Internal

Admin dashboard

Single-pane-of-glass for the on-call admin. Today, · all times in UTC · displayed in clinic's local timezone where applicable · Multi-province: timezone follows the clinic's registered province

Active clinics
Verified pros
OWNER ONLY
Revenue (30d)
Platform fees
OWNER ONLY
Total processed
— shifts (30d)
Invoice Challenge
Founder-led agency markup analysis · 5-slot weekly capacity
Active analyses
of 5 slots
Slots open
Waitlist depth
Contacted in order
Completed
Lifetime analyses
Active queue
LocationStatusSLA
Loading…
Waitlist
Loading…
Operations queue · needs your attention
All items SLA-tracked. Sorted by oldest first.
Loading…
Recent platform activity
TimeEventSubjectDetail
Loading…

Command Center

Owner-only platform visualization · live from clinic & pro activity · OWNER ONLY

Auto-refresh ·
GMV processed
— completed payments
Platform revenue (30d)
— all-time fees
Active clinics
— total on platform
Active pros
— verified
Completed shifts
— in last 30d
Avg fee / shift
platform take
Platform fees by clinic
Top locations by fees collected
Clinics by tier
Subscription mix
Professionals by role
Active workforce composition
Credential status
Verification pipeline
Geographic footprint
Clinics by city
Shift funnel
Lifecycle state (all-time)
Top clinics by activity
Ranked by fees collected · last activity
ClinicLocationTierFeesShifts (30d)ProsLast activity
Loading…

Customers

All clinic accounts. Click any row for the full customer drawer.

 Account actions
Search a user above (name, email, or ID) and select them to lock, reactivate, or restore the account.
| Sorted by MRR contribution
Clinic Tier Subscription MRR Shifts (30d) Status Last activity
Loading…
Live customer list

Pricing overrides

Per-clinic pricing adjustments. All overrides are time-limited, fully audited, and dual-approval-gated below the Multi-location rate.

Money-floor guardrails (server-enforced): the lower the fee, the more distinct admin signatures required. An override at or above the $49 PAYG rate activates on submission. Below $49 requires dual approval; below the $29 platform floor requires triple approval — each signature from a separate admin with the pricing capability. A single rejection cancels a pending override. Overrides are time-limited and every action is written to the append-only audit log.
Clinic Override Reason Created by Signatures Effective Expires Status
Loading…
Full audit log retained. Every override creation, modification, approval, and revocation is logged with admin user ID, timestamp, before/after values, and justification. Audit data is append-only and retained for the lifetime of the clinic relationship plus 7 years.

Bulk feature toggles

Enable or disable a feature flag across all active clinics in one action. Every change writes one append-only audit row per clinic. Reason required.

The bulk action and the affected-clinic counts below are live. State is per-clinic (missing row = enabled by default), so counts reflect active clinics minus explicitly-disabled ones.
Platform-wide flag control
Primary use: Phase 2 urgency surcharge activation across all clinics simultaneously
 Bulk actions write one audit row per active clinic. At 50 active clinics, a bulk toggle writes 50 append-only records. Reason field is mandatory — a minimum 10-character reason is required before any bulk action fires. This cannot be undone.
Feature flag Current state Enabled clinics Bulk action
Loading…
 Bulk toggles write one append-only row to clinic_feature_flags per active clinic — same structure as per-clinic toggles. No UPDATE or DELETE permitted. Every row includes: admin_id, reason, previous_state, timestamp.

Subscriptions

Paid subscription management.

Active subscriptions
Paid tiers
MRR contribution
Live
Annualized (ARR)
MRR × 12
Past-due / suspended
| |
Clinic Plan Cadence Amount Renews Churn risk Status
Loading…
Automated reminder cadence
Per Playbook V §4.3 · all sends Stripe-hosted billing portal links
30d before
Annual subscribers
7d before
All subscribers
1d before
All subscribers
Day of fail
Update payment
Day 3 fail
Final notice
Day 7 fail
Auto-suspend

Signup review queue

Flagged signups awaiting manual approval. SLA: 24h. Per Playbook V §7 four-layer defense.

Live queue: accounts held inactive at signup by a fraud signal, awaiting manual approval. Approve to activate the account; reject to keep it out. In queue and Rejection rate (7d) are live; auto-pass rate and avg review time are not tracked (a held-then-approved account is indistinguishable from an auto-passed one afterward).
In queue
Auto-pass rate (7d)
not tracked
Avg review time
not tracked
Rejection rate (7d)
Pending review · oldest first
Each account was held by a fraud signal at signup. Review the flags, then approve or reject.
Loading…

Leads

Waitlist and application submissions from the marketing-site forms (clinics & professionals). Newest first.

ContactSourceRoleLocationClinicDetailsReceived
Loading…

Licence Reviews

Professionals awaiting credential verification. Open the registry link to confirm, then approve — the pro is emailed automatically on approval.

ProfessionalRoleLicence #RegistryAuto-lookupSubmittedActions
Loading…

Province Waitlist

Professionals outside Alberta captured at signup (hard-blocked, no account). Filter by province to target them when we expand. Newest first.

NameEmailProvinceRoleLicence #SourceCaptured
Loading…

Clinic Ownership Reviews

Clinics that submitted a CRA Business Number for ownership verification. Approve to confirm they're authorised (unlocks shift publishing), or reject to send back for resubmission.

ClinicOwner emailCityBusiness #StatusReviewed bySubmittedAction
Loading…

Pros

All verified professionals. Identity displayed at admin Tier 3 access — full names visible to admins, masked to clinics until interest accept.

Verified pros
Active (last 30d)
Top Tier (95+)
Read-only (lapsed)
Awaiting renewal
Active · — Stage 2 (score frozen) · — Dormant · — Inactive · — | | | Read-only · — Sorted by reliability score
ProRoleEngagement typesReliabilityShifts (30d)StatusLast shift
Loading…
Documents awaiting review
Open the file, check it against what the professional entered, then approve or reject. A rejection reason is shown to them — say what to fix.
Loading…
Reliability tiers — the same scale a clinic sees: 95+ Top Tier · 85-94 Excellent · 70-84 Trusted · <70 Building. A professional with no completed shifts bands New, and under five completed shifts Building, whatever the score — it starts at 100, so it means nothing until there is a record behind it. Score mechanics: no-show −15 · late cancellation (<24h) −10 · each clinic rating blends 30% of the pro's star average (5★=100) into the score, which is the only thing that raises it. Floors at 0, caps at 100, no time decay. Separately, 2+ late cancellations in 30 days auto-suspends for 14 days. Admin adjustments are recorded and appealable.

Transactions

Every billed shift. Stripe Connect application_fee model — full fee breakdown per row. Direct Hire conversions and subscription charges are billed elsewhere and do not appear here.

Transactions (all-time)
Live
OWNER ONLY
Gross volume
Live
OWNER ONLY
Platform revenue
Live
Revenue (30d)
Live
| Direct Hire · n/a Subscriptions · n/a | |
DateTypeClinic → ProGrossPro receivesPlatformStripeNetStatus
Loading…
Fee breakdown · Stripe Connect
Application_fee model — clinic charged, pro paid (100% wages), platform receives application_fee. PCI-DSS L1 inherited from Stripe. Volume & revenue are live; Stripe costs are estimated at standard rates (actual charged fees vary).
Owner · Tier 1 only
Gross volume
Pro wages
Platform revenue
Stripe fees est. (2.9% + $0.30)
Stripe Connect est. (0.25%)
Express payouts est. ($2/payout)
Net platform revenue (est., after Stripe costs)

Verification

Manual verification queue. Items here failed auto-match (Layer 3 of Playbook V §8.3) and need human disambiguation.

Live credential-verification queue — same data and actions as Licence Reviews. In queue, Auto-verified (7d) and Lapsed → read-only are live; re-verifications and the lapsed-credentials table below stay placeholders until continuous re-checking writes those events.
In queue
Auto-verified (7d)
Re-verifications (mo)
not tracked
Lapsed → read-only
Credential verification queue · pending pros
Professionals awaiting credential verification. Open the registry link, confirm, then Approve — the pro is emailed automatically on approval.
ProRoleLicenceRegistryAuto-lookupSubmittedAction
Loading…
Lapsed credentials · read-only mode active
Continuous re-verification detected expired or suspended licences. Pros cannot accept new shifts until status restored.
ProRoleLicenceDetectedStatusAction
Preview — not yet wired to live data.
Continuous monitoring (Playbook V §8): All verified pros are re-checked monthly against their respective regulator (ACDH / CDSA / CADA). Expired or suspended status moves the pro to read-only automatically; existing booked shifts are not auto-cancelled — admin team evaluates regulatory specifics before clinic notification. Audit log retained 7+ years.

Disputes

Timesheet disputes, circumvention flags, and general grievances. Dispute mediation is included in the platform fee per Playbook V §3.

Open disputes
SLA OK
Resolved (30d)
Avg 1.4 days to close
Circumvention flags
open · off-platform contact
Dispute rate
Below 3% target
 Dispute dossier

Pull a clinic's or professional's recent shifts, payments, chargebacks and refunds in one view. Enter the entity ID (from Customers / Pros). Dollar figures show only to owner-level admins.

Disputes
Loading…
Loading disputes…
Timesheet hold rate · by clinic
A hold keeps a shift out of the payment run until the concern is resolved. Most clinics will never raise one. A clinic holding a large share of what it is billed for is either being badly served or working the payment calendar — both worth knowing early. Last 90 days; only clinics with at least one hold appear.
ClinicHoldsTimesheets submittedHold rate
Loading…
Circumvention flags · off-platform contact attempts
Live signal: contact info (email / phone / URL / handle) a party tried to exchange inside an in-engagement message — redacted from the thread and flagged here. Severity escalates on repeat (medium → high → critical). Relationship-pattern matching is a planned follow-on signal.
FlagSeverityActorPatternDetectedStatus
Loading…
Resolution principles: Mediation is provided by the platform. Admin team has authority to recommend resolution; both parties must accept or escalate to formal arbitration (Alberta governing law, per ToS §11). Tier 1 circumvention exact matches trigger NCA enforcement workflow with counsel review. Tier 3 fuzzy matches are stored but not actioned to prevent false-positive harassment.

Communications

Admin-initiated outbound messaging. Transactional sends fire automatically; this panel governs announcements, marketing, and platform notices.

Send volume is live (best-effort counter, go-forward only). Open / bounce / spam rates are not tracked — Cloudflare Email Sending has no analytics API. Campaign management is a planned feature.
Sends (this month)
transactional + marketing
Open rate (avg)
not tracked
Bounce rate
not tracked
Spam complaints
not tracked
Active campaigns
Scheduled and currently sending.
CampaignAudienceChannelScheduleStatus
Preview — not yet wired to live data.
Channel mix
Transactional (Cloudflare)
Receipts, alerts, reminders. ~$0.50/mo cost.
Marketing (Cloudflare)
Newsletters, drip. Separate DKIM domain.
Per Playbook VI §5.3: Transactional and marketing always sent from separate subdomains with separate DKIM keys.
System-driven reminder cadences
Automated transactional flows. Configurable in Settings → Cadences. Public-facing language is moat-protected.
CadenceAudienceTriggerStatusLast sent
Preview — not yet wired to live data.

Analytics

Platform-wide metrics. Click any KPI for the underlying cohort.

Monthly Recurring Revenue
Live
Annualized Run Rate
MRR × 12
Revenue (30d)
Live
Total processed
Live
Reveal dial performance
Does revealing the clinic name lift fill-rate — and at what circumvention cost? Tune the per-shift reveal dial from this.
Reveal levelPostedFilledFill-rateAvg hrs → fillCirc. flags
Loading…
Contact-circumvention flags: · platform-level (per-reveal attribution is a follow-on)
Signup funnel · Clinics (last 30d)
Land → signup → onboarded → first shift posted → first shift filled.
Landed on for-clinics
Signup started
Account verified
Onboarded (NCA signed)
Posted first shift
First shift filled · ACTIVATED 42 2.3%
Cohort retention · Clinics
% still posting shifts in given month after signup.
CohortSizeM1M2M3
Loading…
M3 = % of a signup cohort that posted a shift in their 3rd month. Cells for months not yet elapsed show “—”.
Operations metrics (last 30 days)
MetricCurrentTargetStatusTrend
Preview — not yet wired to live data.

Referral fraud review queue

Soft-flagged referrals awaiting review. Flags remain open until an admin acts — there is no automatic approval. Hard rejections never appear here.

 Hard rejections are permanent and cannot be overridden. Only soft flags appear in this queue. Approving or rejecting a soft flag is logged to the audit trail with your admin ID.
Flag typeEntityReasonsFlaggedSeverityReviewed byActions
Loading…
All actions are append-only logged to the fraud_flags table and the audit trail. Confirmed and dismissed flags record the reviewing admin and time. Rejected referrals are permanent — no credit is ever issued.

Clinic account locks & suspensions

Three lock types of increasing severity. All actions append-only audit logged. System-initiated locks (payment default, cure breach, PC lapse) are automated. Admin-initiated locks are tier-gated.

Posting lock Tier 3a+
Login: allowed
View records: allowed
Post new shifts: blocked
Existing shifts: protected
Use for: payment hold, cure breach, minor violation
Read-only Tier 2+
Login: allowed
View records: allowed
All actions: blocked
Shift posting: blocked
Use for: dispute investigation, compliance hold
Full suspension Tier 2 + co-sign
Login: blocked
All access: blocked
Confirmed shifts: reviewed
Lift: Tier 2 co-sign
Use for: ToS violation, fraud, non-payment 72h+
Active locks
Clinic Lock type Source Reason Applied Applied by Actions
Loading…
System trigger status
Automated locks — actor: system · append-only audit log
Payment default
Stripe charge fails → posting lock applied immediately
Retry at 24h and 48h automatically
72h unresolved → full suspension
Pro paid from $2,000 reserve fund at 72h
Founding Clinic cure breach
Below 3 shifts/quarter → posting lock
30-day cure window · D1, D15, D28 notifications
Cured → lock auto-lifts, rate preserved
Expired → rate reverts to PAYG permanently
PC lapse (pro-side)
PC registration lapsed → pro posting lock
72h resolution window · pro notified D1
Resolved → lock lifted, PC elections restored
Unresolved → auto Employee reclassification
Lock audit log
Append-only · no UPDATE or DELETE · 7-year retention
Timestamp Clinic Action Lock type Actor Reason (min 20 chars)
Loading…

DSO Consolidated Invoicing

Generate one invoice per DSO organization per billing period, itemized by clinic/location. Download as PDF.

Invoice # Period Wages Fees GST Total Due Status Generated Actions
Select an organization to view invoices

Audit log export

Append-only audit log — every platform event, immutable. Filter by any dimension and preview below. Export delivery is live: CSV and Excel downloads each carry a SHA-256 integrity hash computed over the exported dataset.

Audit retention: 7 years
Export via: [email protected]
 Export scope is tier-gated: Single clinic date range = Tier 4+  ·  All clinics date range = Tier 3a/3b+  ·  Full platform export (all time) = Tier 1 only  ·  Forensic export = Tier 1 via [email protected] only
Export filters
Preview & export
Timestamp (UTC) Event type Actor Entity Entity ID Details IP Audit row ID
Loading…
 Export delivery is live. CSV and Excel downloads include a SHA-256 integrity hash in the footer, computed from the full exported dataset and verifiable against the live database — making it legally defensible for dispute resolution or regulatory submission. The preview above reads live audit data. (PDF and scheduled/recurring exports are not yet available.)
Scheduled exports
Auto-deliver recurring exports to up to 3 email recipients via [email protected]
ClinicFrequencyRecipientsLast sentAction
Preview — not yet wired to live data.

Direct Hire invoice

Manual billing for permanent-hire conversions. Enter salary and shift count — the system calculates the correct tier fee automatically. Quote-only preview; live billing (charge to the clinic's saved method) is not yet wired.

 Internal only — Tier 3a+. Fee schedule never shown on public pages or clinic-facing UI.
 Year 1 waiver — Owner only. The waiver control is shown only to Owner-capability admins.
The formula
Shifts completed → determines rate tier
First-year salary × rate tier = raw fee
Fee = max($1,500, min($15,000, raw fee))

The floor and cap are hard — the formula never produces a number outside $1,500–$15,000 regardless of salary or tier.

Invoice inputs
$
Owner · Tier 1 only Admin-only — never visible to clinics
Eligibility check (all must pass): (1) Clinic is within 12 months of account creation. (2) This is their first Direct Hire conversion. (3) Professional was introduced on platform ≥90 days ago. (4) NCA Protected Period still active.
⚠ Counsel ToS amendment required before activating. Every waiver is logged to audit trail with Owner ID + timestamp.
Sliding scale — rate tiers
Shifts completedFee rateOn $85,000 salary
0–4 shifts12%$10,200
5–14 shifts8%$6,800
15–29 shifts5%$4,250
30+ shifts3%$2,550
Floor: $1,500 — fee never goes below this Cap: $15,000 — fee never exceeds this + GST: 5% added to final fee
Invoice preview
Enter inputs
Professional
Clinic
Shifts completed
First-year salary
Rate tier
Raw fee
Floor / cap applied
Direct Hire fee
GST (5%)
Total charged
Enter salary and shift count above to see calculation.
Payment method
Saved payment method — not yet wired
Quote only — live Direct Hire billing (Stripe charge + invoice + audit entry) is not yet wired.
Recent Direct Hire invoices
DateClinicProfessionalShiftsFeeGSTTotal
No Direct Hire invoices yet — live billing is not yet wired.

Treasury — reserve & operating funds

Internal bookkeeping ledger for the risk reserve, the operating (opex) fund, and expenditures. Tracking only — it records how funds are allocated for the books; it does not move real money. Actual funds move via Stripe / bank outside this console. Owner-only; every entry is append-only and attributed. The reserve and operating funds are deliberately separate accounts (a liability is never commingled with spendable working capital).

Revenue
Reserve (risk)
Operating (opex)
Move funds
Record expenditure
Expenditures
VendorCategoryAmountStatus
Loading…
Recent ledger
WhenTypeFrom → ToAmount
Loading…

System Health

One window for live system health, capacity utilization, and security posture — auto-refreshing. No secret values are exposed.

Overall
checking…
Database
latency
Background jobs
freshness
Container memory
RSS / limit
Event-loop lag
CPU saturation
Error rate
4xx + 5xx
Health detail
Health status
Overall
Database
API uptime
Background jobs
Email delivery
Origin gate (Cloudflare-only access)
CPU load — host, shared (1m / cores)
Host memory — shared (free / total)
API memory (RSS)
Capacity
System utilization
Live host metrics + history for capacity planning. Auto-refreshes; samples recorded ~every 5 min while the console is active.
Memory · process RSS / container limit
Event-loop lag
Capacity signals are the container (RSS vs its limit; event-loop lag) — Railway OOM-kills at the memory limit. Host CPU/RAM are shared across tenants and shown for reference only.
Peak memorylast 24h
Request performance
Request performance
Live HTTP traffic, latency percentiles, and error rates. In-process (resets on redeploy); the console's own health polling is excluded.
Requests
Error rate
Latency p50
median
Latency p95
95th pct
Latency p99
Top endpoints — by traffic
RouteReqsp95Err
Slowest endpoints — by p95
Routep95Reqs
Backups & recovery
Backups & recovery
Encrypted daily database backups in remote storage. Read-only — restore is a manual runbook procedure, never a button.
Last backup
Restore points
retained d
Total size
Live deploy
Restore point (UTC)Size
Loading…
Backups are gpg-encrypted before leaving the server. To restore, follow RESTORE_RUNBOOK.md (break-glass, into a fresh DB first). For a bad deploy, roll back in Railway / CF Pages or git revert — no DB restore needed.
Security posture

Security posture

Configuration self-report — controls, integrations, and data-integrity locks. Owner-only.

Passing
Warnings
Critical
Environment
Posture checks
Loading…

Settings

Admin team, system configuration, audit log access. Tier 4-5 admins only.

Admin team
Capability-based roles: Owner (full access) · Ops Admin · Finance Admin. Pricing, ownership, and team changes are Owner-only.
AdminTierCapabilitiesLast active2FA
Loading admin team…
GST / HST
Owner-only. Off until Facioneer is GST-registered. Switching it on applies GST (5%) to platform fees across all new invoices, stored totals, and dashboards.
Off
9 digits + RT + 4 digits. Required to switch on.
Province expansion state
Four-state model per Playbook III.
Alberta Active
British Columbia Waitlist
Ontario Waitlist
All others (8) Off
System config
Public pricing visibility Hidden (locked)
Compute residency Canada (OVHcloud QC)
Storage residency Canada (Cloudflare R2)
NCA clickwrap version v1.0
ToS version v1.0
Privacy Policy version v1.0
Audit log retention 7yr + relationship
Audit log access
Append-only ledger. Every admin action, override, approval, rejection, and configuration change.
TimestampAdminActionSubject
Loading…
Security: 2FA mandatory for all admin tiers. SSO via Google Workspace required for Tier 4-5. Audit log is append-only — no admin (including Owner) can edit or delete entries. Forensic export available on request via [email protected].