High-level health stays visible to the Toura family without granting access to protected system controls.
Welcome to MEL.
Sign in with your Toura identity. Your dashboard, analytics, and workstations are projected from your governed role after authentication.
Good morning.
Your Toura heartbeat is online. Company-wide context is visible here; workstation authority remains role-specific.
Only workstations granted to your role open operational controls. All others remain visible but locked.
Where you can work
Marketplace
Open the shared Marketplace catalog, supplier resources, and your role-based station.
Member Operations
Visible in MEL so you understand the organization; operational controls are not included in your current role.
Partner Operations
Company context remains visible, while Partner workstation authority stays protected.
Economic Operations
Economic and settlement controls require separate explicit authority.
MEL lets the Toura family understand Toura’s heartbeat and growth without converting that visibility into permission. Direct URLs and server-side commands remain independently enforced.
Toura growth at a glance.
Shared, read-only company analytics. These numbers provide company context and never grant operational authority in the underlying domains.
The Toura family can understand company growth and operating posture here. Detailed governance, system assurance, economic controls, and unrelated workstation records remain outside the current role unless explicitly granted.
Good morning, Robert.
The command shell is online. Certified ecosystem layers are now visible through governed observation surfaces; mutation remains disabled.
Canonical rails are holding.
No critical conditions are currently known. Jarvis will become Mel’s governed interpretation layer as live operational intelligence is connected.
Authority before action.
Mel exposes a command only after explicit domain mutation authority is earned. Certification, visibility, Pulse, Sensors, or operator identity alone never create command authority.
Prove allowed acts and denied stays denied.
Prove the boundaries work together.
Prove separate certified domains leave one reconstructable trail.
Prove one missing boundary cannot create a false ecosystem PASS.
Reconstruct one governed journey from identity to Control Center.
Prove the full journey fails closed and returns intact.
Prove one domain failure cannot contaminate the ecosystem.
Prove the isolated failure can recover cleanly with no residual contamination.
Prove Mel can reconstruct the incident without rewriting history.
Prove the complete failure campaign closes fail-safe and returns to canonical truth.
Inventory every remaining gate before Production can be considered.
What Mel is watching
Inspect the nervous system
Source & authority topology
Where you were
The nervous system has a heartbeat.
Brick 076.2 routes controlled watched-boundary conditions into Needs Attention with severity while preserving the 60-second continuous sensor sweep and zero business mutation.
What is participating in the heartbeat
Certified boundaries under watch
The automatic 60-second sweep evaluates all 15 certified sensor endpoints with GET-only, no-write requests. “Record fresh evidence” explicitly runs the governed POST evaluators and persists new sensor observations; it never runs automatically.
Prove watched conditions become operator work.
Prove the heartbeat reacts.
Underlying health checks
The heart is HEALTHY only when Foundation health is proved and every currently activated cross-domain Pulse signal is observable. Pending domains remain outside the active heartbeat until their governed live signal is earned. Missing active proof becomes UNKNOWN; a proved harmful condition becomes DEGRADED.
Work that actually needs an operator.
This queue is derived from governed conditions, not notifications. Controlled limitations that require no action remain visible in Pulse without becoming fake work.
Current items
Jarvis architect triage & owner decisions
Every family suggestion is retained. Jarvis classifies and routes the work first; only items requiring Owner authority are promoted into your Needs Attention count.
Known limitations
Businesses waiting for Toura review.
Verify the business before Marketplace tools unlock. Supplier approval does not approve any Marketplace offer.
Supplier applications
This workspace may approve, request changes, or decline a Supplier application only. It cannot approve Marketplace offers, publish inventory, move Points, settle funds, or activate Production authority.
Verify the bank deposit before Points move.
Toura Control Center reviews the private SINPE evidence. Passport DEV remains the canonical funding and Points source of truth.
Bank verification activity
Grand Cajeta authenticates the Toura owner/admin operator and records the human operator identity. A narrow server-side bridge invokes Passport DEV verification. Confirmation can fund only the existing canonical request snapshot; rejection creates zero Points. Production authority remains disabled.
One certification surface for Mel's nervous system.
Brick 074 begins unifying documentary certification, live Sensors, Pulse, Deep Certification, authority boundaries, and release posture across the connected ecosystem. Documentary truth and live runtime proof remain visibly distinct.
Publication, place identity, evidence freshness, and launch data
Waiting for governed release state.
Waiting for canonical place-link readiness.
Waiting for durable evidence freshness.
Waiting for governed inventory classes.
Waiting for connection-health evidence.
Waiting for release-registry posture.
Marketplace content is not public merely because Owner review passed. Passport acknowledgement must complete first, and Explorer visibility remains blocked until a verified canonical place link exists. Durable sensor evidence is shown with freshness, not historical green. Launch records remain non-destructive until their governed classification is explicit.
Sensor → Pulse → Deep Certification
Session-live tripwires
All 15 registered boundary evaluators are probed every 60 seconds while Control Center is open. Automatic probes never write evidence.
Production-safe active proof
Evidence-backed operational health. Green is earned; unknown remains unknown.
Controlled exhaustive testing
Release-level proof across identity, authority, contracts, events, evidence, sensors, regressions, and failure boundaries.
Unified certification matrix
FOUNDATION-ASSURANCE-001
Certified historical records, live Sensor observations, Pulse state, and Deep Certification are different proof classes. Big Mama may unify their presentation, but never converts missing runtime proof into green and never treats documentary certification as current production health.
Parallel development command board.
Owner-only production governance view of active build lanes, deployment HEADs, stale-base protection, and recent coordination events. This surface observes the control registry; it does not deploy code.
Who is building what
What changed
When a registered production candidate HEAD changes, any writable lane still based on an older deploy is automatically marked REBASE REQUIRED. When Mission Control reserves the deploy baton, that lane becomes UP NEXT FOR DEPLOY and all other execution-lane deploy permissions remain blocked until the baton is released.
Workspace
This domain is registered in the global shell but intentionally not activated in Control Center Build Brick 3.
Prove health from evidence, not assumption.
Independently evaluate the durable Brick 008 proof and persist one FOUNDATION_INTEGRITY sensor observation. HEALTHY is allowed only when every required Foundation signal has fresh positive evidence; missing evidence remains UNKNOWN and failed required evidence becomes DEGRADED.
This brick does not trust the writer to certify its own truth. A separate server-mediated FOUNDATION_INTEGRITY evaluator reads the authenticated actor, explicit Production capability, Foundation registries, and Brick 008 durable Event/Evidence correlation, applies freshness rules, then may write one Foundation-owned sensor observation. No production, economic, legacy, or business-domain mutation is introduced.
Connect an existing operator.
No account is created here. Use only the existing Production Supabase Auth identity already provisioned for Foundation testing. Authentication proves identity only; authority remains independently governed.
One audited write path. Zero business effect.
The server-mediated proof writes one fixed foundation.authority_checked.v1 event and one linked FOUNDATION_DURABLE_WRITE_PROOF evidence record. RLS binds both records to the authenticated Production actor and existing test capability.
The writer does not certify its own truth.
The independent evaluator requires fresh positive evidence for application, database connectivity, migration state, auth adapter, authority enforcement, contract registry, event path, evidence path, and observability. Missing evidence cannot return HEALTHY.
Rails beneath Mission Control.
Foundation 001R remains observable from the new shell. Verification is safe, production-safe, and has no economic effect.