Pilot status: Sign-in is available for invited users. This static pilot has no migrated business data and server-side route protection is not yet enabled.
Prototype — no controlled-source inventory connected. This is a static UI scaffold only. It is not a system of record and holds no real asset records.

Link / Index — Not Copy

The Governance Library does not duplicate document bodies. Controlled source assets live in their canonical locations — GitHub repositories and organization shared storage. This library stores metadata records that point to those sources: asset name, source link, version or commit SHA, classification, owner, review date, and disposition. Copying a document into the Portal creates an uncontrolled duplicate; linking preserves a single version history and a single source of truth.

Asset Record — Field Reference

FieldDescriptionValue
Source AssetName or identifier of the controlled source document or repository object.—
Source LinkCanonical URL or path to the asset in GitHub or organization shared storage.—
Version / CommitVersion tag, commit SHA, or document version at time of indexing.—
Classification / SensitivityAccess tier: General, Restricted, or Confidential.—
OwnerRole or individual responsible for the asset.—
Review DateNext scheduled review or last-reviewed date.—
DispositionCurrent disposition code: Link/Retain, Migrate, Archive, or Retire.—

No asset records are indexed in this prototype. Real inventory connects after authenticated RLS/audit validation passes and a controlled migration packet is approved.

Permissible Disposition Values

Migrate

Governed metadata or workflow data will be migrated into a Portal record. The original source file is retained. Migration requires auth/RLS/audit gate approval.

Archive

Retained for provenance and version history. Excluded from active search, templates, and operating views. No operational use without founder approval.

Retire

Operational use disabled after founder approval and confirmed replacement. Asset record is preserved; it is never deleted from this register.

Source Posture & Access Model

GitHub

Canonical source for code, versioned migrations, and configuration. Portal records link commits and releases; source code stays in GitHub.

Organization shared storage

Canonical source for strategy, process, SOP, and decision documents. Portal indexes metadata and source links; document bodies are not copied.

Version history

Every indexed asset record should carry a version tag or commit SHA. Prior versions are preserved as version history, not overwritten.

RLS / future server authorization

Current navigation is static and for UI convenience only. Real access control for restricted and confidential assets requires RLS and future authenticated server authorization. Navigation alone is not a security boundary.

RLS & Authentication Status

Authenticated RLS/audit tests

Blocked by Supabase email rate limit. Password-recovery, unapproved-user, test-organization, audit-trigger, and cross-organization tests are required before any real or sensitive inventory is connected.

Read-only security posture

Nine public tables show RLS enabled; all tables empty; security advisor returned no findings as of 2026-08-06.

Navigation is not a security boundary

This static prototype is UI convenience only. Restricted and confidential assets require explicit grants enforced by RLS and future authenticated server authorization — not sidebar visibility alone.

Controlling Sources

  • intofocus_portal_build_control_and_migration_register_v0_1.md— defines build sequence, migration gates, and the link/index-not-copy rule.
  • intofocus_portal_asset_disposition_register_v1_2026-08-05.md— asset-by-asset disposition inventory and migration controls.
  • intofocus_portal_information_architecture_and_tenancy_v0_1.md— Portal organization, tenancy controls, role model, and navigation rules.
  • intofocus_portal_now_next_later_v0_1.md— current Portal program status and decision log.

Source document bodies are not reproduced here. The filenames above are references only; they are stored in canonical shared storage and GitHub.