Platform MVP, Gate 2, and Gate 3 are complete for Xero Demo Company validation. OAuth, refresh, tenant handling, encrypted storage, API gateway, queue, authenticated dashboard, and action results are already built.
Do not edit OAuth, tokens, tenants, encryption, rate limits, idempotency, or Xero transport unless assigned as platform work.
Choose the rollout path before moving any workflow from Demo Company to real company/customer data.
ADMIN.BIZ.JOBS.QA.DOCS.OperatorAccess on state-changing endpoints.storage/private/.The dashboard at / is locked by an operator session. State-changing hosted endpoints require a dashboard/setup session or a valid X-Setup-Key header.
The business user owns workflow, screens, rules, sample data, and acceptance. Platform/Ops owns OAuth, scopes, deployment, backups, support, Xero limits, certification, and rollout governance.
Developer handover refreshed on 17 September 2026. Receive the private credential file from the owner, then read docs/developer-team-handover.md, docs/php-baseline-setup.md, and docs/developer-readiness-2026-09-17.md over FTP for setup instructions and verification results. Keep the credential file off the web server.
Develop in a local working copy. Preserve the hosted .env and storage/private/. Agree the workflow and user flow through the app intake before starting a new business feature; the first business workflow remains unselected.
If connected over FTP or in a local checkout, start with AGENTS.md, README.md, docs/project-segmentation.md, docs/codex-handover.md, docs/developer-team-handover.md, docs/rollout-roadmap.md, docs/non-it-app-builder-guide.md, and docs/work-package-template.md.