{
  "OperationalArea": 2,
  "BaselineDate": "2026-04-28",
  "StandardRolesPresent": true,
  "AdministratorExists": true,
  "BootstrapCredentialsSupplied": true,
  "ProductionReady": true,
  "StandardRoles": [
    "Administrator",
    "IntegrationOperator",
    "SupportAnalyst",
    "ReadOnlyAuditor"
  ],
  "Items": [
    {
      "Key": "phase2-test-first-specifications",
      "Description": "User access and security identity/bootstrap behavior is covered by discoverable tests before production wiring is accepted.",
      "RequiredForWorkflow2": true,
      "Complete": true,
      "EvidencePath": "tests/SweetSpot.Bridge.Workflow2.Tests"
    },
    {
      "Key": "standard-role-catalog",
      "Description": "Administrator, IntegrationOperator, SupportAnalyst, and ReadOnlyAuditor roles are defined centrally.",
      "RequiredForWorkflow2": true,
      "Complete": true,
      "EvidencePath": "src/SweetSpot.Bridge.Core/Workflow2/BridgeRoleCatalog.cs"
    },
    {
      "Key": "password-hashing",
      "Description": "Bootstrap/admin passwords are hashed with PBKDF2-SHA256 and are never stored as cleartext.",
      "RequiredForWorkflow2": true,
      "Complete": true,
      "EvidencePath": "src/SweetSpot.Bridge.Core/Workflow2/PasswordHasher.cs"
    },
    {
      "Key": "admin-bootstrap",
      "Description": "First Administrator is seeded only from deployment-supplied secrets and only when no Administrator exists.",
      "RequiredForWorkflow2": true,
      "Complete": true,
      "EvidencePath": "src/SweetSpot.Bridge.Core/Workflow2/User access and securitySeedService.cs"
    },
    {
      "Key": "audit-evidence",
      "Description": "Role seed, admin seed, skipped seed, login, failed login, and authorization-relevant events are auditable.",
      "RequiredForWorkflow2": true,
      "Complete": true,
      "EvidencePath": "src/SweetSpot.Bridge.Core/Workflow2/IdentityAuditRecord.cs"
    },
    {
      "Key": "authorization-policies",
      "Description": "Admin, replay, support read, and audit read policies are wired in the web host.",
      "RequiredForWorkflow2": true,
      "Complete": true,
      "EvidencePath": "src/SweetSpot.Bridge.Web/Program.cs"
    }
  ],
  "Bootstrap": {
    "Succeeded": true,
    "SeededAdmin": false,
    "SkippedAdminSeed": true,
    "MissingBootstrapSecrets": false,
    "AdministratorAlreadyExists": true,
    "Messages": [
      "Role already present: Administrator",
      "Role already present: IntegrationOperator",
      "Role already present: SupportAnalyst",
      "Role already present: ReadOnlyAuditor",
      "Existing Administrator found; first-admin bootstrap skipped without overwrite."
    ]
  }
}