LIVE PLATFORM CONNECTIONS · S0OMNI is reading the actual shared control-plane readiness contracts.
This surface uses server-side, read-only readiness contracts. It does not accept credentials from the browser and it does not simulate successful Access, Work, Calendar or Audit operations.
S0 governed path4/7
BSV IDENTITY OIDC AVAILABLELast checked 7:03:34 AM Operational test ladder
Each stage reflects a real contract or an explicitly documented gap.
01 · AVAILABLEInterface Preview
Recovered OMNI routes and operator shell.
02 · AVAILABLEGateway P3.2 Readiness
Live Gateway /ready + metadata contract.
03 · AVAILABLEGateway Identity Verification
Legacy signed-assertion verification metadata through Gateway.
04 · AVAILABLEBSV Identity OIDC
Shared BSV Identity issuer + omni-preview OIDC client.
05 · BLOCKEDPlatform Access P3.3
Shared BSV authorization + organization graph + decision receipts.
06 · BLOCKEDWork + Calendar Read
Canonical Daily Ops projections through Gateway.
07 · BLOCKEDAudit-bound S0
Tenant-scoped owner-domain read with verified Audit receipt.
PLATFORM GATEWAY P3.2Governed platform boundary
Gateway readinessConnected
Service identityroll-call-platform-gateway:p3.2-staging
Gateway versionP3.2.0
Environmentstaging
Reference consumersevents, field, experiential, asmbly
GATEWAY IDENTITY VERIFICATIONLegacy verification metadata
VerificationConnected
AlgorithmRS256
Gateway issuance flagNot authoritative for OMNI login
This contract remains visible for Gateway compatibility. OMNI authentication uses the separate BSV Identity OIDC contract.
BSV IDENTITY · SHARED REALMOMNI authentication issuer
OIDC discoveryConnected
Issuerhttps://keycloak-runtime-production.up.railway.app/realms/bsv-shared
Clientomni-preview
AuthorizationP3.3 Access not live
Authentication is not authorization. A valid BSV Identity session does not unlock owner-domain data without an Access decision.
PLATFORM ACCESS P3.3Authorization + organization graph
ReadinessNot configured
ServiceUnavailable
PolicyP3.3 source certified
Access remains fail-closed until the shared authority is deployed and returns an explicit allow decision with a receipt.
AVERY A3.2Governed intelligence runtime
ReadinessConnected
ReleaseA3.2.0
Environmentstaging
OMNI S0 BINDINGSWhat still blocks the first real Daily Ops read
BSV organization bindingPending
OMNI service principalPending
Protected service credentialPending
Work projection contractGateway contract missing
Calendar projection contractGateway contract missing
Verified Audit receiptNot bound
SECURITY RULERead-only until the chain is complete
Authentication alone does not unlock business records. The next platform work is an authenticated, tenant-scoped Access decision plus canonical Work and Calendar read contracts with Audit evidence.