Command Center Frontend — Production Status (2026-08-07)
Measured: 2026-08-07 ~20:30 UTC, HTTP smokes from a source-checkout session
(no gcloud available — control-plane facts are explicitly NOT re-verified here).
Prior snapshot: the 2026-08-06 posture recorded in
FRONTEND_VERIFICATION.md §23.1/§26 (the completion prompt referenced a
2026-08-06 report file that was never created; this dated report is the
sibling it asked for). Claim labels: every row below is a verified
result of the named probe, nothing more.
1. Measured surface (all fresh probes)
| Probe | Result |
|---|---|
GET / /command-center /command-center/approvals /login /domains /intent |
200 each |
GET /api/bff/approvals/pending (unauth) |
401 tenant_required — honest fail-closed, body names the session-tenant contract |
GET /api/bff/registry/status |
200, every governance service configured: false |
GET /api/bff/boss/cells/health |
200, deduped 36-cell roster (healthy 19 / unhealthy 17 at probe time — cells answering unauth 403 are IAM-locked-healthy per the failure-class table, not outages) |
Divergence from 2026-08-06: none observed on the probed surface.
2. Not measurable from this session (operator verification asks)
latestReadyRevisionName == latestCreatedRevisionName+ which revision serves traffic (GOVERNANCE 6.1) — needs gcloud. §23.1 measured that the standalone bundle armsREQUIRE_AUTH=truewhile live behaves flag-off, implying the serving revision may predate the arm commit; still unresolved.- Env posture on the serving revision (REQUIRE_AUTH / SUPABASE / FIREBASE / NEXT_PUBLIC_BOSS_AGENT_URL presence).
3. What changed in the tree this session (implemented, riding the routed deploy — NOT live-verified)
- Role-gated mutation BFF: approvals approve/deny (approver/admin), action redeem/rollback (operator/admin); verified-session actor; BFF-side cross-tenant gates; untranslated 409/403/501 refusals.
/api/auth/whoamisession view + shell SessionIndicator (server-derived environment/enforcement/tenant/role; fictional env/region dropdowns retired).- Job-oriented IA: Command Center leads, governed-pathway child order, Events→Evidence rename.
- KG ledger browsing (bounded, on-demand, thin-Boss-ledger source labeled); learning center composed from outcomes + audit-recent.
- 2D step-7 ratchet 8→10 (usePathMetrics, CooldownMonitor); seven 0-importer modules archived.
Full evidence: docs/frontend/FRONTEND_VERIFICATION.md §29 (Run B) and §28 (Run A).
4. Wave O — operator/owner actions that gate live truth
- Governance redeploy (
ops/remediation/deploy_all.sh) → flips/api/bff/registry/statustoconfigured: true; every 1D live section and the new mutations then read/exercise real backends. Until then the UI stays tri-state UNAVAILABLE with exact reasons (by design). - Supabase credentials +
REQUIRE_AUTH=trueon the serving revision (confirm delivery mechanism:--set-env-varsvs image bake), roles intoapp_metadata(approver/operator/admin), then retire the spoofable legacy page-availability bridge. - HD-3 staging tenant before any production mutation e2e.
- HD-2 P1 / HD-5 owner decisions (permanent deletions after retention
window;
apps/webretirement). - Control-plane check from §2 (serving-revision identity + env).