History
Superseded documents, kept so the reasoning behind early decisions stays readable.
Nothing in this folder describes the system as it is today
Every page here is out of date on purpose. Do not build from these pages, quote them to staff, or treat them as a specification. If a page here disagrees with the rulebook, the rulebook is right.
The January 2026 specification set
Written before the system was built, as a plan. The behaviour they describe was partly built, partly built differently, and partly replaced during the September 2026 upgrade.
Other superseded pages
| Page | Why it is here | Replaced by |
|---|---|---|
| Serverless migration plan | The migration it plans has happened. There is no Node server; the browser talks to Supabase and enforcement lives in the database. | Architecture |
| Roles & permissions (April 2026) | Describes a "bypass tier" where CEO, GM and IT_ADMIN skip permission checks. That tier no longer exists: SUPER_ADMIN is the only role with full rights, and it holds them because every permission row is granted to it. |
PERMISSIONS.md, Access control |
Audits
Audits are findings at a point in time, not instructions, but they are not superseded — they record what was wrong and what was done about it.