Google Workspace SSO — configured in Development only, and not yet accepted
Google Workspace SSO (DEC-059) is implemented — OIDC sign-in, server-side sessions, revocation, suspension detection and a step-up foundation (MSAI-008). A Development OAuth client is now configured, so this environment can attempt the flow. Staging and Production are not configured. Configuration is not acceptance: interactive sign-in and Google Workspace suspension acceptance have not been performed, and the Admin SDK directory path is unconfigured, so suspension detection is not active. Configuring identity granted no permission and no authority — every actor remains default-deny. There is deliberately no local password fallback and no development bypass.
This Development staff-pilot is intended for authorised Mirrorstone staff at https://agents.mirrorstone.co.uk only, behind Google Workspace SSO and host-nginx TLS. Raw dashboard, API, database and observability ports remain localhost-bound. Staging and Production are unchanged. This notice is not evidence that live hostname verification has passed.
Operational views are read-only visibility. They cannot write, send, approve, replay, publish or delete events, create, cancel, enable, disable or trigger a schedule, toggle a kill switch, select a model, change a route, edit policy, configure a business unit, grant permission, change Charter or autonomy, or create or mutate audit records. It composes already-exposed audit correlation identifiers with event-runtime type-level summaries; that is not a per-event join and it does not invent identifiers. Cross-business comparison shows only fields the existing approved-scope and runtime contracts already return; visibility is not permission, and the view cannot enlarge approved scope or change isolation. The Review & oversight centre composes existing review-queue, runtime, briefing and audit reads; it cannot approve, reject, send or write. The only existing dashboard write remains the Daniel review surface, which records a human decision already taken. Fresh, stale, partial, unavailable, unknown, loading and error are contract states — a missing timestamp is Unknown, never current. Bookmarking a view does not grant permission.
Sign in required
This Development staff dashboard is available to authorised Mirrorstone Google Workspace identities only. There is no local password, guest access or development bypass. Signing in grants no send, write, spend or autonomy authority.