START HERE

GCD-OHR-029 evaluates trusted server facts. It does not authenticate users or grant cross-tenant access.

  1. Read the README security boundary.
  2. Complete Sections A through G in order.
  3. Run all 16 tests and the example.
  4. Define exact roles and permissions without wildcards.
  5. Integrate only behind server authentication.
  6. Verify database tenant filters, session revocation, every denial, and rollback.
  7. Use a timer only for a deliberate cancellable deployment sequence; delayed work must reload facts and reauthorize.
  8. Use the Floot Update/Publish control only after every gate passes.

Final step — Publish your changes. When your build is ready, use the Floot Update/Publish control to push the latest version live. Until you publish, visitors may still see the previous version.