Private platform migration in progress — business operations remain disabled.

Bordoh OS · private administration

One governed engine.
Three isolated surfaces.

Bordoh OS coordinates platform operations while Auto Tech and Cleaning keep their own code, data access and business workflows.

Authorised users only. Access is identity-gated and audited.

Architecture

Clear ownership replaces the old mixed repository.

Every app crosses the same versioned, tenant-scoped engine boundary.

01

Platform only

Engine Admin

Organisations, integrations, audit, identity and system health.

02

Business isolated

Auto Tech Admin

Jobs, vehicles, customers and communications through versioned contracts.

03

Business isolated

Cleaning Admin

Jobs, properties, customers and communications through versioned contracts.

Security boundary

Identity before application.

Cloudflare Access protects the administration surface. Bordoh OS then verifies the signed identity, tenant binding and phishing-resistant second factor.

  • Business-email identities are allowlisted per administration app.
  • Passkeys or security keys protect privileged access.
  • Tenant selection is server-owned and cannot come from request input.
  • Provider traffic enters through a signed, replay-resistant gateway.
  • Secrets stay in Cloudflare or the approved secret manager, never GitHub.

Controlled migration

The old deployment retires only after rollback is proven.

  1. 01
    Architecture foundation

    Repositories, contracts and tenant boundaries established.

  2. 02
    Staging implementation

    Identity, recovery and Neon connectivity under validation.

  3. 03
    Production cutover

    Move domains only after staged health and rollback checks pass.

  4. 04
    Retirement

    Archive the old repository after the rollback window expires.