Maintenance Online EC
Previewing console as: Admin— admin-only screens are visible; superadmin controls hidden.

Dashboard

Real-time platform health. Everything an operator checks first.

All systems operational Last checked 12s ago · standby warm on :8095
Maintenance mode
build 2026.07.16-a3f9c1smoke pass· 24/24 checksView test log →
Transfers total
18,442
+312 this week
Claimed
14,907
80.8% claim rate
Active users
1,284
23 pending registration
Errors (24h)
7
2,109 total in log
Pending registrationsView all →
nadia@northwind.io — Team tier4m
t.okafor@ravel.dev — Pro tier38m
sam@lumen.studio — Team tier2h
Recent errorsView all →
StripeWebhookError · /webhooks/stripe11m
TimeoutWarning · db.list_transfers1h
KeyError · storage.region_for_country3h
Recent audit activityView all →
EC approved claim request HAVVPX6m
EC minted access code LAUNCH5022m
system graduated 3 EAP applicants to active1h
EC rolled org invite link · Northwind2h

Transfers

Cross-org, cross-user view of every relay on the platform.

1–8 of 18,442
TitleCodeStatusOrgUserAgeSizeActions
Q3 onboarding handoffHAVVPXactiveNorthwindusr_8f3a4m12.4K
Migration runbook v2PMHUK3claimedRavelusr_2c191h48.1K
Design review — v3.5-a4TNE7KactiveRelay Contextusr_00012h31.7K
Incident postmortemA4K9R2claimedLumenusr_71bd5h9.8K
Sprint plan draftQNHC2CexpiredNorthwindusr_8f3a3d6.2K
Client brief — Ravel7HZQAXclaimedRavelusr_2c193d22.0K
Weekly sync contextFFFC90activeLumenusr_71bd4d14.9K
Deprecated payload testZX01QPdeletedRelay Contextusr_00016d1.1K

Users

Every account across every org. Search, inspect, suspend.

1–7 of 1,284
NameEmailOrgRoleSetupCreatedActions
Erik Christensenerik@relayctx.comRelay Contextsuperadmin100%Feb 2026
Nadia Fourniernadia@northwind.ioNorthwindmember60%Jul 2026
Tunde Okafort.okafor@ravel.devRavelowner100%Jun 2026
Sam Ihejirikasam@lumen.studioLumenmember30%Jul 2026
Priya Ramanpriya@ravel.devRavelmember100%May 2026
Marco Bellimarco@northwind.ioNorthwindowner100%Apr 2026
Lena Voslena@lumen.studioLumensuspended100%Mar 2026

Account migrations

Merge one account into another, or split an address into a fresh one. Dual consent, journaled, tier-1 only — nothing executes until every required consent is in.

4 migrations · 1 ready to execute
KindSource → TargetConsentStatusCreatedActions
merge erik@erikchristensen.ca → erik@relayctx.com
2 emails · 4 grants · 1 membership move — founder consolidation
1 / 2 awaiting consent 2h
split lena@lumen.studio − freelance@vos.dev → new account
address detaches · data stays with owner · fresh account invited
1 / 1 consented 1d
merge sam@oldstudio.io → sam@lumen.studio
executed by usr_0001 · workspace admins notified (Lumen)
2 / 2 completed 6d
merge nadia@personal.me → nadia@northwind.io
declined by source · everyone notified · nothing changed
0 / 2 cancelled 8d
state machinedraft → awaiting consent → consented → executing → completed · exits: cancelled / expired / failedtier-1· every action audit-logged · consent links are signed pointers, action requires sign-in as the party

Claim approvals

Cross-user claim requests waiting on an operator decision.

3 pending · 1 urgent
NF
Nadia Fournier requests HAVVPX
nadia@northwind.io → owned by usr_0001 (Relay Context)
4m ago
TO
Tunde Okafor requests PMHUK3
t.okafor@ravel.dev → owned by usr_71bd (Lumen)
1h ago
SI
Sam Ihejirika requests FFFC90
sam@lumen.studio → owned by usr_71bd (Lumen)
6h ago

Access codes

Typed fast-tracks on the early-access form — the invite and referral classes, seen from the code side. Every code also mints its own tracked link at /x/{CODE}, which is why it shares the campaign handle space.

5 codes · 2 active
CodeLabelCampaignShare linkUsesStatusActions
Two columns, two jobs. label is the human name; campaign_slug is the attribution key. Today they are the same field — so a code called "Elevate Festival" drops out of its campaign's panel, and a campaign-scoped code cannot be given a name. Share link is the part that surprises people: minting a code also mints /x/{CODE}, so a code and a campaign slug spelled alike are one key in one space, and /x/ resolves campaigns first.

Roles & access

Who can do what, platform-wide. Capabilities are code-owned; roles group them. Org-scoped RBAC is delegated to org admins in the app.

Platform capabilities × platform roles. System roles are locked.
3 platform roles · system, locked
Capabilitysupportplatform_adminsuperadmin
Users · platform.users.manage✓✓✓
Transfers (global) · platform.transfers.view✓✓✓
Claim approvals · platform.approvals.manage✓✓✓
Orgs admin · platform.orgs.manage—✓✓
Finance · platform.finance—✓✓
Flags · platform.flags—✓✓
Maintenance · platform.maintenance—✓✓
Roles & groups · platform.groups.manage—✓✓
Force connect · platform.force_connect——✓
Tier-1 destructive · platform.tier1——✓+ELEV
Tier-1 capabilities require a short-lived elevation token (step-up re-auth) on top of the role — the same second factor the console uses today for destructive actions.
Org-scoped RBAC is delegated. Org admins manage their own groups & roles self-service in the app (Team → Roles & Groups), bounded to their org and their own permission ceiling — they can never grant platform capabilities. One capability model, two planes. Spec: briefs/SPEC.rbac.md.

Investor track

Provision access, map packs to people, and evidence compliance — who holds what, under which signed version, and when they last looked. Pack IDs are opaque and never leave this screen or the Access policy.

Tier-1 surface. Guarded by check_tier1 — superadmin and platform_admin only, never general check_auth. Its web counterpart is founder-only; the console must not be looser. Signature status and version render here; the executed PDF is fetched only on explicit request, never inline in a list.
6 in the register · 1 flagged
InvestorLensPackNDAToSTierLast accessActions
Erik Christensenproduct investorQX7M4Dv1.2Feb 2026NDA2h ago
A. SorenseninvestorK4RZ7Qv1.2Jun 2026NDAAug 5
M. DelacroixinvestorP9WX2Mv1.1 — staleMay 2026access, no current signatureAug 6
R. NakamurainvestorH3JD8Vv1.2Jul 2026OPENJul 31
L. FerreirainvestorB6QT4NunsignedJul 2026OPENnever
T. AbiodunrevokedC2YL5Sv1.1Mar 2026—Jul 12
Every name and pack ID on this screen is synthetic. This repo publishes — main is production, no build step — so a real pack ID beside a real name would put the exact mapping this screen exists to protect onto a static site. Prototypes get invented data; the register is the only place the real mapping lives.

Pack IDs stay opaque. Six characters, A–Z0–9 — never a name, initials, or firm, in a URL, page title, filename, or log line. The pack ↔ person mapping exists in the register and the Access policy, nowhere else. T. Abiodun shows the rule that exemption never rewrites history: access is revoked, the signed v1.1 acceptance row stays forever.

Campaigns

One entity, four classes — every tracked acquisition surface, whichever door someone arrives through. Slugs and codes share one handle space, so a new one is refused at mint (DEC-030).

Active campaigns
3
of 8 across 4 classes
Arrivals
0
clicks + code redemptions
Signups
0
— arrival → signup
First transfers
0
— of signups activate
8 campaigns · 3 live
HandleClassAccessTrackTagsStatusFunnelConvSignupsActions
DEC-030 — what this screen now shows: the four things the word "campaign" named are one entity with a class column, not three screens sharing a name. A campaign is the thing tracked; a route is how someone arrives — so /i/ keeps its own door and beta_codes keeps its own table. Tags carry the grouping, which is what lets Track (formerly Angle) go optional behind a General default. Access is the third axis (§8): class is how someone arrives, Track is what voice the relay uses, Access is what they get — and a trial length exists only on a plan-aligned trial, because EAP's tier has nowhere to put one. Kill switch: pausing or expiring goes dark everywhere — /x/{handle}, personalize and verify all 410 (#1896).
One handle space— handles
Why this panel exists. /x/{code} resolves campaign → short link → relay Code, in that order, so a campaign slug silently shadows an access code spelled the same way. On 2026-08-01 an audit found four access_code_share rows already colliding with live transfers, and the Elevate work order still mitigates it with a spelling convention — "not ELEVATE26 … the hyphen keeps them apart". Handles are compared case-folded: the card printed /x/elevate-2026 while the code minted /x/ELEVATE-2026, and only one of those resolved.

ai-leaders

Demo relayctx.com/x/ai-leaders ↗ product track · 14-day trial · created Jun 2, 2026

Live — accepting signups expires Sep 30, 2026 · Turnstile + rate limits on personalize & verify
Live
Landing funnel96 / 250 signups
Live demo & activation
Access codes · campaign_slug = ai-leaders+ Generate →
Scoped by the campaign_slug column, not by overloading label — so a code can be named and scoped at once. Today one field does both jobs and the console filters it with a Python string compare, so naming a code costs you the campaign link.
Access · what the signup gets
Handle · route
One campaign, several doors. Every row here is the same tracked thing — which is why they share attribution columns and why the class, not the prefix, says what it is.
Event loglast 100
TimeEventSessionDetail

Screen

Specced in the console screen audit.

On the map, not yet skinned

This screen is part of the 36-screen console and is fully specced in AUDIT.console-v35.md. This prototype builds the shell plus the canonical screens (Dashboard, Transfers, Users, Claim Approvals, Access Codes, Roles & access, Campaigns) as the v3.5-a pattern-setters.

The re-skin of the remaining screens is tracked as Linear issues under the console epic (RCTX-705, batches RCTX-706–712).

v3.5-a re-skin · planned