# Platform Operations Dashboard

The Platform Operations Dashboard is an internal, browser-authenticated workspace for active `platform_admin` users. It adds no public API and does not grant tenant membership. Switching into a tenant workspace continues to require an existing active tenant membership.

## Overview definitions

All time windows use UTC with an inclusive lower boundary and exclusive upper boundary. Message counts use one authoritative `messages` row per submitted message and the existing message/delivery status vocabulary. SMS units come only from `usage_records` with `usage_type=outbound_sms`; they are never inferred from message count. Wallet coverage counts tenants with a TZS wallet. Pricing readiness requires a currently effective active rate through platform fallback, tenant scope, or application scope.

The Overview exposes aggregate counts and recent sanitized audit identity only. It never reads or renders message bodies, recipients, credentials, provider secrets, or raw audit metadata.

## Tenant visibility

The Tenant inventory is server-paginated and deterministically ordered. Search treats a valid ULID as an exact public-ID lookup; all other input is a bounded name-prefix search. Status, wallet-coverage, and tenant-pricing filters are supported. Tenant detail displays public identifiers, application and Sender ID counts, memberships, authoritative usage, configured limits, wallet/reconciliation state, pricing configuration, and bounded recent audit activity.

Tenant creation, deletion, and lifecycle mutations are intentionally excluded because the repository has no approved tenant lifecycle or creation service. Platform role alone never grants tenant-workspace access.

## Operations health

Operations is status-only. Health states are `Healthy`, `Attention Required`, `Not Configured`, and `Unavailable`. Values come from persisted outbox, message, wallet, reconciliation, pricing, and webhook state or from the presence of expected SMPP configuration. Configuration secrets are never shown. Runtime OS state is marked unavailable because it is not persisted authoritatively.

The page cannot execute shell commands, arbitrary Artisan commands, SQL, filesystem operations, NSSM controls, or provider configuration changes.

## Audit visibility and security

Audit records are ordered by `created_at DESC, id DESC` and paginated server-side. Filters support UTC from/to-exclusive, actor ID, action, tenant public ID, subject type, and outcome. Detail presentation uses an explicit metadata allowlist. Unknown keys and password, API key, provider credential, recipient, message, session, idempotency, exception, and filesystem-path material never render. Numeric internal actor/subject identifiers are not presented as public references.

## Base-path and deployment verification

All links and forms combine `Request::getBaseUrl()` with relative named routes exactly once. Verify both host-root deployment and a subdirectory such as `/smsgateway/public`:

1. Sign in as a platform administrator and open Platform Overview.
2. Follow Overview, Tenants, Users, Operations, Pricing, and Audit sidebar links; Commercial remains marked Future.
3. Filter and paginate Tenants, open Tenant detail, and return to the inventory.
4. Filter and paginate Audit, open a detail, and confirm only approved metadata appears.
5. Confirm every URL contains the deployment base once and Switch workspace remains available.
6. Confirm a tenant-only user receives the neutral platform-workspace denial and a platform administrator without membership cannot enter tenant workspaces.
