Multi-site operations

Today

Loading registry Loading capabilities
Loading meeting delivery…

Churchill Operator Path

Known-good site
Churchill operator path unavailable

Completion Cue

Review focus

Primary Operator Path

Read-only guide
Operator path unavailable

Today

0 meetings

Needs Attention

Sites and runs

Operation Readiness

Read-only

Hosted Read Proof

Read-only

Selected Site Evidence

Read-only

Rollout Readiness

Read-only

Meeting Readiness

Read-only

Finalization Readiness

Read-only

Activity Operations

Read-only
Activity operations summary unavailable

Notification Handoff

Read-only
Notification handoff unavailable

Notifications / Activity

0 items

Activity Source

Read-only
Source metadata unavailable

Selected site

Guided site workspace

Choose an area to continue setup

People

Contacts, operators and meeting assignments.

Devices

Basestation, Clerk pairing and observed status.

Cameras

Camera inventory, PTZ readiness and presets.

YouTube

Verify the selected site’s channel and destination.

Open YouTube

Commissioning

Generate bounded packages and complete the final rehearsal.

Open commissioning

Churchill Operator Page

Known-good site
Churchill operator summary unavailable

No-Code Site Setup

Read-only
No-code site setup summary unavailable

Client / Producer Operations

Read-only
Client / producer operations unavailable

Sites

0 sites

Site

Unknown
Select a site to review edge roles

Complete Operation Readiness

Select site
No site selected

Site Rollout Checklist

Select site
No site selected

VOD / Caption Handoff

Select site
No site selected

Onboarding Package

Select site

Guided site workspace

Select site

New-site workspace

Guided task list
  1. Identity and routes
  2. People and assignments
  3. Basestation and Clerk pairing
  4. Cameras and PTZ
  5. Audio — choose exactly one

    RM-CR/RM-WAP addresses, credentials, mappings, Windows capture identifiers, channels, gain, and delay stay on the Basestation.

  6. Sources and ProgramOut
  7. YouTube destination
  8. Recording, finalization, and VOD policy
  9. Final rehearsal
No configuration snapshot loaded

YouTube destination

Not connected
Connect the selected site to its authorized YouTube channel. Offline OAuth remains backend-only and permits verified destination reads plus reviewed description-block updates; Nindeo does not upload or delete YouTube videos through this connection.

No provider request has been made.

Packages contain bounded non-secret intent only; camera, ADECIA, analog capture, and provider secrets stay local.

Generate a package to prepare the exact post-install command.
No package generated
No desired/observed snapshot loaded

New Site Draft

Read-only
1
Site Inputs Profile, timezone, template, and edge roles
2
Preflight Setup path and source fit
3
Review Package Preview and read-only proof
Setup path not loaded
Template details not loaded
No draft generated
No draft generated

Site Registry Source

Read-only
Source metadata unavailable

Site Edge Readiness

Select site
No site selected

Site Device Inventory

Select site
No site selected

Readiness Reasons

Select site
No site selected

Site Readiness Return Cue

Select site
No site selected

Real Site Rehearsal

Select site
No site selected

Site Setup Evidence

Select site
No site selected

Site Template Preview

0 templates

No-Code Site Setup Readiness

0 templates

Template Requirements / Site Defaults

0 templates

People Operations

Read-only
People operations summary unavailable

People Access Handoff

Read-only
People access handoff unavailable

Role Coverage

Read-only

People Directory

0 people

Assignment Coverage

Select meeting

Assignment Source

Read-only
Assignment source metadata unavailable

Device Check-ins

0 devices

Status refreshes every 60 seconds while this view is open.

No device recovery assessment loaded
Device Site Edge App Last Check-in Session Checks State
No clerk devices loaded
Device status source unavailable
Device operations summary unavailable
Loading meeting delivery…

Meeting Operations

Read-only
Meeting operations summary unavailable

Meeting Schedule

Read-only calendar
Meeting schedule unavailable

Meeting Runs

0 meetings

Run Detail

Select meeting

Run Source

Read-only
Run source metadata unavailable
Loading library…

Review Target

Read-only

VOD / Caption Operations

Read-only
Finalization operations summary unavailable

Finalization Jobs

Read-only status

VOD / Caption Detail

Select run

Finalization Source

Read-only
Source metadata unavailable

Reviewed Publication

Database claim gate unknown

Generation, artifact upload, and YouTube description publication are separate states. This queue cannot activate its worker.

No publication jobs loaded
Policies

Clear, reviewed operating rules

Site configuration, meeting delivery, retention, captions, transcripts and publication remain versioned and reviewable.

Access

People and permissions by site

Global Admin, site Admin, operator and client access remain governed by the existing site-scoped roles and assignments.

Integrations

Connected services without exposed secrets

YouTube, VOD and caption connections stay within their existing provider contracts; credentials remain backend-only.

Settings Readiness

Read-only
Settings readiness unavailable

Settings Operations

Read-only
Settings operations summary unavailable

Settings Handoff

Read-only
Settings handoff unavailable

Integration Ownership

Read-only
Settings boundary unavailable

Technical audit

Implementation and rollout evidence

Hidden from primary operations

Readiness evidence, source metadata, framework bindings, route ownership, hashes and implementation boundaries live here without interrupting everyday work.

Captions

Authenticated private-caption verifier

Read-only verification for one exact channel and meeting. This control exposes cue counts and hashes only; it cannot write captions, reveal credentials or create a transcript revision.

Enter the exact channel and meeting to run a signed-in read-only check.

Meetings

Selected-meeting technical evidence

Select a meeting to load its technical evidence.

Product Boundaries

Accepted split

Next Build Slice

Safe path
  1. Current build lane: the read-only Admin MVP path now connects Command, Sites, Devices, Meetings, VOD / Captions, Settings, Site Onboarding, and Site Draft while accepted registry rows feed existing GET /api/admin/sites, accepted device rows feed existing GET /api/admin/devices, fixture fallback and source metadata stay visible, and selected edge export reads remain the safe alternate behind GET /api/admin/device-status.
  2. Real-site rehearsal is active: Churchill remains the known-good baseline, the accepted queue drives South Lake Tahoe, Douglas County, TDPUD, RTC, Incline Village, and future site review, and the first create-site write package stays feature-gated local proof only.
  3. Next safe slice: keep operator-reviewed package work on existing Admin surfaces through site rehearsal, the Site Draft review stack, metadata checklist, reviewed package handoff, promotion manifest, reviewed diff preview, accepted-registry contract, source-of-truth check, diff hygiene, and draft PR review.
  4. Stop before production persistence, automatic Git actions, write flag enablement, live controls, VOD/caption generation, deploys, restarts, SSH, duplicate endpoints, local config writes, or secrets.

Admin Completion Tracker

Convergence gates
Ready Read-only MVP shell Command, Sites, Devices, Meetings, VOD / Captions, Settings, Activity, People, Onboarding, and Site Draft are connected through existing Admin reads.
In progress Real data exit Move selected fixtures and samples to accepted read files or selected edge exports only through existing contracts and routes.
Handoff reviewed Churchill selected-export proof Selected-export review reports basestation ready and clerk source-ready; no Clerk install is needed for this proof step.
Active rehearsal SLT selected-export cue Site Draft and Device Status now name the next reviewed edge export input while keeping review on GET /api/admin/device-status.
Browser pass complete Visual operator pass Browser-smoked Command, Activity, Sites, People, Devices, Meetings, VOD / Captions, Settings, and Focus at desktop 1440x900 and mobile 390x844 with no console errors or global overflow; hosted Admin cue is visible in Command evidence and Sites detail.
SLT package proof held Real-site path South Lake Tahoe is rehearsed through accepted registry, Site Onboarding, Site Draft package preview, expected accepted-row collision blocking, disabled duplicate/default write routes, and unchanged registry proof.
Approved bridge Hosted Admin mapping The first hosted bridge is approved only as read-only mapping from the accepted registry into hosted Admin planning; production persistence, live controls, deploys, restarts, and VOD/caption execution remain locked.

Complete Operation Checklist

8 done / 7 remaining
First deliverable Read-only MVP complete Hosted read-only Admin MVP is the current complete deliverable after accepted runtime smoke, Git-reviewed read artifacts, and core read-surface coverage.
Operation status Not complete Complete operation still needs real edge evidence, Producer context approval, real data cutover, write-lane approvals, VOD/caption execution approval, live-control approval, and deploy/runtime approval.
Safe next work Review, do not execute Allowed without new approval: source-only tests/docs/contracts, operator-collected redacted edge export evidence, and read-only review of accepted artifacts or selected export files.
Source package Complete-operation rollup admin-app/lib/hosted-admin-complete-operation-rollup-package.js keeps this checklist source-reviewed and adds no route, handler, persistence, upload, collector, edge call, live control, deploy, restart, or VOD/caption execution.
Operator input Real edge evidence Collect selected basestation/clerk edge exports for rollout sites when the real machines are available; do not substitute fake fixtures.
Review needed Producer context approval Review proposed station/session rows before any future meeting write; no Producer launch, station/session write, ops call, or stream/record control is unlocked.
Approval required Real data cutover Choose storage owner, backup, rollback, audit, replay, and idempotency model before any production persistence or canonical data ownership changes.
Still locked Writes and execution Operational writes, VOD/caption jobs, live controls, deploys, restarts, SSH, local edge config access, provider calls, uploads, publishing, and secrets remain outside this Admin checklist.

Edge Evidence Collection Queue

2 present / 10 missing
Queue status 1 complete / 5 collection needed Churchill basestation and clerk selected exports are present; South Lake Tahoe, Douglas County, TDPUD, RTC, and Incline Village still need operator-collected selected exports.
Next selected files South Lake Tahoe slt-basestation-edge-checkin-export.json and slt-clerk-edge-checkin-export.json under admin-app/local/edge-checkin-exports/.
Rollout files Douglas County / TDPUD / RTC / Incline Village douglas-county-basestation-edge-checkin-export.json, tdpud-basestation-edge-checkin-export.json, rtc-basestation-edge-checkin-export.json, and matching clerk exports.
Review surface GET /api/admin/device-status No upload route, watcher, collector, edge-machine call, local edge config access, write handler, deploy, restart, or VOD/caption execution is added.

Producer Context Approval Queue

3 ready / 2 review / 0 blocked
Queue status 2 station/session proposals need review SLT Planning and TDPUD Intake are missing meeting station/session fields; both have accepted basestation proposals ready for operator review before any future meeting write.
Selected review South Lake Tahoe Setup Review mtg-slt-planning: propose slt-basestation-01 / render-slt-basestation-01 from accepted device inventory; producer owner remains unassigned.
Second review TDPUD Intake mtg-tdpud-intake: propose tdpud-basestation-01 / render-tdpud-basestation-01 from accepted device inventory; producer owner remains unassigned.
Review surface GET /api/admin/meetings + Run Detail No /api/admin/station-session route, meeting write, handoff package file, Producer launch, ops/edge call, stream/record control, deploy, restart, or VOD/caption execution is added.

Real Data Cutover Gate

No-Go / owner review
Source lanes 6 ready / 0 live cutover Meetings, People, Activity, Finalization, Settings, and Edge Check-ins are ready for cutover approval review; fixture/sample fallbacks remain visible.
Owner rows 6 surface owners / 0 named Name production owners for accepted read-source cutover rows before any storage implementation or fallback replacement.
Storage decisions Pending production approval Canonical storage, migration, backup/restore, audit, replay/idempotency, rollback, auth/access, release, support, and monitoring remain approval rows.
Stop line No persistence or writes No database, migration, hosted write API, route publication, upload route, collector, local edge config access, live control, deploy, restart, or VOD/caption execution is added.

Production Persistence Plan Review

Review only / no implementation
Canonical path Git-reviewed artifacts selected First production persistence path is reviewed hosted read artifact promotion with 7 planned artifacts for Sites/Devices, Meetings, People, Activity, Finalization, Settings, and Edge Check-ins.
Cutover sequence 6 steps / 0 complete Freeze approvals, prepare artifacts, capture backup, wire read adapters, run post-cutover smoke, then accept evidence or rollback.
Rollback / support Owners pending Rollback command template, support window, escalation owner, and failure-reporting path remain pending production owner decisions.
Stop line No artifact creation or adapter switch No database, migration, hosted write API, route publication, upload route, collector, local edge config access, live control, deploy, restart, or VOD/caption execution is added.

Hosted Readiness Snapshot

Read-only
Hosted readiness snapshot not loaded

Production Readiness Gates

What is left
Build-ready Read-only Admin The operator shell is ready for review across Command, Sites, Devices, Meetings, VOD / Captions, Settings, Activity, People, Onboarding, Site Draft, and Focus using existing read surfaces.
Needs owner Hosted storage owner Name canonical hosted storage ownership, migration ownership, backup/restore, audit retention, and rollback responsibility before any production persistence lane opens.
Still locked Production persistence Production persistence is not approved by the read-only Admin build. No database, hosted registry API, upload route, watched folder, background collector, or production storage write is unlocked.
Needs acceptance Live data ownership Replace fixture/sample inputs only through accepted read files or selected edge exports behind the existing read routes before treating the app as operational source-of-truth.
Future package Controlled writes Any write enablement still needs a separate approval package with idempotency, audit, replay, rollback, source-of-truth checks, diff hygiene, and a reviewed PR path.

Hosted Build Handoff Checklist

Pre-build packet
Name owner Storage owner packet Confirm canonical hosted storage owner, backup/restore, migration ownership, audit retention, and rollback owner before production persistence moves from review to build.
Accept reads Read-owner contracts Sites/Devices, VOD / Captions, Settings, Activity, People, and Meetings need accepted read-owner contracts before hosted implementation replaces local proof inputs.
Exit samples Live data sources Replace fixture and sample inputs only through accepted read files or selected edge exports behind existing read routes; no hidden upload, watcher, or collector is added.
Separate approval Persistence package No database, hosted registry API, upload route, collector, production storage write, or write flag is approved by this checklist.
Future lane Controlled write package Any write path still requires idempotency, audit, replay, rollback, source-of-truth checks, diff hygiene, reviewed PR path, and disabled-by-default flags.

Hosted Admin Mapping

Architecture bridge
Proof input Selected edge exports Churchill basestation and clerk check-ins stay as operator-selected files until a hosted storage owner is approved.
Review surface GET /api/admin/device-status Keep selected-export review inside the existing device-status read so Sites, Devices, Onboarding, and Meetings share one edge proof source.
Hosted target nindeo.io Admin Map the temporary local Node proof back to the hosted Admin/Laravel direction before replacing selected files with owned hosted reads.
Approved read-only mapping Hosted read model ready NINDEO-HOSTED-ADMIN-MAPPING-DECISION-PACKAGE-2026-06-30.md is approved as approved-read-only-mapping; admin-app/lib/hosted-admin-read-model.js packages the accepted registry only, while storage owner approval is still required and production writes stay locked.
Read model composition Complete read adapter set aligned admin-app/lib/hosted-admin-read-model.js emits ready-for-hosted-read-model-composition when supplied ready Sites/Devices, Finalization, Settings, Activity, People, and Meetings adapter payloads in memory; no hosted route, persistence, upload, collector, live control, or VOD/caption execution is added.
Import rehearsal Read-only import path held admin-app/lib/hosted-admin-import-rehearsal.js rehearses Sites and Devices import coverage from the accepted registry in memory only; POST /api/admin/sites stays locked and storage owner approval remains next.
Framework adapter Skeleton review ready admin-app/lib/hosted-admin-framework-adapter.js maps the rehearsal plus accepted read-owner completion checkpoint into six hosted read-owner adapter targets, including boundary-backed Settings metadata, with no Laravel route, hosted endpoint, migration, queue, or database write; storage-owner approval remains next.
Sites/devices framework binding Binding review ready admin-app/lib/hosted-admin-sites-devices-framework-binding.js maps hosted Sites/Devices read payloads to future SitesDevicesReadController, AcceptedRegistryArtifactReadService, resource, and DTO names for review only; no PHP file, Laravel route, hosted endpoint, middleware, persistence, write API, deploy, live control, or VOD/caption execution is added.
VOD/caption framework binding Binding review ready admin-app/lib/hosted-admin-finalization-framework-binding.js maps hosted Finalization read payloads to future FinalizationReadController, FinalizationArtifactReadService, resource, and DTO names for review only; no PHP file, Laravel route, hosted endpoint, middleware, caption generation, VOD build, upload, publishing, provider call, persistence, write API, deploy, live control, or VOD/caption execution is added.
Storage owner gate Review-ready, not approved admin-app/lib/hosted-admin-storage-owner-gate.js now summarizes the six accepted read-owner binding targets for storage review, but names the hosted persistence decision as read-only status only; no database, migration, upload, collector, hosted endpoint, or production storage write is created.
Hosted owner package Accepted read-only NINDEO-HOSTED-STORAGE-OWNER-APPROVAL-PACKAGE-2026-06-30.md approves Git-reviewed artifact promotion only for the next hosted artifact review contract; hosted persistence remains locked.
Artifact review contract Accepted read-only admin-app/lib/hosted-admin-artifact-review-contract.js proves hosted Sites/Devices reads from the Git-reviewed accepted registry artifact only after the six accepted read-owner binding targets are present, with no hosted route, database, migration, upload, collector, deploy, or live action.
Implementation handoff Adapter map ready admin-app/lib/hosted-admin-implementation-handoff-map.js maps the accepted proof surfaces into hosted controller/service targets for review only; no controller, service, endpoint, persistence, write API, upload, collector, deploy, live control, or VOD/caption execution is added.
Acceptance checkpoint Read-only package ready admin-app/lib/hosted-admin-implementation-acceptance-checkpoint.js accepts the six hosted read adapter targets as a future implementation package only; no hosted route, persistence, write API, upload, collector, deploy, live control, or VOD/caption execution is added.
Read implementation package First slice selected admin-app/lib/hosted-admin-read-implementation-package.js selects Sites/Devices as the first hosted read-only implementation lane and names the implementation plan for review only; no hosted endpoint, persistence, write API, upload, collector, live control, deploy, or VOD/caption execution is added.
Hosted target gate Modern Admin selected admin-app/lib/hosted-admin-target-gate.js selects the current admin-app shell as the modern Admin implementation target while keeping old Laravel as read-only product reference material; no hosted endpoint, persistence, write API, deploy, live control, or VOD/caption execution is added here.
Proof index Review map complete admin-app/lib/hosted-admin-proof-index.js indexes the hosted Sites/Devices, VOD / Captions, Settings, Activity, People, and Meetings proof surfaces for one read-owner review map; no endpoint, database, migration, upload, collector, persistence, live control, or VOD/caption execution is added.
Still locked No hidden ingest No upload route, watched folder, background collector, edge-machine call, registry persistence, live control, or VOD/caption execution is introduced by this bridge.

Hosted Read Owner Decision

Owner package
Sites / devices admin-app/data/site-registry.accepted.json Accepted non-secret site and device rows stay behind GET /api/admin/sites and GET /api/admin/devices until a hosted registry owner is approved.
Sites/devices contract Accepted registry read owner admin-app/lib/hosted-admin-sites-devices-read-owner-contract.js emits nindeo.hosted-admin.sites-devices-read-owner-contract.v1 for the accepted-registry-read owner; no hosted route, persistence, upload, collector, live control, or VOD/caption execution is added.
Sites/devices adapter Read payloads ready admin-app/lib/hosted-admin-sites-devices-read-adapter.js builds route-equivalent hosted Sites/Devices read payloads from the accepted registry and the implementation handoff map; no hosted route, persistence, write API, upload, collector, live control, or VOD/caption execution is added.
Current Admin slice Existing routes proven admin-app/lib/modern-admin-sites-devices-read-slice.js proves current admin-app Sites/Devices reads use GET /api/admin/sites and GET /api/admin/devices against the accepted registry; no duplicate endpoint, persistence, write handler, edge call, Producer control, deploy, or VOD/caption execution is added.
Edge proof Selected-export evidence Basestation and clerk check-ins stay behind GET /api/admin/device-status; no upload route, folder watcher, or edge-machine collector is added.
VOD / captions GET /api/admin/finalization-detail Artifact metadata belongs to the finalization read contract; Admin review stays separate from caption generation, VOD builds, uploads, and publishing.
Finalization contract VOD / Captions read owner admin-app/lib/hosted-admin-finalization-read-owner-contract.js emits nindeo.hosted-admin.finalization-read-owner-contract.v1 for the finalization-artifact-read owner; no hosted route, job execution, persistence, upload, publishing, provider call, or VOD/caption generation is added.
Finalization adapter Metadata payloads ready admin-app/lib/hosted-admin-finalization-read-adapter.js builds route-equivalent hosted finalization collection/detail read payloads from the finalization artifact read and implementation handoff map; no hosted route, job execution, persistence, upload, publishing, provider call, or VOD/caption generation is added.
Settings contract Settings read owner admin-app/lib/hosted-admin-settings-read-owner-contract.js emits nindeo.hosted-admin.settings-read-owner-contract.v1 for the settings-integration-read owner; no hosted settings route, credential read, local config read, provider call, persistence, live control, or settings write handler is added.
Settings adapter Boundary payload ready admin-app/lib/hosted-admin-settings-read-adapter.js builds a boundary-equivalent hosted Settings read payload from non-secret Settings metadata; no hosted Settings route, credential read, local config read, provider call, persistence, live control, or settings write handler is added.
Settings framework binding Binding review ready admin-app/lib/hosted-admin-settings-framework-binding.js maps hosted Settings boundary payloads to future SettingsReadController, SettingsIntegrationBoundaryReadService, resource, and DTO names for review only; no PHP file, Laravel route, hosted endpoint, middleware, credential read, local config read, provider call, persistence, write API, deploy, live control, or VOD/caption execution is added.
Activity contract Activity read owner admin-app/lib/hosted-admin-activity-read-owner-contract.js emits nindeo.hosted-admin.activity-read-owner-contract.v1 for the activity-notification-read owner; no notification delivery, acknowledgement, task mutation, chat, persistence, live control, or Activity write handler is added.
Activity adapter Route payloads ready admin-app/lib/hosted-admin-activity-read-adapter.js builds route-equivalent hosted Activity collection and item read payloads from Activity metadata; no notification delivery, acknowledgement, task mutation, chat, persistence, live control, or Activity write handler is added.
Activity framework binding Binding review ready admin-app/lib/hosted-admin-activity-framework-binding.js maps hosted Activity read payloads to future ActivityReadController, ActivityNotificationReadService, resource, and DTO names for review only; no PHP file, Laravel route, hosted endpoint, middleware, notification delivery, acknowledgement, chat/message send, task mutation, persistence, write API, deploy, live control, or VOD/caption execution is added.
People contract People read owner admin-app/lib/hosted-admin-people-read-owner-contract.js emits nindeo.hosted-admin.people-read-owner-contract.v1 for the participant-assignment-read owner; no participant import, invite, account approval, role mutation, assignment write, persistence, live control, or People write handler is added.
People adapter Route payloads ready admin-app/lib/hosted-admin-people-read-adapter.js builds route-equivalent hosted People, Roles, Assignments, and Assignment Detail read payloads from participant metadata; no participant import, invite, account approval, role mutation, assignment write, persistence, live control, or People write handler is added.
People framework binding Binding review ready admin-app/lib/hosted-admin-people-framework-binding.js maps hosted People read payloads to future PeopleAssignmentReadController, ParticipantAssignmentReadService, resource, and DTO names for review only; no PHP file, Laravel route, hosted endpoint, middleware, participant import, invite, account approval, role mutation, assignment write, authorization write, notification delivery, persistence, write API, deploy, live control, or VOD/caption execution is added.
Meetings contract Meetings read owner admin-app/lib/hosted-admin-meetings-read-owner-contract.js emits nindeo.hosted-admin.meetings-read-owner-contract.v1 for the meeting-run-read owner; no calendar write, handoff package generation, station/session write, Producer launch, ops control, stream/record control, VOD/caption execution, persistence, live control, or Meetings write handler is added.
Meetings adapter Route payloads ready admin-app/lib/hosted-admin-meetings-read-adapter.js builds route-equivalent hosted Meetings, Run Detail, Handoff, Assignment Detail, Finalization Detail, and Finalization queue read payloads from meeting metadata; no calendar write, handoff package generation, station/session write, Producer launch, ops control, stream/record control, VOD/caption execution, persistence, live control, or Meetings write handler is added.
Meetings framework binding Binding review ready admin-app/lib/hosted-admin-meetings-framework-binding.js maps hosted Meetings read payloads to future MeetingRunReadController, MeetingRunReadService, resource, and DTO names for review only; no PHP file, Laravel route, hosted endpoint, middleware, meeting CRUD, calendar write, handoff package generation, station/session write, Producer launch, ops control, stream/record control, VOD/caption execution, persistence, write API, deploy, live control, or Meetings write handler is added.
Promotion / audit Git-reviewed package lane Durable changes still require the storage ownership package, source-of-truth checks, diff hygiene, and an explicit approval boundary before persistence.
Implementation checklist Read owners ready for review admin-app/lib/hosted-admin-read-owner-checklist.js turns the proof index into a hosted read-owner implementation checklist for Sites/Devices, VOD / Captions, Settings, Activity, People, and Meetings; storage, persistence, write APIs, uploads, collectors, local config access, live controls, and VOD/caption execution remain locked.
Read-owner completion Six contracts ready admin-app/lib/hosted-admin-read-owner-completion-checkpoint.js emits nindeo.hosted-admin.read-owner-completion-checkpoint.v1 with ready-for-hosted-read-owner-acceptance across Sites/Devices, VOD / Captions, Settings, Activity, People, and Meetings; no hosted endpoint, persistence, write API, upload, collector, live control, or VOD/caption execution is added.

Hosted Persistence Approval Checklist

Still locked
Owner / storage Named before build No production storage write, database, or hosted registry API starts until owner, canonical storage, migration, and backup/restore are approved.
Audit / replay Idempotency required Approval must cover audit records, idempotency records, response hashes, replay behavior, and rollback for accepted registry changes.
Runtime boundary No hidden ingest No second site-registry endpoint, upload route, watched folder, background collector, edge-machine call, or local config write is unlocked.
Release boundary Separate approvals Deploys, restarts, automatic PR/merge, Producer/ops live controls, VOD/caption generation, and secrets/provider credentials stay outside this checklist.

Current Real Read Status

Active read
Active source Site registry accepted read Accepted registry rows for Churchill, South Lake Tahoe, Douglas County, TDPUD, RTC, and Incline Village feed the existing Sites surface.
Route GET /api/admin/sites No /api/admin/site-registry endpoint or duplicate draft read is added.
Proof Operator path coherent Accepted rows, source metadata, site rehearsal, Producer handoff, meeting/run detail, and VOD/caption review now compose through existing reads.
Stop line Review only Create-site writes stay feature-gated; no local config write, live control, VOD/caption generation, deploy, restart, SSH, or secret handling.

Build Phase 1 Read Status

Read-only proof
Primary read GET /api/admin/sites Accepted non-secret site registry rows are active behind the existing Sites route.
Safe alternate GET /api/admin/device-status Use selected basestation/clerk edge check-in exports only if the site registry input is not ready.
Proof held Read stack complete Accepted registry rows, finalization artifact proof, meeting/run record proof, edge export proof, MVP route rehearsal smoke, source metadata, fixture fallback, and no duplicate endpoints.
Real-site package SLT package rehearsal proof held The first non-Churchill package path is verified on existing Site Draft and accepted-registry preview surfaces; hosted mapping, storage ownership, production persistence, and write flag enablement still need a separate approval package.

Build Handoff Review

Manual gate
Ready evidence Admin MVP read path Command, Sites, Devices, Meetings, Run Detail, VOD / Captions, Settings, Site Onboarding, and Site Draft all rehearse through existing read contracts.
Package proof Operator review result Site Draft now surfaces validation proof, the next reviewed export input, operator result, final manual packet, promotion manifest, reviewed diff preview, and locked runtime boundary.
Next approval Promotion lane package Accepted-registry edits still need an approved write package, storage owner, explicit Git promotion lane, source-of-truth check, and diff hygiene.
Still locked No runtime mutation No Admin apply action, automatic branch, PR, merge, deploy, restart, SSH, live edge call, Producer control, VOD job, caption job, local config write, or secret handling.

Real Data Owner Gate

Fixture exit
Meetings / runs GET /api/admin/run-detail Owner: MEETING-RUN-READ-CONTRACT.md; expand existing meeting/run reads before any calendar CRUD or /api/admin/meeting-runs route.
People / assignments GET /api/admin/assignment-detail Owner: PARTICIPANT-ASSIGNMENT-READ-CONTRACT.md; keep role coverage read-only before participant imports, invites, account approvals, or role mutations.
Activity GET /api/admin/activity Owner: ACTIVITY-NOTIFICATION-READ-CONTRACT.md; move real task/notification rows behind existing activity reads before delivery or acknowledgement actions.
Settings Non-secret ownership only Owner: SETTINGS-INTEGRATION-READ-CONTRACT.md; choose one read owner before any settings route, credential read, provider write, or local config access.
Finalization GET /api/admin/finalization-detail Owner: FINALIZATION-ARTIFACT-READ-CONTRACT.md; keep VOD, captions, uploads, publishing, and artifact execution outside Admin until an execution contract exists.
Edge check-ins GET /api/admin/device-status Owner: EDGE-CHECKIN-READ-CONTRACT.md; replace fixture status behind Device Status only, with no /api/admin/edge-checkins route or edge-machine call.

Settings Integration Boundary

Read-only
Settings boundary unavailable
Calendar write

New meeting

Canonical meeting completion

Record completed run

Central meeting
Meeting assignment

Assign person

Central People directory

Add person

Roles
Sites
This changes only the central People directory. It does not create a login, send an invitation, alter role vocabulary, or change meeting assignments.
Git-reviewed central metadata

Update site details

Values are locked to the Git-reviewed accepted registry. This does not change readiness, devices, edge configuration, or operational controls.
Central device pairing

Pair edge device

Review-only control plane

Prepare finalization review

This creates central review records only. Execution is fixed off: no transcription, VOD assembly, upload, publish, provider call, edge access, or live control can start here.
Evidence review only

Record finalization review

This records the operator's evidence decision only. Artifact statuses remain unchanged and no caption, VOD, upload, publish, provider, edge, or live action can start here.
Terminal evidence decision

Record finalization closeout

This records the terminal six-row evidence decision only. Artifact statuses, execution state, media, providers, uploads, publishing, edge configuration, and live controls remain unchanged.
Central request only

Request finalization run

This records approved central intent only. It does not dispatch a worker, call an edge machine or provider, process media, generate captions or VOD, upload, or publish.
Existing results only

Attest publication evidence

This records reviewed hashes and counts from an existing upload result. It cannot claim work, execute media, call a provider, upload, publish, or change YouTube.
Captions-only recovery

Reset failed captions for review

This resets only the validated failed captions review state. It does not claim a queue item, start transcription, run media, upload, publish, or request finalization execution.

Secure operator access

Sign in to Nindeo Admin

Use your assigned Admin account. Access is authenticated and site-scoped; available actions follow the enabled workflows.

Authentication grants only the site-scoped Admin workflows assigned to this account. Live Stream, Record, graphics, and PTZ controls remain in Producer and Basestation.