Feature Control Command Center

What changes for whom? Preview impact, roll out safely, and keep critical control human-approved.
PRE-MERGE • DEMO DATA

Observability & Incident Intelligence

Advanced SLOs, error budgets, correlation and incident grouping underneath. One simple operational surface.
Loading observability…

Safe Incident Injection

PRE-MERGE telemetry only. Does not change Orders, money, products or stock.

SLO / Error Budget

Loading SLOs…
Fast burn means the error budget is being consumed unusually quickly. SLO changes affect monitoring only, never business behavior.

Reliability Control Plane

Advanced worker, retry and dependency safety underneath. Simple controls here.
Loading reliability controls…

Failure Injection Test

Safe PRE-MERGE test: changes only dependency-health simulation, never Orders, money or stock.

Core Commerce Promise

✓ Orders continue if AI is down
✓ Inventory/warehouse continue if analytics is down
✓ notification failures queue safely
✓ payment retries require idempotency
✓ critical jobs cannot be discarded silently
✓ AI may recommend retry priority but cannot execute critical retries

Authentication & Device Trust

Production-login readiness underneath; easiest provider/device/session controls on the surface.
Security Health
Loading identity providers…

Test Independent Login

PRE-MERGE contract test only. Production will receive identity/MFA/passkey assertions from the configured provider.
No test login yet.

Safe Provider Outage Test

When the provider is DOWN, new privileged login is blocked. Existing authorized sessions do not receive extra lifetime; they only continue until normal idle/absolute expiry.

Devices & Sessions

Loading devices…

Super Admin Governance

Multiple trusted Super Admin identities for true four-eyes approvals. MFA and audit always stay active.
Approval Inbox
Loading Super Admin members…

Add Super Admin Member

Invite tokens are displayed once for this local PRE-MERGE test and stored only as hashes.

Emergency Access Mode

Important: Emergency mode does NOT bypass MFA, permissions, approval rules or audit. It only creates a visible time-limited emergency state for incident handling.
Checking emergency state…

Persistent Access Policy

Current access survives restart. Draft safely, preview exact diff, publish, or restore a previous revision.
Loading policies…

Policy Draft / Preview

Choose a staff member and preview changes.

Policy Safety Rules

✓ Deny overrides Allow
✓ High-risk permissions may require dual approval
✓ Fresh re-auth before publish
✓ Published changes revoke stale sessions
✓ Every publish creates a revision
✓ Previous revision can be restored
✓ AI can recommend but never publish

Add Admin Staff — Identity & Security

Create identity → issue one-time invite → accept → enroll MFA → activate. No shared password.
Safe onboarding
Invite tokens are shown once for this local PRE-MERGE test. The identity database stores only their SHA-256 hashes. Production email delivery is not enabled here.

Identity Lifecycle

Persistent PRE-MERGE identity records. Permissions remain controlled by the delegated Admin engine.
Loading identities…

Delegated Admin Access

Super Admin stays master. Staff get least privilege, limits, scopes and automatic expiry.
Loading staff…

AI Least-Privilege Assistant

Describe the job in plain language. AI prepares a recommendation only — it cannot grant access.
No recommendation yet.

Permission Levels

VIEW — see authorized data
MANAGE — work/update authorized records
APPROVE — approve controlled high-risk actions

Separate controls: Export • Reversible Archive • Refund limit • Payout limit • Warehouse scope • Vendor scope • Temporary expiry.
Permanent destructive Delete is intentionally not included in default delegated roles.

Preview As This Admin

Read-only preview. It never changes the Super Admin session or performs business actions.
Choose a staff member.

Separation of Duties

The system warns when one delegated Admin can both create/manage and approve the same sensitive flow — especially payouts, refunds, access control or security.

Delegated Admins cannot grant themselves higher access. Super Admin approval + fresh re-auth is required for permission publishing.

Role Templates

Loading templates…

Feature Control Command Center

What changes for whom? Advanced dependency, targeting, rollout and D10 safety underneath — one simple control surface.
Loading feature control health…

1. Choose Feature

Choose a feature.

2. Simple Configuration

3. Impact & Approval

Preview before applying. Critical changes will clearly show D10 Four-Eyes requirement.

4. Emergency Safety

Emergency Pause is defensive.
It turns evaluation OFF without deleting the published configuration. Resume stays controlled and critical features require exact D10 approval.

Smart Rollout Safety

Draft

No live change.

Impact Preview

Dependencies + blast radius.

D10 if critical

Exact plan Four-Eyes.

Publish

New immutable revision.

Restore / Pause

Safe recovery.

AI is advisory only — zero publish authority.

Advanced Rollout Governance

Who is affected? What depends on this? What does evidence say? What should I do next?
PHASE 2 • HUMAN CONTROLLED

Impact Graph + Cross-Role Preview

Choose a feature, then inspect who changes and what depends on it.

Guarded Rollout Plan

No rollout plan yet.

Rollout Health Evidence

Evidence decides whether Admin should advance, hold, or review.

Lifecycle + Schedule Intelligence

Temporary flags show owner, retire-by and cleanup guidance. AI is advisory only.
Guarded rollout safety: cohort membership stays deterministic for the rollout. Health evidence may recommend PAUSE / HOLD / ADVANCE, but AI has zero advance, rollback or publish authority. Critical rollout start requires exact D10 Four-Eyes approval.

Unified Feature Safety Gate

One answer before you act: Is this feature safe, waiting, stale, paused, or integrity-blocked?
FINAL D16 GATE • READ-ONLY INTELLIGENCE

Safety Preflight

Choose a feature. D16 will correlate configuration, dependencies, D10 evidence, rollout, schedules, lifecycle and integrity.

Final Feature Control AI

AI explains evidence and the safest next action. It has zero publish, rollout, rollback, payment, stock or permission authority.
Simple status: READY • WAITING APPROVAL • ACTION REQUIRED • REPLAN REQUIRED • EMERGENCY PAUSED • INTEGRITY BLOCKED. Advanced evidence stays underneath; the Admin sees what matters now.

Master Feature Controls

FeatureStateScopeAdmin control
Marketplace Master ONGlobal
Vendor Dashboard ONGlobal + seller override
Vendor Finance View OFFGlobal + role permission
Storekeeper Dashboard ONGlobal + location override
Receive / Pick & Pack / Count Stock ONWarehouse location
AI Recommendations ONAdvisory only
Primary dashboards
3
CONNECTED
Controlled feature groups
12
AUDITED
Production integration
WAIT
.86.5.1 REQUIRED

One Connected Route Map

Main Admin

/admin

Vendor

/vendor

Storekeeper

/warehouse

Orders

linked work

Inventory

shared safe truth

Important: These are different role views inside one KizzdayTech platform — not separate websites or databases.
RouteDashboardRequired featureSecurity
/vendor/ordersVendorVendor DashboardDeny default + server auth
/vendor/financeVendorVendor FinanceRole + feature + server auth
/warehouse/receiveStorekeeperWarehouse ReceiveRole + seller/location scope
/admin/feature-controlMain AdminSuper Admin onlyFresh auth for critical publish

View As Role

Super Admin can preview how a Vendor or Storekeeper sees the system.

Vendor Preview

TechBay Electronics • read-only

Storekeeper Preview

Lisbon Warehouse • read-only

Safety Rule

View As Role never becomes that user.

No write authority. No authorization bypass. No payout/refund/stock action through preview.

✓ read-only

✓ seller/location scoped

✓ expiry

✓ audited access

Safe Configuration Lifecycle

1. Draft

Nothing live changes.

2. Preview

Show before/after impact.

3. Confirm

Critical controls require explicit confirmation.

4. Publish

Creates immutable version.

5. Restore

Restore verified previous version.

Example: Disable Vendor Finance for one seller only → preview → reason → publish → audit. Other sellers stay unchanged.

What is protected now

✓ Marketplace OFF preserves direct store

✓ Vendor A / Vendor B isolation remains authoritative

✓ Storekeeper least privilege remains

✓ Unknown route denies by default

✓ View-As-Role is read-only

✓ Feature changes are versioned/audited

What is still NOT live

Production merge is not complete.

Exact protected V4.4.9.86.5.1 application source is still required before wiring these contracts into the real website.