Supabase / auth
ReadySign-in, registration, and workspace persistence all sit on Supabase.
Next action: No action — Supabase auth is configured.
Readiness command centre
This is the founder release-control surface. Each category is checked against live config and the Supabase readiness resolver. No env values, tokens, or secrets are ever shown.
Overall status
Public beta blocked
Public beta cannot be enabled yet.
Public beta is blocked. Backend readiness incomplete.
Sign-in, registration, and workspace persistence all sit on Supabase.
Next action: No action — Supabase auth is configured.
Workspaces, agents, reviews, reports, invites, and connections must persist with workspace-scoped isolation.
Warnings
Next action: Validate migrations with the S34D schema validator and confirm tables reachable.
Private-beta invites must be created, optionally sent by email, and accepted via the documented 8-state lifecycle.
Next action: No action — invite system is enabled.
Invite emails are honest-disabled. The UI uses copy-link mode.
Warnings
Next action: Optional — set AGENTPROOF_PRIVATE_BETA_EMAILS_ENABLED + AGENTPROOF_EMAIL_PROVIDER to enable.
Microsoft Entra OAuth is read-only. AgentProof never requests business records, only metadata.
Next action: No action — Microsoft connector is configured.
Manual non-Microsoft agents let a tester describe a website chatbot, internal agent, OpenAI-style agent, or workflow automation agent.
Next action: No action — manual non-Microsoft flow is enabled.
Demo mode shows AgentProof against two isolated demo agents. Demo data never appears in real workspaces.
Warnings
Next action: Set AGENTPROOF_DEMO_MODE_ENABLED=true to expose /demo.
AgentProof produces a print-ready readiness report (cover, score, evidence, risks, controls, methodology). Browser print only — no PDF-export service is shipped.
Warnings
Next action: Use the browser print dialog to capture the report.
Every workspace read + write is scoped by workspace_id. RLS policies forbid cross-workspace reads at the Supabase layer.
Next action: No action — workspace isolation is structural.
AgentProof never bundles the Supabase service-role key, Microsoft client secret, OAuth tokens, refresh tokens, id tokens, raw invite tokens, or email API keys into the browser bundle.
Next action: No action — the archive build script refuses to package forbidden files.
AgentProof is invitation-only. Public registration is being prepared.
Next action: When the readiness backend is fully green, set AGENTPROOF_PUBLIC_REGISTRATION_ENABLED=true.