START HERE
GCD-OHR-029 evaluates trusted server facts. It does not authenticate users or grant cross-tenant access.
- Read the README security boundary.
- Complete Sections A through G in order.
- Run all 16 tests and the example.
- Define exact roles and permissions without wildcards.
- Integrate only behind server authentication.
- Verify database tenant filters, session revocation, every denial, and rollback.
- Use a timer only for a deliberate cancellable deployment sequence; delayed work must reload facts and reauthorize.
- Use the Floot Update/Publish control only after every gate passes.
Final step — Publish your changes. When your build is ready, use the Floot Update/Publish control to push the latest version live. Until you publish, visitors may still see the previous version.