Blueprint · relationship

Privacy-safe CareerVector operation

Operators see aggregate health and explicitly supplied diagnostics, never a general browser over private workspaces.

Cell 4.3 · operations · privacy · control · evidence
  • Aggregate signals to Ops · QA · Status: observe
  • User-supplied evidence to Ops · QA · Status: consented diagnostic
  • Ops · QA · Status to Scoped command capability: request action
observeconsented diagnosticrequest action
storetarget

Aggregate signals

Service health, queues, models, token use, local adoption, and error classes.

CareerVector
boundaryopen

User-supplied evidence

Explicitly scoped diagnostics for one support case.

Workspace participant
perspectivetarget

Ops · QA · Status

Investigate releases, incidents, AI supply, and participant lifecycle.

Management
boundaryopen

Scoped command capability

Revocable support authority, typed workspace op, or erasure request.

Management and participant
privacy-safe operationaggregate evidence / scoped supportsupport implements commitmentsstatus and recovery
  1. 01 · store · target Aggregate signals

    Service health, queues, models, token use, local adoption, and error classes.

    CareerVector
  2. 02 · boundary · open User-supplied evidence

    Explicitly scoped diagnostics for one support case.

    Workspace participant
  3. 03 · perspective · target Ops · QA · Status

    Investigate releases, incidents, AI supply, and participant lifecycle.

    Management
  4. 04 · boundary · open Scoped command capability

    Revocable support authority, typed workspace op, or erasure request.

    Management and participant

Flows

  • Aggregate signals Ops · QA · Status observe
  • User-supplied evidence Ops · QA · Status consented diagnostic
  • Ops · QA · Status Scoped command capability request action
as built target / open Boundary arrows open the neighbouring module; ports stay machine-only

CareerVector × Management

Purpose

Operate and support CareerVector without creating a privileged browsing surface over private workspaces or an unrecorded path for agents to alter user state.

Operator pathways

  • Understand aggregate service health, realtime behavior, work queues, model availability, token use, local-execution adoption, and error classes.
  • Investigate a user-reported problem with explicit, scoped evidence supplied by the user or generated by privacy-safe diagnostics.
  • Manage Included AI supply, provider availability, zero-cost budgets, and model catalogues.
  • Review QA, releases, incidents, migrations, and public status.
  • Execute participant erasure and verify completion across product boundaries.

Invariants

  • There is no general operator workspace browser.
  • Private prompts, documents, keys, and workspace content do not enter telemetry by default.
  • Every write to workspace truth uses the same typed operation contract as other actors.
  • Support capability is explicit, scoped, revocable, and visible to the participant.
  • Aggregate learning and observability cannot reconstruct a person's workspace activity.

Decisions still required

  • Support-capability lifecycle and evidence-sharing UX.
  • Privacy-safe telemetry tiers and redaction contract.
  • Included AI capacity policy, fairness, and exhaustion behavior.
  • Operator approval boundaries for model/provider changes.

Completion evidence

Resolve a real support case using only scoped evidence; prove denial of unrelated workspace access; audit every state-changing action; verify erasure and key isolation end to end.

Source: architecture/modules/careervector-management.md