TenantSage

Governance Console

property_alpha_01

Operational readiness

Governed retrieval is active for approved property knowledge, role-scoped users, and audit-reviewed query paths.

Checking Firebase session...

Substrate Active Open AI Test Bench
Workspace tier Starter

Firestore family tier is present; payment enforcement must remain server-side.

Usage counter Tracked

Monthly query counts are modeled under each family workspace.

Audit status Valid

Allow and deny paths are recorded for review.

Governed Controls

Every source and chunk must remain inside Firebase-authenticated family, role, legal-hold, effective-window, and audit controls.

Run Test Bench
Control Firebase Path Enforcement Status
Identity-derived scope users/{uid} familyId + role Required
Governed source access families/{familyId}/rag_sources visibility + window Indexed
Vector chunk boundary families/{familyId}/rag_chunks source + property Indexed
Usage and tier gates families/{familyId}/usage query count Modeled

Latest Decision Trace

{
  "action": "RAG_ALLOW",
  "user": "staff_001",
  "scope": "property_alpha_01",
  "retrieval": "approved_sources_only",
  "audit": "logged_before_retrieval"
}