Shared Supabase project
The single shared store the time-series data lands in, with row-level security and provenance on from the start.
The platform stands up in order: data first, then ingestion with a human in the loop, then query, then the extras. Nothing ships before it is safe.
The platform is built on a shared foundation: the firm registry, the access kernel, the audit spine, and secrets handling. That foundation carries its own four-part acceptance gate, and the first data phase blocks on it.
A row-level-security leak suite, registry coverage, audit completeness, and secrets hygiene. All four pass, or the first data phase does not start. This is not a checklist to revisit later; it is a hard gate at the front.
The platform's access scope is ratified inside the Cockpit governance process. The platform proposes the scope it needs; the governance process decides. Policy is never set by the code that consumes it.
Consume the shared substrate once its acceptance gate passes. The platform depends only on the foundation, never on any Cockpit phase.
Stand up the time-series store; migrate the legacy spreadsheet gated by the reconciliation checks. The migration fails loudly if position counts and totals do not tie out. Provenance links from day one.
Turn on the document agents and the needs-review workflow. The buy-versus-build decision on an extraction feed is made at this kickoff: run vendor conversations in parallel; either way, a vendor feed and the firm's own agents are interchangeable producers into the same tables and validation path. The #ingestion-review queue lands here.
Dashboards and natural-language query; the datastore query tool ships, caller-scoped and citing its figures. The #portfolio channel and ephemeral deal channels come online here, because they need the query tool.
Firm-wide consolidation, alerts that flow into briefings, and scenario tools.
One rule carries the weight: connector credentials are issued per role tier exactly as the access matrix grants them. A role that is not granted a connector never holds its credential.
The single shared store the time-series data lands in, with row-level security and provenance on from the start.
Read-only credentials issued per role tier for reconciliation against the accounting system of record.
Read-only credentials issued per role tier for investor and fund data drawn from the portal.
The workspace where query, review, and alerts surface; the platform bot answers and posts within it.
The deal pipeline runs sourcing through close in Linear; agents draft and label, a human moves a stage.
The firm model gateway for all model calls, plus observability and evaluation tooling (Langfuse) for the extraction eval gates.
Ask in plain English and get cited answers back, caller-scoped to what your role may see.
Confirm extracted figures before they land; a human is the verification layer between extraction and the store.
Calls and distributions posted with their source links, ready to become deadlines and briefing items downstream.
The weekly new / stale / missing report, so gaps are caught before someone needs the number.
DSCR, LTV, and upcoming maturities, surfaced before they become a scramble.
The Slack channel surface ships only after the governance amendment (v2.2) is signed. The channels wait on the paperwork, not the other way around.
The platform runs in parallel with the Cockpit rollout; the two do not block each other on delivery.
The platform depends only on the shared foundation. That single dependency, and its acceptance gate, is the whole precondition.
Data first, then ingestion with a human in the loop, then query, then the extras. Each stage earns the next, and nothing ships before it is safe.