Northstar Demo Lab
Six products. One operational picture.
XFlow coordinates audit evidence, entitlement policy, trust signals, grounded content, and creative delivery so an operator can see what is healthy, what needs attention, and what to do next—without moving sensitive data between product boundaries.
6
Connected products
4 / 6
Healthy now
2
Non-critical issues
17 / 20
Evidence channels
Guided operating path
The next three moves
Ordered by impact and evidence freshness so the operator never has to scan every dashboard.
Refresh Verixet entitlement snapshot
The latest synthetic snapshot is eight minutes outside the workspace freshness target.
Verixet · 2 min
Review two Crevux delivery retries
Both demo deliveries succeeded on retry; inspect the shared pattern before closing the issue.
Crevux · 4 min
Publish the weekly evidence brief
Combine current audit, trust, provenance, and delivery evidence into one review package.
XFlow · 6 min
Connected ecosystem
Six application workspaces
Each product owns its workflow; XFlow coordinates status, evidence, and operator action.
Last synthetic scan · 2 minutes ago

XFlow
Control plane and workflow orchestration
Automations
24 active
AudAiX
Audit and evidence intelligence
Checks reviewed
186

Verixet
Entitlements and release governance
Policy decisions
42 today
RatAiFy
Trust, risk, and scam-signal review
Trust score
92 / 100

WordGeni
Grounded writing and research
Claims grounded
38 of 41
Crevux
Creative production and asset workflows
Assets delivered
46 of 48
Identity and first-run architecture
From workspace creation to trusted operation
Onboarding teaches the product model while the authentication boundary protects the browser-to-desktop handoff.
Create workspace
Establish the tenant boundary, member roles, and audit context.
Register applications
Give each product a stable identity and evidence contract.
Authorize with PKCE
Exchange a one-time code without placing a client secret on the desktop.
Verify and operate
Validate evidence channels, surface gaps, and guide the next action.
Workspace boundary preserved
Application reads resolve through the authenticated active workspace; a client-supplied workspace identifier is not treated as authority.
OAuth 2.0 · Authorization code
S256 PKCE handoff
Desktop creates verifier
The high-entropy verifier remains on the requesting device.
Browser receives S256 challenge
Only the SHA-256 challenge, state, and exact redirect are authorized.
User approves workspace access
Consent binds the client, scopes, active workspace, and one-time code.
Desktop exchanges the code
The server verifies the original verifier before issuing a bounded session.
Operational focus
Evidence and integration coverage
Freshness warning
Verixet entitlement snapshot is eight minutes beyond target.
Delivery observation
Crevux retried two of 48 synthetic asset deliveries.
Cross-application evidence
Recent workspace activity
A short, sourced timeline of the work that changed the operator’s picture.
Accessibility evidence bundle indexed
AudAiX · 12 routes · 186 checks · no critical findings
Launch brief passed provenance review
WordGeni · 38 grounded claims · 3 awaiting editorial review
Trust review completed
RatAiFy · Ownership, privacy, and reputation signals current
Freshness warning opened
Verixet · Entitlement evidence exceeded the 15-minute target
Delivery retry moved to operator review
Crevux · 2 retries across 48 synthetic deliveries
Technical evidence drawer
Implementation boundaries and focused verification
Expand for the engineering proof behind this presentation fixture.
+
Technical evidence drawer
Implementation boundaries and focused verification
Expand for the engineering proof behind this presentation fixture.
Route and access inventory
441 routes inventoried
122 protected API routes and 50 dashboard actions covered by focused validators.
OAuth / PKCE boundary
S256 + exact redirect matching
Verifier, state, origin, device, and workspace checks are exercised in local package tests.
Workspace isolation
App-specific RLS policies
Authenticated-access and cross-workspace denial definitions are present and statically validated.
AI action controls
Preview, confirmation, idempotency
Chronicle actions create receipts and fail closed while external execution remains disabled.
Claim boundary
This page is a local presentation fixture. It demonstrates implemented repository architecture and synthetic product behavior; it does not represent customer activity, deployed SSO, production database enforcement, or live provider execution.