work from intake → classification
→ execution → evidence → completion, producing audit-ready artifacts automatically.

### 6.1 Categories

| # | Category | Flow |
|---|----------|------|
| 1 | **AI Risk** | Registration → risk scoring → drift review → bias evaluation → validation |
| 2 | **Incident** | Intake → classification → investigation → remediation → evidence |
| 3 | **Compliance** | Consent → training verification → policy mapping → regulation alignment → audit prep |
| 4 | **Contributor** | Intake → contributor assignment → reviewer assignment → deliverable → client approval |
| 5 | **Career** | Resume review → interview prep → coaching → portfolio |
| 6 | **Client Hiring** | Intake → candidate matching → interviews → offer → placement (15% fee) |
| 7 | **Managed Services** | Connector setup → SSO/IdP → monitoring → monthly health checks → audit simulation |

### 6.2 Engine

The engine uses the **CNCF Serverless Workflow** format. Workflows are durable (they survive
restarts); wait steps use ISO-8601 durations.

```
Trigger (scheduled · entity event · connector webhook · manual)
        │
        ▼
  Workflow engine (CNCF SWF)
    step: call    → invoke_backend_function / compute_seconds_until
    step: wait    → durable pause (ISO-8601)
    step: switch  → branch on jq conditions
        │
        ▼
  Entity update · notification · ticket creation
```

**99 workflow definitions** are deployed. The full list — cadence, trigger entity, and the
function each calls — is in
[`EFICENS_WORKFLOW_SCHEDULES.md`](./EFICENS_WORKFLOW_SCHEDULES.md).

Representative examples: `Auto-orchestrate tenant provisioning`, `Audit Evidence
Auto-Collection`, `SOC2 Daily Audit Evidence Snapshot`, `Escalate Stale Critical Alerts to
Incidents`, `Model Retirement Workflow`, `Quarterly Access Review`, `Daily Tenant Usage
Metering`, `Monthly DR Drill`.

---

## 7. Backend functions

**998 function directories** under `base44/functions/`. Each is an HTTP handler, scheduled
job, or webhook processor.

### 7.1 Product data functions (76)

Every product view is backed by `products/get<Name>Data`. These functions:

- authenticate via `base44.auth.me()`;
- resolve the caller's `tenant_id` from `DeploymentUser` membership;
- filter every entity query by `tenant_id` (or `workspace_id` for compliance entities);
- accept an optional `ai_system_id` for cross-product scoping;
- return `{ _empty: true }` when the tenant has no data — **never** mock or hardcoded numbers;
- accept `limit` and `sort` for server-side pagination.

Pagination is provided by `src/lib/paginationUtils.js` (`buildPaginationParams`,
`buildPaginatedFilter`, `hasMorePages`, `nextOffset`).

### 7.2 Other domains

| Domain | Representative functions |
|--------|--------------------------|
| Provisioning | `provisionTenant`, `provisionTenantOrchestrator`, `createManagedDeployment`, `createDeployment`, `provisionEnterpriseGroups` |
| Billing & payments | `createStripeCheckout`, `stripeWebhook`, `pushUsageToStripe`, `billingPortal`, `processPartnerPayouts`, `paypalWebhook` |
| CRM & sales | `createZohoCRMContact`, `createZohoCRMProspect`, `getZohoCrmDeals`, `autoAssignLead`, `generateLeadIntelligence` |
| AI & LLM | `aiGovernanceAssistant`, `aiReviewAssistant`, `aiProjectMatcher`, `aiCorrelationEngine`, `aiBulkReview` |
| Curriculum & training | `fetchCurriculumFromGitHub`, `syncCurriculumFromGitHub`, `generateModuleContent`, `autoGradeAssessment` |
| Security & compliance | `secretsRotationCheck`, `scanTenantSecurity`, `runSastScan`, `runDastScan`, `verifyAuditChain`, `enforceDataResidency`, `enforceDataRetention` |
| Infrastructure | `monitorEcsHealth`, `configureAutoScaling`, `createDedicatedVpcCluster`, `createDedicatedRds`, `createDedicatedAlb` |
| Deployment | `orchestrateFullDeployment`, `deployBlueGreen`, `autoRollbackDeployment`, `scaleDeploymentResources` |
| Air gap & self-hosted | `generateAirGapBundle`, `generateAirgapRelease`, `generateEmbeddedSdkPackage`, `generateSelfHostedPackage` |

### 7.3 Observability

`src/lib/structuredLogger.js` emits JSON logs carrying `trace_id` and `span_id` for
distributed trace correlation. **Built.**

---

## 8. Row-Level Security

RLS is applied across the entity catalog — **473 entities at last audit** of 476 schemas.
Every entity uses one of five patterns, chosen by its scoping field:

| Pattern | Scoping field | Read / create / update | Delete |
|---------|---------------|------------------------|--------|
| Tenant-scoped | `tenant_id` | `data.tenant_id` = `{{user.data.tenant_id}}`, `$or` admin fallback | admin only |
| Workspace-scoped | `workspace_id` | `data.workspace_id` = `{{user.data.tenant_id}}`, `$or` admin fallback | admin only |
| User-scoped | `user_email` | `data.user_email` = `{{user.email}}`, `$or` admin fallback | admin only |
| Owner-scoped | `created_by_id` | `created_by_id` = `{{user.id}}`, `$or` admin fallback | admin only |
| Admin-only | global config | `user_condition.role = admin` | admin only |

**Prerequisite:** every User record must carry `tenant_id`. This is written by
`provisionTenant` and `setupTenantWorkspace` via `base44.auth.updateMe({ tenant_id })`.
Without it, tenant-scoped RLS cannot match and users see nothing.

Worked examples:

| Entity | Pattern | Read | Create/Update | Delete |
|--------|---------|------|---------------|--------|
| `AIIncident` | tenant | tenant + `audience ∈ {tenant, both}`, or admin | tenant or admin | admin |
| `ReviewQueueItem` | tenant | admin only (current) | admin only | admin |
| `RiskScenario` | workspace | workspace or admin | workspace or admin | admin |
| `ServiceEntitlement` | user | `user_email` or admin | `user_email` or admin | admin |
| `FeatureFlag` | admin-only | public | admin | admin |

> **Open item:** `ReviewQueueItem` is currently admin-only. Opening the tenant queue to
> non-admin tenant reviewers is a security decision that requires an explicit role list.

---

## 9. User types

Seven personas, each with its own onboarding, pricing, and entry point.

| # | Persona | Entry point | Pricing | Key functions |
|---|---------|-------------|---------|---------------|
| 1 | **Tenant Admin** (enterprise customer) | `/CustomerCommandCenter` | $2K–$15K/mo, dedicated custom | `getTenantDashboard`, `provisionTenant`, `getCommandCenterData`, `deprovisionTenantProduct` |
| 2 | **Professional Plan** (individual practitioner) | `/ProfessionalPricing` → `/ProfessionalDashboard` | $59 / $149 / $399 per month; domain add-ons $349–$499 | `createStripeCheckout`, `fetchDomainTraining`, `generateCertificate`, `getDomainProgress` |
| 3 | **Client Member** (talent buyer) | `/ClientMembershipPricing` → `/TalentBuying` | $99 / $199 / custom | `generateBidPackage`, `aiProjectMatcher`, `aiContributorMatching`, `createZohoCRMContact` |
| 4 | **Contributor** (marketplace worker) | `/ContributorIntakeEnhanced` → `/ContributorDashboard` | Free training → paid plan | `fetchCurriculumFromGitHub`, `autoGradeAssessment`, `badgeUnlockAutomation`, `runWeeklyPayoutBatch` |
| 5 | **Partner** (technology / implementation) | `/PartnerApply` → `/PartnerDashboard` | Commission-based | `routePartnerLead`, `setupPartnerWebhook`, `partnerSaleWebhook`, `processPartnerPayouts` |
| 6 | **W2 Employee** (Struxel staff) | `/EmployeeOnboarding` → `/EmployeeHome` | Salary | `zohoProvisionEmployee`, `personalizeEmployeeDashboard`, `hrPerformanceInsights`, `autoEnrollOnHire` |
| 7 | **Public visitor** | `/` | — | Marketing pages only |

**Contributor badges:** BGD-GEN, BGD-MSTR, BGD-AUD across Bronze / Silver / Gold tiers.
**Partner types:** technology, implementation, referral, marketplace vendor.

---

## 10. Current AWS infrastructure

| Resource | Current setup |
|----------|--------------|
| Compute | ECS Fargate (shared cluster), auto-scaling per service |
| Database | RDS PostgreSQL (Supabase-managed), read replicas for analytics |
| Cache | ElastiCache Redis (rate limiting, session cache) |
| Load balancer | ALB (shared, 80/443) |
| Storage | S3 (uploads, air gap bundles, evidence artifacts) |
| DNS | Route 53, wildcard TLS via ACM |
| Secrets | AWS Secrets Manager via Base44 — see [`EFICENS_SECRETS_REFERENCE.md`](./EFICENS_SECRETS_REFERENCE.md) |
| Networking | VPC, public/private subnets, security groups per tier |
| CI/CD | GitHub Actions → GHCR/ECR → ECS |

### Application-layer hooks already built for AWS services

These exist in code today; Eficens provisions the AWS side.

| Capability | App-side hook | AWS services |
|-----------|---------------|--------------|
| Data warehouse | `STAGING_DATABASE_URL` / `PROD_DATABASE_URL` configured | Redshift, Athena, Glue |
| Event streaming | `healthSse` (SSE) for real-time updates | Kinesis, MSK |
| Distributed tracing | `structuredLogger.js` with `trace_id` / `span_id` | OpenTelemetry, X-Ray |
| Rate limiting | `checkRateLimit`, `checkRateLimitWithBurst` | API Gateway, WAF |
| SLO/SLI dashboards | `getSloDashboardData` | CloudWatch, QuickSight, Grafana |
| Blue-green migrations | `validateBlueGreenMigration` (expand-contract, 6 steps) | CodeDeploy, Lambda |
| Environment parity | `generateMaskedDataset` (masks email, phone, name, address, SSN, API key, URL) | DMS, Lambda |
| Cost tagging | `applyCostTags` — `struxel:tenant`, `struxel:environment`, `struxel:cost-center`, `struxel:managed-by`, `struxel:billing-category` | Cost Explorer, Compute Optimizer |
| Secret sprawl audit | `auditSecretSprawl` — redundancy pairs and rotation recommendations | Secrets Manager |

---

## 11. Feature flags

**Built.** `/FeatureFlagAdmin` gives administrators centralised control of feature rollout,
backed by the `FeatureFlag` entity.

| Capability | Detail |
|-----------|--------|
| Create / delete flags | Unique `key`, description, enabled state |
| Toggle | `FeatureFlag.update(id, { is_enabled })` |
| Rollout percentage | 0–100% |
| Role restriction | `allowed_roles` array |
| Email allowlist | `allowed_emails` array |
| RLS | Public read, admin-only create/update/delete |

**Fields:** `key`, `description`, `is_enabled`, `rollout_percentage`, `allowed_roles`,
`allowed_emails`, `ai_system_id`.
**Data fetching:** `base44.entities.FeatureFlag.list('-updated_date', 200)`.

---

## 12. Eficens engagement scope

### 12.1 What Eficens provides

1. **AWS production readiness audit** — review the current setup against SOC 2 / ISO 27001.
2. **Dedicated AWS account** — IAM, VPC architecture, cost allocation tags.
3. **Infrastructure as code** — Terraform/CloudFormation for tenant provisioning, multi-region DR, security baselines.
4. **Cost optimization** — right-size ECS, Spot for batch, Savings Plans.
5. **Security hardening** — GuardDuty, Security Hub, Config Rules, Secrets Manager rotation.
6. **Performance** — RDS read replicas, ElastiCache tuning, CloudFront, API Gateway caching.
7. **CI/CD** — GitHub Actions → ECR → ECS blue/green with automated rollback.
8. **Data warehouse** — Redshift/Athena off operational PostgreSQL.
9. **Event streaming** — Kinesis/Kafka for alerts and incidents.
10. **Distributed tracing** — OpenTelemetry/X-Ray across services.
11. **SLO dashboards** — QuickSight/Grafana over `getSloDashboardData`.
12. **Blue-green DB migrations** — wire `validateBlueGreenMigration` into CI/CD.
13. **Environment parity** — wire `generateMaskedDataset` into the staging refresh pipeline.

### 12.2 Application-layer backlog — **complete**

| Item | Outcome |
|------|---------|
| C1 Mock-data migration | Product functions query live entities; no mock data |
| C2 `ai_system_id` filtering | Product functions filter by `ai_system_id` when passed |
| C3 `ai_system_id` on schemas | Field declared on 122 entities |
| C4 RLS policies | Applied across the entity catalog |
| C5 Custom subtab widgets | `WIDGET_TYPES` registry + `resolveWidgetType()` |
| C6 Widget auto-detection | Keyword detection + explicit override |
| C7 Schema-driven forms | `CreateRecordDrawer` reads `schema()` and generates fields |
| C8 Product alias registration | `product_aliases` on `ProductRelease` |
| C9 Pagination | `paginationUtils.js`; functions accept `limit` + `sort` |
| C10 Emerging-risk subtabs | All 17 emerging-risk functions return distinct slices |

### 12.3 AWS provisioning backlog (Eficens scope)

| # | Item | Existing app-side hook | AWS services to provision |
|---|------|------------------------|---------------------------|
| A1 | Real-time guardrail API | `generateEmbeddedSdkPackage` | API Gateway + Lambda authorizer + DynamoDB DAX |
| A2 | Cross-region DR | `setupMultiRegionFailover` | Aurora Global Database + Route 53 failover |
| A3 | Security hardening | `scanTenantSecurity` | GuardDuty, Security Hub, Config Rules |
| A4 | Audit evidence pipeline | `auditEvidenceAutoCollection` | S3 + Athena workgroup + Glue + QuickSight |
| A5 | Data warehouse | `STAGING_DATABASE_URL` / `PROD_DATABASE_URL` | Redshift + Athena/Glue |
| A6 | Event streaming | `healthSse` | Kinesis Data Streams or MSK |
| A7 | Distributed tracing | `structuredLogger.js` | X-Ray daemon + OpenTelemetry collector |
| A8 | SLO dashboards | `getSloDashboardData` | QuickSight or Grafana |
| A9 | Blue-green DB migrations | `validateBlueGreenMigration` | CodeDeploy wiring |
| A10 | Environment parity | `generateMaskedDataset` | DMS wiring |
| A11 | Dedicated tenant provisioning | `createDedicatedVpcCluster`, `createDedicatedRds`, `createDedicatedAlb` | Terraform/CloudFormation templates |
| A12 | Cost optimization | `applyCostTags` | Tag application, Spot, Savings Plans |
| A13 | Air gap automation | `generateAirgapRelease`, `AirgapDeliveryManager` | KMS-encrypted S3 + Snowball Edge |

### 12.4 Integration points

- **Secrets** — see [`EFICENS_SECRETS_REFERENCE.md`](./EFICENS_SECRETS_REFERENCE.md)
- **Connectors** — Google Calendar, Slack (OAuth-connected)
- **Workflows** — see [`EFICENS_WORKFLOW_SCHEDULES.md`](./EFICENS_WORKFLOW_SCHEDULES.md)
- **RLS** — Section 8

---

## 13. Roadmap

### Infrastructure & compliance (12–24 months)

1. Dedicated AWS account migration → SOC 2 Type II
2. Multi-region active-active (us-east-1 primary, eu-west-1 for GDPR)
3. HIPAA / FedRAMP Moderate
4. Automated dedicated tenant infrastructure

### Product & platform

1. Real-time policy enforcement via the embedded SDK
2. Full autonomous-agent governance
3. Federated learning & cross-tenant model registry (anonymised)
4. Carbon-aware AI (AWS Carbon Footprint Tool integration)
5. Visual workflow builder for tenant admins
6. ~~HITL completion~~ — **shipped (Rev 6)**: two-person approval, SLA auto-escalation, evidence export, attachments, reviewer capacity metrics (Section 5.4)

### Business

1. $8M ARR in 18 months (19 enterprise customers at $423K ACV, $5M seed)
2. Eficens as primary AWS partner; 5+ implementation partners
3. 100+ contributor placements per quarter
4. First-mover in EU AI Act tooling; 20+ jurisdictional frameworks

---

## Revision history

| Rev | Date | Change |
|-----|------|--------|
| 6 | 2026-09-24 | HITL section 5.4 closed out: two-person approval, SLA auto-escalation, evidence-bundle export, decision attachments, reviewer capacity metrics. Added `attachments` to `ReviewQueueItem`. Counts updated to 999 functions / 99 workflows. |
| 5 | 2026-09-24 | Rewritten for consistency and navigation. Added doc conventions, verified inventory, HITL section, and the Built / Eficens labelling. Corrected stale function, entity, and product-function counts. |
| 4 | 2026-09-11 | Competitive positioning, analytics instrumentation, ROI calculator, getting-started wizard, cross-product correlation hero, cornerstone blog content. |
| 3 | — | AWS infrastructure specifications, secret consolidation, cost tagging. |
| 2 | — | RLS coverage, personas, feature flag admin. |
| 1 | — | Initial architecture brief. |
base44
Edit with Base44