NEXUS CLOUD v1.0 · BUILD CONTROL

One operating system.
Every company keeps its own space.

NEXUS Cloud is being built as a secure, multi-company automotive operating platform. Future Lease 4 U is the flagship implementation and first controlled pilot.

Private Cloud workspaceNo customer data importedLive website unchanged

NON-NEGOTIABLE DELIVERY GATE

Every work card follows the same release discipline.

Nothing is published just because it looks finished. Each capability must pass all five gates in sequence.

  1. 01

    Build

    Create the requested capability in the Cloud workspace.

  2. 02

    Automated tests

    Run the relevant build, unit, integration and safety checks.

  3. 03

    Fix every issue

    Resolve confirmed failures before a release can progress.

  4. 04

    Regression review

    Recheck protected journeys, permissions and prior releases.

  5. 05

    Publish

    Release only after every earlier gate is green.

THE DELIVERY ROADMAP

Fifty-one work cards. One controlled route to launch.

PublishedActiveQueued behind its dependency
WORK CARD 01Published

Cloud foundation

Architecture, delivery controls and acceptance-test baseline.

WORK CARD 02Published

Multi-tenant architecture

Company boundaries, data ownership and isolation controls.

WORK CARD 03Published

Authentication and permissions

Secure sign-in, roles and tenant-scoped access.

WORK CARD 04Published

Super Admin

Platform oversight, support boundaries and audit controls.

WORK CARD 05Published

Company workspace

The first safe operational workspace for Future Lease 4 U.

WORK CARD 06Published

Subscriptions and billing

Plans, trials, renewal controls and billing boundaries.

WORK CARD 07Published

Onboarding and customer portal

Company setup and a customer-safe self-service journey.

WORK CARD 08Published

AQUA governed AI

Tenant-safe read, draft and approval-gated action workflows.

WORK CARD 09Published

Security and operations

Resilience, recovery, observability and hardening evidence.

WORK CARD 10Published

Pilot and commercial launch

Private-team pilot gate; customer and commercial release remain no-go.

WORK CARD 11Published

Migration readiness

Metadata-only dry-run controls; no records, documents or legacy connections move.

WORK CARD 12Published

Integration gateway

Contract-only registry; every provider, credential, request and retry remains off.

WORK CARD 13Published

Document and customer access

Private storage, identity and invitation controls remain blocked until independently proven.

WORK CARD 14Published

Commercial release control

Evidence-based go/no-go, rollback and owner sign-off for launch.

WORK CARD 15Published

Production readiness baseline

Owner-only runtime evidence for the private Future Lease 4 U pilot.

WORK CARD 16Published

Production data plane

Database lifecycle, migration verification and safe health controls.

WORK CARD 17Published

Staff identity and access

Named staff roles, least privilege and MFA readiness for the pilot.

WORK CARD 18Published

Website intake and reconciliation

Signed connectivity boundary; customer routing and reconciliation remain gated.

WORK CARD 19Published

Private document service

Sealed storage and metadata/audit foundation; document content remains gated.

WORK CARD 20Published

Controlled data migration

Metadata-only quarantine plan; source access, records and import execution remain off.

WORK CARD 21Published

External integration gateway

Metadata-only contract reviews; providers, credentials, callbacks and deliveries remain off.

WORK CARD 22Published

Recovery and observability

Planning-only recovery boundary; backups, restores, rollback drills and alert delivery remain off.

WORK CARD 23Published

Future Lease 4 U pilot

Planning-only staff-UAT boundary; UAT, workflows, support cases and commercial pilot remain off.

WORK CARD 24Published

Commercial billing controls

Provider-disabled billing boundary; checkout, payment, invoices and customer billing remain off.

WORK CARD 25Published

Independent launch review

Missing-evidence no-go boundary; assessment, sign-off and commercial launch remain off.

WORK CARD 26Published

Controlled commercial rollout

Rollout-not-started boundary; cohorts, customers, migration, payments, providers and notifications remain off.

WORK CARD 27Published

FL4U staff-pilot lead desk

A clearer tenant-scoped lead and follow-up home for the private Future Lease 4 U team.

WORK CARD 28Published

Protected lead records

A tenant-scoped read-only lead record, reached only through the signed-in FL4U workspace.

WORK CARD 29Published

Duplicate-safe lead capture

Email-based duplicate prevention for internal FL4U leads and their follow-up work items.

WORK CARD 30Published

Follow-up ownership

An open internal follow-up can be claimed once by an authorised FL4U staff member, with a tenant-scoped audit trail.

WORK CARD 31Published

Personal follow-up queue

Authorised FL4U staff see their own claimed follow-ups first, without exposing other company work.

WORK CARD 32Published

Controlled lead stages

Authorised FL4U staff can move a lead through a limited internal workflow with a tenant-scoped audit trail.

WORK CARD 33Published

Safe follow-up completion

Only the FL4U staff member assigned to an open follow-up can mark it complete, with an audit trail.

WORK CARD 34Published

Operational role boundaries

Lead and follow-up controls now use explicit, least-privilege permissions rather than a broad customer-write grant.

WORK CARD 35Published

Safe lead activity timeline

A tenant-scoped, state-only history shows fixed internal stage changes without exposing free-form audit content.

WORK CARD 36Published

Private internal notes

Authorised FL4U staff can add tenant-scoped internal context without creating a customer message or external action.

WORK CARD 37Published

Synthetic pilot workflow regression

A clean-schema workflow test proves lead creation, staging, ownership, notes and completion remain tenant-scoped and content-safe.

WORK CARD 38Published

Private pilot evidence gate

The final private-workflow evidence is explicit about what it proves—and why customer UAT and commercial launch remain closed.

WORK CARD 39Published

NEXUS Cloud operations intelligence

AQUA now has a governed Cloud operating model, evidence-aware health briefings, a fault-and-retest process, recommendations and protected aggregate statistics.

WORK CARD 40Published

Private runtime evidence

A display-safe runtime check now distinguishes configured foundations from any permission to accept real work.

WORK CARD 41Published

Staff pilot readiness

Role integrity is measured separately from MFA evidence; no staff account is created or widened by the check.

WORK CARD 42Published

Signed intake rehearsal

The website boundary remains signed and reference-only while live customer routing stays closed.

WORK CARD 43Published

Lead operations controls

Internal follow-ups can carry an optional due time and remain tenant-scoped, duplicate-safe and action-free externally.

WORK CARD 44Published

Document quarantine contract

Only a bounded, metadata-only document preflight contract exists; upload, scanning, access and customer visibility remain off.

WORK CARD 45Published

Check My Options staging rehearsal

An automated-only synthetic lead-to-task proof for the first FL4U website journey; real website intake remains closed.

WORK CARD 46Published

Communications readiness

Sender, delivery telemetry and failed-message handling are prepared while all provider delivery remains disabled.

WORK CARD 47Published

Website routing readiness

The signed, exact-once Check My Options routing contract is prepared; the live website switch remains off.

WORK CARD 48Published

Recovery drill readiness

Backup, restore and rollback runbooks are prepared without claiming that a recovery drill has run.

WORK CARD 49Published

Migration reconciliation readiness

Field mapping, dry-run harness and reconciliation rules are prepared without accessing or importing legacy records.

WORK CARD 50Published

Pilot operations readiness

Private staff-pilot controls are prepared while staff UAT itself remains a human-owned evidence gate.

WORK CARD 51Published

Controlled go-live gate

The final ledger combines technical readiness while requiring real human evidence and an owner decision before launch.

WORK CARD 01 · PUBLISHED

Build the platform rules before moving customer work.

The foundation release establishes the product structure, quality gates and proof required before future development can introduce records, document uploads, integrations or automated actions.

WORK CARD 02 · PUBLISHED

Tenant isolation is a platform rule, not a screen setting.

Every future record, activity and event is being made workspace-owned from day one. A request cannot simply choose another company's data by changing a browser value.

A

Workspace ownership

Core platform records carry a required workspace ID and indexed tenant boundary.

B

Server-resolved scope

Browser-provided workspace headers are never treated as authority for data access.

C

Evidence trail

Audit and outbox events are tenant-owned, correlation-ready and duplicate-safe.

WORK CARD 03 · PUBLISHED

The right user, only inside the right workspace.

NEXUS Cloud now has a server-side permission contract. A signed-in Work identity must hold an active membership and the right role before a workspace action can be allowed.

01

Platform Owner

Platform controls only, never company customer access.

02

Company Owner

Full control inside one company workspace.

03

Director / Admin

Company administration without ownership transfer.

04

Manager

Operational control without company or platform administration.

05

Staff

Day-to-day customer and follow-up work only.

06

Restricted / read-only

Limited visibility with no write capability.

WORK CARD 04 · PUBLISHED

One platform to govern. Clear limits on what support can see.

The Super Admin centre governs companies, pilot status and operational support. It deliberately excludes customer documents, applications and financial records from the platform overview.

SUPER ADMINPRIVATE PILOT
COMPANIES01Workspace registry
SUPPORT00Open operational cases
DATA SCOPESAFENo customer financial or document data
Future Lease 4 UPilotReady to initialise

WORK CARD 05 · PUBLISHED

An operational workspace that begins empty—and stays inside its company boundary.

The first pilot workspace has a protected enquiry queue and follow-up control. A signed-in member is resolved to the company on the server; a browser cannot select another tenant's records.

FUTURE LEASE 4 UPRIVATE PILOT
01
Internal enquiryCreated only by an authorised member
02
Follow-up queueTenant-owned and audit-ready
03
External actionOff until a later approved work card

No historic customer data is imported by this release.

SUBSCRIPTIONSPROVIDER DISABLED
Private pilot planTenant-owned record
Renewal decisionManual review only
Payment collectionOff until approved

WORK CARD 06 · PUBLISHED

Billing controls are live. Payment collection is deliberately not.

Each company now has a tenant-scoped plan and subscription record, entitlement policy, audit trail and retry-safe preparation flow. No card, checkout, invoice delivery or provider connection is enabled.

WORK CARD 07 · PUBLISHED

Company onboarding is prepared. Customer access is intentionally still gated.

The pilot now has a tenant-owned onboarding record, readiness controls and a visible customer-portal boundary. It will not issue links, show records or send messages until an approved identity and invitation path exists.

CUSTOMER PORTALNOT ACTIVATED
01InvitationRequired before access
02IdentityMust be verified
03RecordsNot visible by default

Tenant selection from the browser is never accepted.

AQUADRAFT ONLY
Workspace signalAnonymous queue summary
DraftingHuman review required
External actionOff by policy

WORK CARD 08 · PUBLISHED

AQUA can help the team think—without taking control.

AQUA now has a tenant-safe draft path and operational-insight boundary built around an anonymous queue summary. Its server-only model connection remains closed until the runtime secret is configured; it cannot see documents or financial data, send messages, approve applications, update records or trigger payments.

WORK CARD 09 · PUBLISHED

Security and operations are now measured against real launch gates.

Every Cloud response is hardened with security headers, and Super Admin now has a protected evidence board. It deliberately shows a commercial NO-GO until backup/restore, private documents, controlled integrations and verified customer access have independent proof.

OPERATIONSCOMMERCIAL NO-GO
Response hardeningVerified
Tenant audit trailVerified
Restore evidenceRequired
Customer accessGated
FUTURE LEASE 4 UPRIVATE PLANNING REVIEW
Operator accessSuper Admin planning only
Customer recordsNot migrated
Staff UAT / workflowNot started

WORK CARD 23 · PUBLISHED

The Future Lease 4 U pilot remains a private review, not a customer rollout.

The owner can record the UAT planning boundary without pretending a scenario has run. No staff UAT, customer workflow, support case, message, payment or commercial pilot can start here.

WORK CARD 14 · PUBLISHED

Fifty-one private work cards are released. Commercial launch is not active.

The final control pulls together the remaining evidence without pretending it exists. Recovery proof, migration reconciliation, provider contracts, private document custody, customer identity and named owner approval still keep commercial release at NO-GO.

COMMERCIAL RELEASENO-GO
Recovery evidenceRequired
Customer accessClosed
Owner sign-offRequired
Release actionUnavailable