Close Vergabe binding and record remaining recovery blockers
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e3b3-11fe-7ba0-a4a3-92331aab0ba1
This commit is contained in:
parent
1839c0ba42
commit
cfbc95e11d
6 changed files with 136 additions and 36 deletions
|
|
@ -9,8 +9,9 @@ the historical deployment is still live.
|
|||
|
||||
Before native admission, record the following non-secret values in the company
|
||||
binding. The user selects a fresh `demo-company` workspace; see
|
||||
[its prepared binding](vergabe-demo-company-binding.md). Native tenant/user/password setup is verified; application hostname admission
|
||||
and product placement remain pending.
|
||||
[its prepared binding](vergabe-demo-company-binding.md). Native tenant/user/password setup, hostname admission and product placement are
|
||||
verified. The binding task closed on 2026-09-27; recovery and recipient
|
||||
acceptance remain blocked in the existing tasks.
|
||||
|
||||
| Binding | Required evidence |
|
||||
| --- | --- |
|
||||
|
|
@ -72,20 +73,21 @@ HA is not claimed.
|
|||
|
||||
## Manual onboarding and acceptance
|
||||
|
||||
Use the existing Django administration via the admitted operator path to create
|
||||
ordinary active members. Keep staff/superuser access with the designated
|
||||
operator. Supply initial credentials over the existing private human channel;
|
||||
never paste them into Git, State Hub, command arguments or chat. Members can
|
||||
change passwords in the UI; operators handle reset and deactivation manually.
|
||||
Do not run `seed_dev` on a pilot/customer database.
|
||||
The current demo-company release uses NetKingdom OIDC and the company welcome
|
||||
flow. Provision ordinary members through the native User Engine journey and
|
||||
have each invited recipient complete their own login/MFA and confirmation.
|
||||
Do not substitute shared Django passwords or staff identities for this gate.
|
||||
The founder's September 24 sign-in is recorded; a fresh recipient journey and
|
||||
two-user acceptance remain VERGABE-WP-0019-T04/T06. Never place credentials or
|
||||
setup links in work records, and do not run `seed_dev` on a pilot database.
|
||||
|
||||
Before admitting the first users, verify HTTPS login, CSRF failure behavior,
|
||||
anonymous document refusal, two separate user sessions and deactivation of an
|
||||
already logged-in account. Complete the tender → lot → task/document → domain
|
||||
approval → submission workflow and feedback with the company contact. Customer
|
||||
support contact, incident routing and backup responsibility must be recorded.
|
||||
Pricing, automated invitation email, SSO and shared tenancy can be considered
|
||||
later; none is implied by this initial pilot contract.
|
||||
Pricing, automated invitation email and shared tenancy remain outside this
|
||||
pilot contract. SSO is deployed; recipient acceptance remains a separate gate.
|
||||
|
||||
## Current inventory — 2026-09-11
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue