3,962 words · 618 lines · Markdown
# Struxel Dynamics — Architecture & Workflow Brief
**Prepared for:** Eficens (AWS Technology Partner) — production readiness & AWS optimization
**Last verified:** 2026-09-24 · **Revision 5**
**App URL:** https://struxel.base44.app
**Runtime today:** Base44 BaaS on AWS · **Target:** dedicated, hardened AWS account
---
## How to read this document
This brief mixes two things that must never be confused. Every capability is labelled:
| Label | Means |
|-------|-------|
| **Built** | Exists in the application today; a code path is given. |
| **Eficens** | An AWS service the partner provisions. The app-side hook may exist; the infrastructure does not. |
| **Built + Eficens** | The application half exists; the AWS half is outstanding. |
Counts are measured against the repository and dated. See [`EFICENS_README.md`](./EFICENS_README.md)
for the doc map, the full verified inventory, and the "where does X live?" index.
**Companion documents**
- [`EFICENS_README.md`](./EFICENS_README.md) — index, conventions, verified inventory
- [`EFICENS_PRODUCT_FUNCTION_MAPPING.md`](./EFICENS_PRODUCT_FUNCTION_MAPPING.md) — product view → backend function
- [`EFICENS_SECRETS_REFERENCE.md`](./EFICENS_SECRETS_REFERENCE.md) — secret inventory & consolidation
- [`EFICENS_WORKFLOW_SCHEDULES.md`](./EFICENS_WORKFLOW_SCHEDULES.md) — workflow cadences & triggers
- [`EFICENS_PHASE_1_2_ARCHITECTURE.md`](./EFICENS_PHASE_1_2_ARCHITECTURE.md) — Phase 1 POC / Phase 2 target architecture and the gap register
**Contents**
1. [Executive summary](#1-executive-summary)
2. [Platform architecture](#2-platform-architecture)
3. [Tenant workspace (CCC)](#3-tenant-workspace-ccc)
4. [Alert & incident routing](#4-alert--incident-routing)
5. [Human-in-the-Loop (HITL)](#5-human-in-the-loop-hitl)
6. [Workflows](#6-workflows)
7. [Backend functions](#7-backend-functions)
8. [Row-Level Security](#8-row-level-security)
9. [User types](#9-user-types)
10. [Current AWS infrastructure](#10-current-aws-infrastructure)
11. [Feature flags](#11-feature-flags)
12. [Eficens engagement scope](#12-eficens-engagement-scope)
13. [Roadmap](#13-roadmap)
---
## 1. Executive summary
Struxel Dynamics is an **audit-grade AI governance and compliance platform** delivered as a
multi-tenant SaaS. It gives enterprise customers AI risk management, compliance automation,
incident response, and contributor marketplace capability through a unified tenant workspace —
the **Customer Command Center (CCC)**.
The application is built on the **Base44 platform** (authentication, PostgreSQL/Supabase
database, serverless functions, workflow automation, integrations). The frontend is
React + Tailwind CSS + Vite. It runs on Base44-managed AWS infrastructure today and is
ready to migrate to a dedicated AWS account for production hardening, cost optimization,
and SOC 2 Type II / ISO 27001 certification.
### Verified inventory (2026-09-24)
| What | Where | Count |
|------|-------|-------|
| Entity schemas | `base44/entities/*.jsonc` | 476 |
| Workflow definitions | `base44/workflows/*.jsonc` | 99 |
| Backend function directories | `base44/functions/*` | 999 |
| Product data functions | `base44/functions/products/*` | 76 |
| Page components | `src/pages/*.jsx` | 485 |
| In-app agents | `base44/agents/*.jsonc` | 1 |
### Highlights
- **148 product views** across 60 vertical bundles (catalog figure).
- **Struxel Security Suite** — 5 security products (Sentinel, Shield, Probe, Comply, Pulse)
with dedicated backend functions and workspace pages.
- **What-If Simulator** — LLM threshold-impact prediction on every product view's Analyze tab.
- **Human-in-the-Loop review** — tenant-facing and staff review queues (Section 5).
- **5 delivery modes** — cloud SaaS (shared/dedicated), self-hosted (ECR/DockerHub), air gap,
embedded SDK.
- **7 user types** with distinct onboarding, pricing, and access patterns (Section 9).
- **Target ACV** $423K · **Seed raise** $5M · **18-month GTM** to $8M ARR.
---
## 2. Platform architecture
### 2.1 Technology stack
| Layer | Technology |
|-------|-----------|
| **Frontend** | React 18, Tailwind CSS, Vite, shadcn/ui, Recharts, Framer Motion |
| **Backend** | Base44 serverless functions (TypeScript/Deno) |
| **Database** | PostgreSQL (Supabase-managed), Redis (cache / rate limiting) |
| **Auth** | Base44 Auth — email/password, Google OAuth, OTP, SAML/SSO |
| **Payments** | Stripe (primary), PayPal (alternative) |
| **AI/LLM** | OpenAI GPT-5, Anthropic Claude, Google Gemini (via Base44 `InvokeLLM`) |
| **Integrations** | Zoho CRM/Projects/Desk, ClickUp, GitHub, Google Calendar, Slack, LinkedIn, Calendly, ShipStation, Zoom, Affinda, Google Ads |
| **Infrastructure** | AWS ECS Fargate, ALB, RDS PostgreSQL, ElastiCache Redis, S3, Route 53, ACM |
| **CI/CD** | GitHub Actions, GHCR/ECR registry |
### 2.2 High-level architecture
```
┌──────────────────────────────────────────────────────────────┐
│ USER LAYER │
│ Tenant Admins · Contributors · Reviewers · Coaches · Public │
│ Partners · W2 Employees · Professional Plan · Client Members │
└────────────┬────────────────────────────┬────────────────────┘
│ │
┌─────────▼─────────┐ ┌─────────▼──────────┐
│ Marketing site │ │ Tenant workspace │
│ (public pages, │ │ (CCC — product │
│ blog, pricing) │ │ views, alerts) │
└─────────┬─────────┘ └─────────┬──────────┘
│ │
┌─────────▼────────────────────────────▼──────────┐
│ Base44 application layer │
│ ┌───────────┐ ┌───────────┐ ┌────────────────┐ │
│ │ Auth & │ │ Entities │ │ Functions │ │
│ │ RLS │ │ + schemas │ │ (999 dirs) │ │
│ └───────────┘ └───────────┘ └────────────────┘ │
│ ┌───────────┐ ┌───────────┐ ┌────────────────┐ │
│ │ Workflows │ │ AI │ │ Integrations │ │
│ │ (99) │ │ InvokeLLM │ │ (Zoho, Slack…) │ │
│ └───────────┘ └───────────┘ └────────────────┘ │
└─────────┬────────────────────────────┬──────────┘
│ │
┌─────────▼──────────┐ ┌──────────▼─────────┐
│ PostgreSQL (RDS) │ │ Redis (ElastiCache)│
│ 476 entity schemas │ │ cache + rate limits│
└────────────────────┘ └────────────────────┘
```
### 2.3 Multi-tenancy model
Shared database, tenant-isolated:
- Every record carries a scoping field — `tenant_id`, `workspace_id`, `user_email`, or
`created_by_id` depending on the entity.
- **Row-Level Security (RLS)** enforces that a user reads and writes only their own scope
(Section 8).
- Provisioning creates isolated workspace config, product entitlements, data-source
connections, and alert routing rules.
- Enterprise tenants can take **dedicated infrastructure** (own ALB, RDS, ECS cluster) for
data-isolation compliance (HIPAA, GxP, SOX).
### 2.4 Service domains
The backend is organised into logical service domains. Each maps to a `*_SERVICE_URL` secret
and is deployed as an ECS Fargate service in the target architecture.
| Service | Responsibility | Secret |
|---------|---------------|--------|
| AI | LLM invocation, model monitoring, bias detection, explainability | `AI_SERVICE_URL` |
| Governance | Policy management, compliance tracking, audit evidence | `GOVERNANCE_SERVICE_URL` |
| Data | Data lineage, quality monitoring, dataset cataloging | `DATA_SERVICE_URL` |
| MLOps | Model registry, drift monitoring, change control | `MLOPS_SERVICE_URL` |
| Security | Identity management, key rotation, vulnerability scanning | `SECURITY_SERVICE_URL` |
| Monitoring | Alert routing, SLA tracking, incident management | `MONITORING_SERVICE_URL` |
| Automation | Workflow engine, scheduled tasks, webhooks | `AUTOMATION_SERVICE_URL` |
| Integration | External connectors (Zoho, Slack, GitHub, …) | `INTEGRATION_SERVICE_URL` |
| Analytics | Usage metering, billing, reporting | `ANALYTICS_SERVICE_URL` |
| Operational | Deployment orchestration, provisioning, health checks | `OPERATIONAL_SERVICE_URL` |
| Worker | Background job processing | `WORKER_SERVICE_URL` |
---
## 3. Tenant workspace (CCC)
The **Customer Command Center** (`src/pages/CustomerCommandCenter.jsx`) is the primary
tenant-facing interface — a governed workspace containing the tenant's purchased products,
compliance tools, and operational dashboards.
### 3.1 Tabs
```
Overview · Products & Views · Alerts & Incidents · Projects & Tasks
Data Sources · Security & Compliance · Billing & Seats · Reports & Exports
Integrations · Audit Prep · Presentations · Team & Settings
```
The same incident surface is reused by the **Service Control Plane**
(`src/pages/ServiceControlPlane.jsx`) in sandbox mode, so tenant and demo users see
identical behaviour.
### 3.2 Product view system
A tenant sees only the views they purchased. Enforcement happens at three layers:
1. **Entitlement** — `ServiceEntitlement` and `TenantMembership` define product/bundle access.
2. **Department mapping** — `DepartmentAccessMapper` maps purchased products to departments.
3. **RLS** — backend functions filter every query by `tenant_id` and verify entitlement.
Views are resolved by `MockupDrivenView` (`src/components/workspace/products/MockupDrivenView.jsx`),
which calls `resolveFunctionName(productId, tabId)` from `src/lib/productViewMetadata.js`.
The per-view function is `products/get<Name>Data`; the full mapping is in
[`EFICENS_PRODUCT_FUNCTION_MAPPING.md`](./EFICENS_PRODUCT_FUNCTION_MAPPING.md).
Categories: AI Risk & Governance · Compliance · Emerging Risk · Data Intelligence ·
Operations · Security · Struxel Security Suite · Analytics.
### 3.3 Data flow
```
Tenant data sources (AWS, Snowflake, APIs)
│
▼
Data source connector (proxy + cache)
│
▼
Product view backend function
· resolves caller's tenant
· applies RLS
· runs analytics
│
├──────────────┬──────────────┐
▼ ▼ ▼
KPI cards Charts Data tables
└──────────────┴──────────────┘
│
▼
InsightBar — LLM narrative:
compliance gaps, remediation actions
```
---
## 4. Alert & incident routing
Three-tier routing, driven by per-tenant rules in `AlertRoutingConfig`:
```
Alert source (product · bundle · infrastructure · security)
│
▼
Alert routing config (per-tenant rules)
│
┌────┴─────────────────┬─────────────────────┐
▼ ▼ ▼
Tenant-owned Managed service Platform backbone
(compliance, (infrastructure (always Struxel)
model, data) when managed)
│ │ │
▼ ▼ ▼
Tenant team Struxel SE team Internal SRE
│ │
▼ ▼
Zoho Desk / Jira Slack / PagerDuty
```
**Built:** `Alert`, `AlertRoutingConfig`, `AIIncident`, `createAlertTicket`,
`escalateAlertToIncident`, `autoCreateAlertTicket`, `syncAlertsToNotifications`.
Incidents carry an `audience` field (`tenant`, `internal`, `both`) that governs whether a
tenant sees them — the same split that governs the review queues in Section 5.
---
## 5. Human-in-the-Loop (HITL)
High-risk AI events route to a human for a documented decision. This is the mechanism the
EU AI Act, NIST AI RMF, SOC 2, and enterprise procurement reviews all ask about.
### 5.1 Two surfaces, one entity
All review work lives in the `ReviewQueueItem` entity and is split by `department`:
| Audience | Departments | UI | Purpose |
|----------|-------------|----|---------|
| **Tenant (customer)** | `legal`, `compliance`, `customer_success` | Incidents tab → **Review Queue** sub-tab | The tenant's own high-risk AI events awaiting a documented decision |
| **Struxel staff** | `engineering`, `platform_ops` (+ all) | `/ReviewQueue` page | Internal governance gates and platform incidents |
`engineering` and `platform_ops` items are Struxel-internal — infrastructure incidents,
managed-service work, product code changes. They are **excluded from the tenant surface**:
a tenant must never see internal platform incidents such as database connection-pool
exhaustion or service latency spikes.
### 5.2 Where it lives
| Piece | File |
|-------|------|
| Queue, filters, tenant scoping | `src/components/ccc/hitl/HITLReviewQueue.jsx` |
| Queue row | `src/components/ccc/hitl/HITLReviewCard.jsx` |
| Task detail + decision form | `src/components/ccc/hitl/HITLDecisionPanel.jsx` |
| Tenant host | `src/components/console/SCPIncidentsTab.jsx` (sub-tab id `hitl`) |
| Staff host | `src/pages/ReviewQueue.jsx` |
| Event-context renderer | `src/components/ccc/hitl/HITLContentRenderer.jsx` |
| Reviewer capacity metrics | `src/components/ccc/hitl/HITLQueueMetrics.jsx` |
| Evidence attachments | `src/components/ccc/hitl/HITLAttachments.jsx` |
| Auditor evidence export | `src/components/ccc/hitl/HITLEvidenceExport.js` |
| SLA escalation job | `base44/functions/escalateOverdueHitlItems/entry.ts` |
### 5.3 Decision gate
A decision cannot be recorded until **every** `resolution_checklist` item is completed, and
a rationale (`reviewer_notes`) is **mandatory** for `high` and `critical` risk. Each decision
writes `status`, `reviewer_decision`, `reviewer_notes`, `reviewed_by`, `reviewed_at`, and
`resolution_checklist`, then appends to `audit_trail` — that array **is** the audit record
(actor, timestamp, action, detail).
Checklist ticks persist immediately, written **cumulatively and in order**: each tick sends
the full list, so two rapid clicks cannot overwrite the first.
**Two-person approval.** A `high` or `critical` item cannot be released by one person. The
first approval records `reviewer_decision` and parks the item in `in_review` with
`second_reviewer_decision: 'pending'`; only a *different* signed-in reviewer can close the
gate, and the first reviewer sees the item read-only. Both decisions append to `audit_trail`
(`first_review_approved`, then `second_review_approved` / `second_review_rejected`).
**Evidence.** Reviewers attach files through `attachments` (the uploaded URL only — never the
bytes) and export an auditor-ready JSON bundle containing the item, decision, checklist,
attachments, and full audit trail.
### 5.4 Built vs outstanding
**Built:** review queue with filters (Needs review / Escalated / Closed / All), task detail
with event context, resolution checklist, contact roster, decision gate, audit trail,
tenant/staff scoping.
**Nothing outstanding.** The five gaps tracked through Rev 5 — two-person approval, SLA
auto-escalation, evidence-bundle export, decision attachments, and reviewer capacity metrics —
are all described in 5.3 and all built. The escalation job is
`escalateOverdueHitlItems`, swept hourly by the *HITL SLA Auto-Escalation* workflow.
**Known constraint (open):** `ReviewQueueItem` RLS is admin-only (Section 8), so the tenant
queue is usable only by tenant admins until an explicit reviewer role is defined. Tracked as
G10 in [`EFICENS_PHASE_1_2_ARCHITECTURE.md`](./EFICENS_PHASE_1_2_ARCHITECTURE.md).
---
## 6. Workflows
A **workflow** is a repeatable, governed process that moves work from intake → classification
→ execution → evidence → completion, producing audit-ready artifacts automatically.
### 6.1 Categories
| # | Category | Flow |
|---|----------|------|
| 1 | **AI Risk** | Registration → risk scoring → drift review → bias evaluation → validation |
| 2 | **Incident** | Intake → classification → investigation → remediation → evidence |
| 3 | **Compliance** | Consent → training verification → policy mapping → regulation alignment → audit prep |
| 4 | **Contributor** | Intake → contributor assignment → reviewer assignment → deliverable → client approval |
| 5 | **Career** | Resume review → interview prep → coaching → portfolio |
| 6 | **Client Hiring** | Intake → candidate matching → interviews → offer → placement (15% fee) |
| 7 | **Managed Services** | Connector setup → SSO/IdP → monitoring → monthly health checks → audit simulation |
### 6.2 Engine
The engine uses the **CNCF Serverless Workflow** format. Workflows are durable (they survive
restarts); wait steps use ISO-8601 durations.
```
Trigger (scheduled · entity event · connector webhook · manual)
│
▼
Workflow engine (CNCF SWF)
step: call → invoke_backend_function / compute_seconds_until
step: wait → durable pause (ISO-8601)
step: switch → branch on jq conditions
│
▼
Entity update · notification · ticket creation
```
**99 workflow definitions** are deployed. The full list — cadence, trigger entity, and the
function each calls — is in
[`EFICENS_WORKFLOW_SCHEDULES.md`](./EFICENS_WORKFLOW_SCHEDULES.md).
Representative examples: `Auto-orchestrate tenant provisioning`, `Audit Evidence
Auto-Collection`, `SOC2 Daily Audit Evidence Snapshot`, `Escalate Stale Critical Alerts to
Incidents`, `Model Retirement Workflow`, `Quarterly Access Review`, `Daily Tenant Usage
Metering`, `Monthly DR Drill`.
---
## 7. Backend functions
**998 function directories** under `base44/functions/`. Each is an HTTP handler, scheduled
job, or webhook processor.
### 7.1 Product data functions (76)
Every product view is backed by `products/get<Name>Data`. These functions:
- authenticate via `base44.auth.me()`;
- resolve the caller's `tenant_id` from `DeploymentUser` membership;
- filter every entity query by `tenant_id` (or `workspace_id` for compliance entities);
- accept an optional `ai_system_id` for cross-product scoping;
- return `{ _empty: true }` when the tenant has no data — **never** mock or hardcoded numbers;
- accept `limit` and `sort` for server-side pagination.
Pagination is provided by `src/lib/paginationUtils.js` (`buildPaginationParams`,
`buildPaginatedFilter`, `hasMorePages`, `nextOffset`).
### 7.2 Other domains
| Domain | Representative functions |
|--------|--------------------------|
| Provisioning | `provisionTenant`, `provisionTenantOrchestrator`, `createManagedDeployment`, `createDeployment`, `provisionEnterpriseGroups` |
| Billing & payments | `createStripeCheckout`, `stripeWebhook`, `pushUsageToStripe`, `billingPortal`, `processPartnerPayouts`, `paypalWebhook` |
| CRM & sales | `createZohoCRMContact`, `createZohoCRMProspect`, `getZohoCrmDeals`, `autoAssignLead`, `generateLeadIntelligence` |
| AI & LLM | `aiGovernanceAssistant`, `aiReviewAssistant`, `aiProjectMatcher`, `aiCorrelationEngine`, `aiBulkReview` |
| Curriculum & training | `fetchCurriculumFromGitHub`, `syncCurriculumFromGitHub`, `generateModuleContent`, `autoGradeAssessment` |
| Security & compliance | `secretsRotationCheck`, `scanTenantSecurity`, `runSastScan`, `runDastScan`, `verifyAuditChain`, `enforceDataResidency`, `enforceDataRetention` |
| Infrastructure | `monitorEcsHealth`, `configureAutoScaling`, `createDedicatedVpcCluster`, `createDedicatedRds`, `createDedicatedAlb` |
| Deployment | `orchestrateFullDeployment`, `deployBlueGreen`, `autoRollbackDeployment`, `scaleDeploymentResources` |
| Air gap & self-hosted | `generateAirGapBundle`, `generateAirgapRelease`, `generateEmbeddedSdkPackage`, `generateSelfHostedPackage` |
### 7.3 Observability
`src/lib/structuredLogger.js` emits JSON logs carrying `trace_id` and `span_id` for
distributed trace correlation. **Built.**
---
## 8. Row-Level Security
RLS is applied across the entity catalog — **473 entities at last audit** of 476 schemas.
Every entity uses one of five patterns, chosen by its scoping field:
| Pattern | Scoping field | Read / create / update | Delete |
|---------|---------------|------------------------|--------|
| Tenant-scoped | `tenant_id` | `data.tenant_id` = `{{user.data.tenant_id}}`, `$or` admin fallback | admin only |
| Workspace-scoped | `workspace_id` | `data.workspace_id` = `{{user.data.tenant_id}}`, `$or` admin fallback | admin only |
| User-scoped | `user_email` | `data.user_email` = `{{user.email}}`, `$or` admin fallback | admin only |
| Owner-scoped | `created_by_id` | `created_by_id` = `{{user.id}}`, `$or` admin fallback | admin only |
| Admin-only | global config | `user_condition.role = admin` | admin only |
**Prerequisite:** every User record must carry `tenant_id`. This is written by
`provisionTenant` and `setupTenantWorkspace` via `base44.auth.updateMe({ tenant_id })`.
Without it, tenant-scoped RLS cannot match and users see nothing.
Worked examples:
| Entity | Pattern | Read | Create/Update | Delete |
|--------|---------|------|---------------|--------|
| `AIIncident` | tenant | tenant + `audience ∈ {tenant, both}`, or admin | tenant or admin | admin |
| `ReviewQueueItem` | tenant | admin only (current) | admin only | admin |
| `RiskScenario` | workspace | workspace or admin | workspace or admin | admin |
| `ServiceEntitlement` | user | `user_email` or admin | `user_email` or admin | admin |
| `FeatureFlag` | admin-only | public | admin | admin |
> **Open item:** `ReviewQueueItem` is currently admin-only. Opening the tenant queue to
> non-admin tenant reviewers is a security decision that requires an explicit role list.
---
## 9. User types
Seven personas, each with its own onboarding, pricing, and entry point.
| # | Persona | Entry point | Pricing | Key functions |
|---|---------|-------------|---------|---------------|
| 1 | **Tenant Admin** (enterprise customer) | `/CustomerCommandCenter` | $2K–$15K/mo, dedicated custom | `getTenantDashboard`, `provisionTenant`, `getCommandCenterData`, `deprovisionTenantProduct` |
| 2 | **Professional Plan** (individual practitioner) | `/ProfessionalPricing` → `/ProfessionalDashboard` | $59 / $149 / $399 per month; domain add-ons $349–$499 | `createStripeCheckout`, `fetchDomainTraining`, `generateCertificate`, `getDomainProgress` |
| 3 | **Client Member** (talent buyer) | `/ClientMembershipPricing` → `/TalentBuying` | $99 / $199 / custom | `generateBidPackage`, `aiProjectMatcher`, `aiContributorMatching`, `createZohoCRMContact` |
| 4 | **Contributor** (marketplace worker) | `/ContributorIntakeEnhanced` → `/ContributorDashboard` | Free training → paid plan | `fetchCurriculumFromGitHub`, `autoGradeAssessment`, `badgeUnlockAutomation`, `runWeeklyPayoutBatch` |
| 5 | **Partner** (technology / implementation) | `/PartnerApply` → `/PartnerDashboard` | Commission-based | `routePartnerLead`, `setupPartnerWebhook`, `partnerSaleWebhook`, `processPartnerPayouts` |
| 6 | **W2 Employee** (Struxel staff) | `/EmployeeOnboarding` → `/EmployeeHome` | Salary | `zohoProvisionEmployee`, `personalizeEmployeeDashboard`, `hrPerformanceInsights`, `autoEnrollOnHire` |
| 7 | **Public visitor** | `/` | — | Marketing pages only |
**Contributor badges:** BGD-GEN, BGD-MSTR, BGD-AUD across Bronze / Silver / Gold tiers.
**Partner types:** technology, implementation, referral, marketplace vendor.
---
## 10. Current AWS infrastructure
| Resource | Current setup |
|----------|--------------|
| Compute | ECS Fargate (shared cluster), auto-scaling per service |
| Database | RDS PostgreSQL (Supabase-managed), read replicas for analytics |
| Cache | ElastiCache Redis (rate limiting, session cache) |
| Load balancer | ALB (shared, 80/443) |
| Storage | S3 (uploads, air gap bundles, evidence artifacts) |
| DNS | Route 53, wildcard TLS via ACM |
| Secrets | AWS Secrets Manager via Base44 — see [`EFICENS_SECRETS_REFERENCE.md`](./EFICENS_SECRETS_REFERENCE.md) |
| Networking | VPC, public/private subnets, security groups per tier |
| CI/CD | GitHub Actions → GHCR/ECR → ECS |
### Application-layer hooks already built for AWS services
These exist in code today; Eficens provisions the AWS side.
| Capability | App-side hook | AWS services |
|-----------|---------------|--------------|
| Data warehouse | `STAGING_DATABASE_URL` / `PROD_DATABASE_URL` configured | Redshift, Athena, Glue |
| Event streaming | `healthSse` (SSE) for real-time updates | Kinesis, MSK |
| Distributed tracing | `structuredLogger.js` with `trace_id` / `span_id` | OpenTelemetry, X-Ray |
| Rate limiting | `checkRateLimit`, `checkRateLimitWithBurst` | API Gateway, WAF |
| SLO/SLI dashboards | `getSloDashboardData` | CloudWatch, QuickSight, Grafana |
| Blue-green migrations | `validateBlueGreenMigration` (expand-contract, 6 steps) | CodeDeploy, Lambda |
| Environment parity | `generateMaskedDataset` (masks email, phone, name, address, SSN, API key, URL) | DMS, Lambda |
| Cost tagging | `applyCostTags` — `struxel:tenant`, `struxel:environment`, `struxel:cost-center`, `struxel:managed-by`, `struxel:billing-category` | Cost Explorer, Compute Optimizer |
| Secret sprawl audit | `auditSecretSprawl` — redundancy pairs and rotation recommendations | Secrets Manager |
---
## 11. Feature flags
**Built.** `/FeatureFlagAdmin` gives administrators centralised control of feature rollout,
backed by the `FeatureFlag` entity.
| Capability | Detail |
|-----------|--------|
| Create / delete flags | Unique `key`, description, enabled state |
| Toggle | `FeatureFlag.update(id, { is_enabled })` |
| Rollout percentage | 0–100% |
| Role restriction | `allowed_roles` array |
| Email allowlist | `allowed_emails` array |
| RLS | Public read, admin-only create/update/delete |
**Fields:** `key`, `description`, `is_enabled`, `rollout_percentage`, `allowed_roles`,
`allowed_emails`, `ai_system_id`.
**Data fetching:** `base44.entities.FeatureFlag.list('-updated_date', 200)`.
---
## 12. Eficens engagement scope
### 12.1 What Eficens provides
1. **AWS production readiness audit** — review the current setup against SOC 2 / ISO 27001.
2. **Dedicated AWS account** — IAM, VPC architecture, cost allocation tags.
3. **Infrastructure as code** — Terraform/CloudFormation for tenant provisioning, multi-region DR, security baselines.
4. **Cost optimization** — right-size ECS, Spot for batch, Savings Plans.
5. **Security hardening** — GuardDuty, Security Hub, Config Rules, Secrets Manager rotation.
6. **Performance** — RDS read replicas, ElastiCache tuning, CloudFront, API Gateway caching.
7. **CI/CD** — GitHub Actions → ECR → ECS blue/green with automated rollback.
8. **Data warehouse** — Redshift/Athena off operational PostgreSQL.
9. **Event streaming** — Kinesis/Kafka for alerts and incidents.
10. **Distributed tracing** — OpenTelemetry/X-Ray across services.
11. **SLO dashboards** — QuickSight/Grafana over `getSloDashboardData`.
12. **Blue-green DB migrations** — wire `validateBlueGreenMigration` into CI/CD.
13. **Environment parity** — wire `generateMaskedDataset` into the staging refresh pipeline.
### 12.2 Application-layer backlog — **complete**
| Item | Outcome |
|------|---------|
| C1 Mock-data migration | Product functions query live entities; no mock data |
| C2 `ai_system_id` filtering | Product functions filter by `ai_system_id` when passed |
| C3 `ai_system_id` on schemas | Field declared on 122 entities |
| C4 RLS policies | Applied across the entity catalog |
| C5 Custom subtab widgets | `WIDGET_TYPES` registry + `resolveWidgetType()` |
| C6 Widget auto-detection | Keyword detection + explicit override |
| C7 Schema-driven forms | `CreateRecordDrawer` reads `schema()` and generates fields |
| C8 Product alias registration | `product_aliases` on `ProductRelease` |
| C9 Pagination | `paginationUtils.js`; functions accept `limit` + `sort` |
| C10 Emerging-risk subtabs | All 17 emerging-risk functions return distinct slices |
### 12.3 AWS provisioning backlog (Eficens scope)
| # | Item | Existing app-side hook | AWS services to provision |
|---|------|------------------------|---------------------------|
| A1 | Real-time guardrail API | `generateEmbeddedSdkPackage` | API Gateway + Lambda authorizer + DynamoDB DAX |
| A2 | Cross-region DR | `setupMultiRegionFailover` | Aurora Global Database + Route 53 failover |
| A3 | Security hardening | `scanTenantSecurity` | GuardDuty, Security Hub, Config Rules |
| A4 | Audit evidence pipeline | `auditEvidenceAutoCollection` | S3 + Athena workgroup + Glue + QuickSight |
| A5 | Data warehouse | `STAGING_DATABASE_URL` / `PROD_DATABASE_URL` | Redshift + Athena/Glue |
| A6 | Event streaming | `healthSse` | Kinesis Data Streams or MSK |
| A7 | Distributed tracing | `structuredLogger.js` | X-Ray daemon + OpenTelemetry collector |
| A8 | SLO dashboards | `getSloDashboardData` | QuickSight or Grafana |
| A9 | Blue-green DB migrations | `validateBlueGreenMigration` | CodeDeploy wiring |
| A10 | Environment parity | `generateMaskedDataset` | DMS wiring |
| A11 | Dedicated tenant provisioning | `createDedicatedVpcCluster`, `createDedicatedRds`, `createDedicatedAlb` | Terraform/CloudFormation templates |
| A12 | Cost optimization | `applyCostTags` | Tag application, Spot, Savings Plans |
| A13 | Air gap automation | `generateAirgapRelease`, `AirgapDeliveryManager` | KMS-encrypted S3 + Snowball Edge |
### 12.4 Integration points
- **Secrets** — see [`EFICENS_SECRETS_REFERENCE.md`](./EFICENS_SECRETS_REFERENCE.md)
- **Connectors** — Google Calendar, Slack (OAuth-connected)
- **Workflows** — see [`EFICENS_WORKFLOW_SCHEDULES.md`](./EFICENS_WORKFLOW_SCHEDULES.md)
- **RLS** — Section 8
---
## 13. Roadmap
### Infrastructure & compliance (12–24 months)
1. Dedicated AWS account migration → SOC 2 Type II
2. Multi-region active-active (us-east-1 primary, eu-west-1 for GDPR)
3. HIPAA / FedRAMP Moderate
4. Automated dedicated tenant infrastructure
### Product & platform
1. Real-time policy enforcement via the embedded SDK
2. Full autonomous-agent governance
3. Federated learning & cross-tenant model registry (anonymised)
4. Carbon-aware AI (AWS Carbon Footprint Tool integration)
5. Visual workflow builder for tenant admins
6. ~~HITL completion~~ — **shipped (Rev 6)**: two-person approval, SLA auto-escalation, evidence export, attachments, reviewer capacity metrics (Section 5.4)
### Business
1. $8M ARR in 18 months (19 enterprise customers at $423K ACV, $5M seed)
2. Eficens as primary AWS partner; 5+ implementation partners
3. 100+ contributor placements per quarter
4. First-mover in EU AI Act tooling; 20+ jurisdictional frameworks
---
## Revision history
| Rev | Date | Change |
|-----|------|--------|
| 6 | 2026-09-24 | HITL section 5.4 closed out: two-person approval, SLA auto-escalation, evidence-bundle export, decision attachments, reviewer capacity metrics. Added `attachments` to `ReviewQueueItem`. Counts updated to 999 functions / 99 workflows. |
| 5 | 2026-09-24 | Rewritten for consistency and navigation. Added doc conventions, verified inventory, HITL section, and the Built / Eficens labelling. Corrected stale function, entity, and product-function counts. |
| 4 | 2026-09-11 | Competitive positioning, analytics instrumentation, ROI calculator, getting-started wizard, cross-product correlation hero, cornerstone blog content. |
| 3 | — | AWS infrastructure specifications, secret consolidation, cost tagging. |
| 2 | — | RLS coverage, personas, feature flag admin. |
| 1 | — | Initial architecture brief. |