TG
TrustGraphVerified workforce record platform
Verified workforce record platform

Verified work records, owned by the worker.

Professionals keep one private record of identity, work history, credentials, references, and evidence. Companies request access to only what they need.

Start here

TrustGraph is a verified workforce passport and corporate review workspace.

Pick the Professional path to build and share your own Passport. Pick the Corporate path to request approved workforce records without browsing the user database.

ProfessionalCreate your Passport

Professional users create a Passport, add records and evidence, recover account access, and control exactly what can be shared.

CorporateOpen Corporate Verify

Corporate teams register a company, invite reviewers, request scoped access by email, and review approved rows only.

Pricing$0 Professional, $149/month per company

Professional pilot is free. Corporate Verify pilot is $149 monthly. Stripe checkout stays human-gated.

RegistrationThe first registration writes a live Supabase registration intent. Corporate users never get open user-database browsing.Corporate accessRequest by professional email, then review only consented records, grants, references, and evidence.Hosted statusGitHub Pages is the current verified build until the VPS release stamp JSON is current.
Who TrustGraph servesChoose the workflow before live database rows are createdpublic_audience_switchboard_explains_professional_corporate_and_operator_paths_pricing_database_effects_scoped_access_and_human_gates_in_first_viewport
Profile, personal organization, Passport recordsProfessional database effectCompany, RBAC seat, subscription ledger, access requestsCorporate Verify database effectAudit, release, security, readiness receiptsTrust operations database effect
Portal front doorCreate Professional Passportpublic_front_door_shows_professional_login_corporate_login_registration_pricing_database_boundary_recovery_and_server_status_before_dense_content
Professional - freeSelected pricingprofile + personal Passport workspaceFirst live database writecheckingServer saved status
Choose your pathProfessional Passport starts with your private recordVerify email if prompted, then login here to start the live Passport workspace.
profile + personal Passport workspaceFirst database writeOwner-controlled PassportProfessionals own Passport rows, evidence, consent, and every Access Grant decision.
Saved buildChecking saved buildLooking for the release stamp on the current host.
Not provenRelease stamp commitcheckingCurrent host status
SSH updaterpublic_server_update_receiptcd /opt/trustgraph && git fetch origin main && git checkout main && git pull --ff-only origin main && bash tools/update-vps-from-github.shtrustgraph-release.json returns JSON for the latest GitHub main commit instead of the app shell HTML
Saved update proofGitHub must match the server bundlegithub_pages_smoke_passes_vps_release_stamp_returns_json_server_head_matches_latest_green_main_and_vfix_route_still_serves_vfix
GitHubSource of truthmirzaraheel99/trustgraph main
Pages smokeGreen bundle firsthttps://mirzaraheel99.github.io/trustgraph/?smoke=live-script
VPS stampNot provenhttps://trustgraph.5-75-224-110.sslip.io/trustgraph-release.json
VFIX boundaryDo not touchhttps://5-75-224-110.sslip.io/CRM-client-demo/login
Hosted build sourceGitHub is current; VPS must prove the saved releasepublic_login_and_registration_must_show_github_as_source_of_truth_pages_as_green_bundle_vps_release_stamp_as_server_proof_and_vfix_as_separate_protected_route
SourceGitHub mainmirzaraheel99/trustgraph main
Green buildPages firsthttps://mirzaraheel99.github.io/trustgraph/?smoke=live-script
Server proofStamp requiredhttps://trustgraph.5-75-224-110.sslip.io/trustgraph-release.json
VFIXSeparatehttps://5-75-224-110.sslip.io/CRM-client-demo/login
Portal launch mapStart in the right portal before live database rows are created
Buyer decision boardPick the account type by role, price, and database boundarypublic_buyer_decision_board_shows_professional_corporate_scale_pricing_first_database_write_portal_outcome_and_scoped_user_database_boundary_before_signup
$0 pilotProfessionalYou own your work history, credentials, references, training, and sharing consent.
First database writeProfile, personal organization, Professional membership, then Passport records.
Portal outcomePrivate Passport workspace with evidence, consent, Access Grants, and exports.
$149/month per companyCorporate VerifyYou review candidates, staff, contractors, or clinicians after they approve scoped access.
First database writeCompany organization, admin membership, pricing ledger, team, and Verify workspace.
Portal outcomeCorporate portal can request one professional by email and see approved shared rows only.
CustomTrustGraph ScaleYou need issuer workflows, Connect clients, compliance operations, or rollout support.
First database writeHuman-gated production decision before paid checkout or regulated traffic.
Portal outcomeScale conversations start through Corporate setup while Stripe remains disabled.
professional_free_corporate_verify_149_pilot_monthly_scale_custom_stripe_disabled_until_human_gateprofessional_owns_passport_rows_corporate_requests_one_professional_by_email_and_reads_only_approved_shared_rows
Operating model

Separate portals, one verified record graph

Professional Passport

Create records, attach private evidence, request references, and approve each Access Grant.

Corporate Verify

Review approved records, request missing items, invite reviewers, and keep scope visible.

Connect and Admin

Operate Connect clients, audit events, release ledger, workflow QA, and security review.

Workflow

From record ownership to permissioned review

1Build the Passport

Professionals add work records, credentials, training, references, and evidence.

2Grant scoped access

Employers and staffing teams request only the records needed for a workflow.

3Operate with audit

Admin teams monitor cases, release readiness, security checks, and exports.

Pilot access

Start with controlled workflows, then scale

Recommended next stepStart Professional registration, then create the private Passport after hosted login.pricing_registration_handoff_keeps_plan_choice_next_registration_database_write_scoped_access_stripe_gate_and_export_visible_before_signup
1. Pick plan$0 Professional pilotBest for one person building and sharing a private Passport.
2. RegisterProfessional accountVerify email if prompted, then login here to start the live Passport workspace.
3. First writeprofile + personal Passport workspaceprofiles, personal organizations, organization_memberships, trust_records
4. BoundaryOwner controlledStripe Checkout stays disabled until the human billing decision is approved.
Which plan?Choose Professional free when one person needs a private Passport, evidence, consent, and controlled sharing.public_pricing_path_answer_recommends_professional_free_corporate_149_or_scale_quote_with_first_live_write_scoped_access_and_stripe_gate_before_plan_cards
Professional$0 pilotBest for a worker creating and controlling their own Passport.
Corporate$149/month per company pilotBest for employers or staffing teams that review approved Passport rows.
ScaleHuman-approved quoteUse only after pilot-owner, billing, legal, security, and VPS cutover decisions.
First live writeregistration_intents, profiles, personal organization, Passport rowsCorporate accessCorporate never receives open user browsing; reviewers see only professional-approved scoped rows.Payment gateStripe checkout, tax, invoices, refunds, dunning, and webhooks stay off until the billing decision is approved.
ProfessionalIndividuals
$0Free

Build a private Passport and decide exactly which records can be shared.

Database pathWrites profile, personal organization, membership, Passport records, and evidence metadata.
Private recordsEvidence uploadsAccess GrantsReference requests
Corporate VerifyEmployers and staffing teams
$149Pilot monthly

Review approved Passport records with scoped access, team roles, and audit history.

Database pathWrites organization, admin membership, plan ledger, invitations, Access Grants, and gap requests.
Corporate RBACMissing-record requestsReadiness reviewAudit trail
TrustGraph ScaleIssuers and compliance teams
CustomPilot agreement

For issuers, integrations, compliance operations, and multi-team rollout.

Database pathUses gated production decisions before external billing, regulated traffic, or issuer rollout.
Credential issuer rolesConnect API clientsWebhooksCompliance support
Live nowSupabase ledgerCorporate Verify pilot activation writes organization_subscriptions rows with audit history.
Corporate pilot$149/month per companyUsed for plan selection, company-level billing visibility, readiness checks, and pilot acceptance evidence.
Human gateStripe checkoutReal payment collection waits for product, tax, invoice, refund, dunning, and webhook decisions.
Pricing and accessProfessional - freepublic_pricing_section_explains_professional_free_corporate_149_pilot_first_database_write_scoped_user_access_and_stripe_boundary_before_signup
Professional$0 Professional Passport pilotPrivate Passport, records, evidence, consent, references, and Access Grant decisions.
Corporate$149/month per company Corporate Verify pilotCompany workspace, RBAC, team, billing ledger, Verify requests, and scoped review.
Selected pathprofile + personal Passport workspaceprofiles, personal organizations, organization_memberships, trust_records
Access ruleOwner controlledProfessional controls every Passport row, evidence item, consent decision, and corporate grant.
Payment gateStripe offSupabase subscription ledger is live for pilot planning; Stripe Checkout remains human-gated.
Before signupProfessional - freepublic_pricing_launch_decision_makes_professional_free_corporate_149_pilot_database_writes_scoped_access_and_stripe_off_boundary_clear_before_signup
User pathProfessional freeProfessional Passport stays free for the pilot and writes owner-controlled profile, Passport, evidence, consent, and sharing rows after hosted login.
Company path$149/month per companyCorporate Verify uses the $149/month per company pilot ledger for company workspace, RBAC, reviewer access, team setup, and scoped user-database requests.
Selected writeprofile + personal Passport workspaceprofiles, personal organizations, organization_memberships, trust_records, evidence_documents
Billing gateStripe offNo card capture, Stripe Checkout, invoice email, refund flow, dunning, tax, or payment webhook is live before the human billing gate.
Corporate Verify Pilot$149/month per companyOne price per company - invite as many reviewers as your pilot needs. Seat tracking is shown for admin visibility only.
Admin workspaceInitial company setup and reviewer routing.Review queueCorporate Verify requests and scoped approvals.Audit exportsPilot team setup, access receipts, and export proof.
Live Supabase AuthPrivate evidence storageScoped RBACAudit-ready workflows
Portal registration

Choose the account type before data is written

Portal decision matrixOne login system, two clean registration paths

Professionals register a private Passport first. Corporate teams register a company workspace first, then activate the Verify plan, invite reviewers, and request scoped Passport access.

Professional userStart with the free Passport, then add records, evidence, consent, and Access Grants.Corporate companyStart with Corporate Verify at $149/month per company, then provision RBAC, reviewer tracking, and review workflows.
Portal database access contractProfessional rows stay owner-controlled; Corporate rows are scoped by request, consent, and RBAC.professional_registration_corporate_registration_pricing_ledger_and_scoped_user_database_access_are_visible_before_signup
Professional registrationProfessional Passportprofile, personal organization, membership, Passport records, evidence metadataProfessional owns records and approves every Access Grant before a company can review rows.
Corporate registrationCorporate Verifycompany organization, admin membership, subscription ledger, team invitationsCompany reviewers request one professional by email and see only approved shared rows.
Pricing structurePilot ledger$0 Professional pilot and $149 Corporate Verify pilot planning rowsSupabase ledger is live for packaging; Stripe payment collection stays human-gated.
Public buyer launch pathFollow the whole path before signup creates live rowspublic_buyer_can_follow_account_choice_hosted_verification_portal_landing_pricing_scoped_database_access_proof_export_and_server_save_before_signup
1Choose accountProfessional userUse Professional Passport when you own the record.
2Hosted verificationVerify emailEmail links must return to https://trustgraph.5-75-224-110.sslip.io/; localhost links are repaired before proof.
3Portal landingPersonal PassportVerify email if prompted, then login here to start the live Passport workspace.
4Pricing boundaryProfessional - freeNo payment collection for the professional pilot plan.
5Database accessprofile + personal Passport workspaceCreate records and decide which company receives each Access Grant.
6Proof and saveGitHub savedGitHub Pages is current; VPS pull remains the server save handoff.
Registration database launch orderProfessional registration creates the Passport owner firstregistration_shows_account_choice_price_first_database_write_portal_landing_required_proof_and_server_save_before_submit
1Select accountProfessional user creates a private Passport.profile + personal workspace
2Confirm pricingProfessional - freeNo payment collection for the professional pilot plan.
3Create first live rowprofile + personal Passport workspaceprofiles, personal organizations, organization_memberships, trust_records
4Land in portalProfessional PassportVerify email if prompted, then login here to start the live Passport workspace.
5Export proofPassport records, evidence, consent, and sharing rows.Live Supabase rows only; preview data is not accepted.
Public portal launch checklistWebsite, login, registration, pricing, scoped database access, and server save path are tracked togetherpublic_website_login_registration_pricing_corporate_database_path_hosted_auth_and_server_release_are_all_clear_before_v1_launch
readyPremium public websiteHero, portal routes, pricing, operating model, and database boundaries are visible before signup.
readyProfessional registration/loginProfessional Passport starts from hosted Supabase Auth and writes owner-controlled Passport rows.
readyCorporate registration/loginCorporate Verify starts from hosted auth, then creates company workspace, RBAC, billing, and Verify paths.
readyPricing structure$0 Professional pilot and $149 Corporate Verify pilot ledger are visible; Stripe remains human-gated.
scoped onlyCorporate user database accessCorporate can request access by professional email and review only approved shared rows.
server update requiredHosted server saved buildRun the VPS update command or add GitHub SSH secrets so the server saves latest main.
Live Supabase
Professional user portal

Creates the signed-in professional profile and live Passport context before records or evidence are saved.

profiles, organizations, memberships, trust_records, evidence_documents
Live Supabase
Corporate company portal

Creates the signed-in corporate admin, employer or staffing organization, and Verify workspace access.

organizations, organization_memberships, invitations, subscriptions, access_grants
After registration

Every portal connects to the live database foundation

Professional

Creates a live profile, personal organization, Professional role, Passport records, evidence, consent, and Access Grants.

Corporate

Creates a live employer or staffing organization, admin membership, plans, invitations, member controls, and Verify requests.

Operator

Admin workspace tracks audit events, release ledger, security review, Connect controls, and pilot acceptance exports.

Portal access

Professional Passport access

Create a user account, verify email if prompted, then start your private Passport.

Start hereRegister your Professional Passportpublic_route_answer_bar_keeps_professional_register_professional_login_corporate_register_corporate_login_pricing_recovery_first_database_write_landing_submit_and_no_open_user_database_visible_as_the_first_auth_answer
SelectedProfessional registerRegister your Professional PassportPricingProfessional - freeNo payment collection for the professional pilot plan.First database writeprofile + personal Passport workspaceprofiles, personal organizations, organization_memberships, trust_recordsLandingPassport portalProfessional Passport records, evidence, consent, and sharingRecoveryEmail neededEnter email to unlock recovery tools
Preview data accepted: noCorporate cannot browse a user database. Corporate requests one professional by email and reviews only approved, consent-scoped rows.
Access answerCreate professional PassportPick one route, enter credentials once, and land in the correct portal. Pricing, recovery, first database write, and the no-open-user-database rule stay visible before submit.
RouteProfessional registrationCreate professional PassportPricingProfessional - freeNo payment collection for the professional pilot plan.First database writeprofile + personal Passport workspaceprofiles, personal organizations, organization_memberships, trust_recordsLandingProfessional PassportVerify email if prompted, then login here to start the live Passport workspace.RecoveryEnter emailEnter email to enable reset, resend, and hosted link repair.Email deliveryHosted links onlySupabase built-in email can rate-limit around 2 messages per hour. Use the newest inbox link, or repair localhost links before requesting more emails.Corporate dataScoped onlyCorporate accounts request access by professional email and review only approved scoped rows; there is no open user database browse.
public_access_answer_keeps_user_register_user_login_corporate_register_corporate_login_pricing_recovery_submit_first_database_write_landing_server_status_and_no_open_user_database_before_credentials | Server: checking | Preview data accepted: no
V1 access runwayProfessional registration: one clear path to the right portalStart here, then use the credential fields below. Professional users manage their own Passport. Corporate accounts request approved scoped rows only.
PriceProfessional - freeNo payment collection for the professional pilot plan.
First database stepprofile + personal Passport workspaceprofiles, personal organizations, organization_memberships, trust_records
LandingProfessional PassportVerify email if prompted, then login here to start the live Passport workspace.
RecoveryEnter emailResend verification, reset password, or repair localhost links from the hosted app.
Server: checkingCorporate database: scoped approval onlypublic_v1_access_runway_keeps_professional_corporate_register_login_pricing_first_database_write_recovery_scoped_database_boundary_and_server_status_visible_before_credentials
Portal access cockpitCreate your Passport first, then decide what companies can seeProfessional users own records, evidence, consent, and every Access Grant decision.
Account typeProfessional userRegister new accountPricingProfessional - freeNo payment collection for the professional pilot plan.First writeprofile + personal Passport workspaceprofiles, personal organizations, organization_memberships, trust_recordsNext dashboardPassportVerify email if prompted, then login here to start the live Passport workspace.
Start hereRegister for Professional userpublic_portal_flow_map_shows_professional_corporate_login_registration_pricing_first_database_write_landing_and_recovery_before_dense_forms
ChooseProfessional userPrivate Passport for the record owner.
AccessRegisterCreate account, verify email, return hosted.
PriceProfessional - freeNo payment collection for the professional pilot plan.
Databaseprofile + personal Passport workspaceprofiles, personal organizations, organization_memberships, trust_records
LandingProfessional PassportVerify email if prompted, then login here to start the live Passport workspace.
Hosted resend, reset, and localhost-link repair stay visible before submit.Recovery route
Choose the right routeProfessional Passportpublic_auth_starts_with_clear_user_vs_corporate_routes_pricing_first_database_write_dashboard_and_access_boundary
Register
Professional - freeSelected pricingprofile + personal Passport workspaceFirst database write
Auth landing commandCreate Professional PassportEnter email and password. Passport setup starts after verification.
Portal start deskCreate the Professional Passport accountportal_start_desk_shows_account_type_mode_pricing_first_database_write_next_dashboard_and_no_preview_rows_before_submit
AccountProfessional userPrivate Passport ownerActionRegisterCreate the Professional Passport accountFirst writeprofile + personal Passport workspaceprofiles, personal organizations, organization_membershipsBoundary$0 pilotNo payment collection for the professional pilot plan.
Passport records, evidence, consent, and sharing
1. Pick portalProfessional creates a private Passport.2. Register or loginCreate the account, then verify email if required.3. Land in dashboardOpen Passport records, evidence, consent, and sharing.
Choose this whenYou own your recordProfessionals create a private Passport and approve every sharing request.
Creates firstprofile + personal Passport workspaceprofiles, personal organizations, organization_memberships, trust_records
Pilot priceProfessional - freeNo payment collection for the professional pilot plan.
After loginPrivate Passport workspaceVerify email if prompted, then login here to start the live Passport workspace.
Public auth flow commandCreate Professional PassportEnter email and password. Passport setup starts after verification.
Account typeProfessional userPrivate Passport workspaceActionRegisterCreate Professional PassportDatabase resultprofile + personal Passport workspaceprofiles, personal organizations, organization_memberships
Registration decision receiptProfessional PassportProfessionals own Passport rows, evidence, consent, and every Access Grant decision.
Professional - freePricing pathprofile + personal Passport workspaceFirst database write2 fieldsemail, passwordProfessional PassportNo payment collection for the professional pilot plan.
Live onboarding acceptance contractProfessional Passport must prove hosted login and real rowsPreview mode, localhost email redirects, and unapproved corporate browsing are not accepted for v1 database proof.
Hosted authConfiguredRedirect must return to https://trustgraph.5-75-224-110.sslip.io/Preview dataNot acceptedV1 proof requires signed-in Supabase rows, not product preview data.First database writeprofile + personal Passport workspaceprofiles, personal organizations, organization_memberships, trust_records, evidence_documentsPassport boundaryOwner controlledprofessional owner controls Passport records, evidence, consent, and Access Grants
1hosted email verified2professional logged in3passport workspace created4real records or evidence loaded5consent or access grant ready
Selected portal routeProfessional PassportProfessional - free
profile + personal Passport workspaceFirst live database write5 tablesprofiles, personal organizations, organization_memberships, trust_records, evidence_documentsProfessional PassportVerify email if prompted, then login here to start the live Passport workspace.
Professional setup stepsVerify email if prompted, then login here to start the live Passport workspace.
Professional registration sequenceProfessional PassportVerify email if prompted, then login here to start the live Passport workspace.
1Register the professionalCreate the user account that owns the private Passport and consent decisions.2Verify and loginReturn to this hosted app after email verification or use the link repair tool if an email points to localhost.3Build the PassportAdd records, evidence metadata, references, Access Grants, and sensitive consent controls.
Portal login switchboardCompare personal and corporate routes before creating database rows.
Create private Professional PassportAdd records and evidence metadataApprove or decline each Access GrantControl sensitive consent and sharing
Auth statusComplete the account fields firstSupabase project email can rate-limit; use one resend or reset, then wait 60+ minutes if limited.
public_auth_status_strip_keeps_selected_portal_login_register_email_password_company_fields_reset_resend_hosted_redirect_rate_limit_and_localhost_repair_visible_before_submit
Registration pathRegister a Professional PassportConfirm the account path, price, first database write, hosted verification, recovery, and database boundary before entering credentials.
LandingProfessional PassportPreview dataRejectedCorporate databaseOwner grants access
public_registration_path_summary_keeps_professional_register_professional_login_corporate_register_corporate_login_pricing_first_database_write_hosted_verification_recovery_landing_and_no_open_user_database_visible_before_credentials
Auth helpEnter email before resend, reset, or link repairUse this when verification points to localhost, Supabase says rate limit exceeded, or the account needs password recovery.
public_auth_help_strip_keeps_email_ready_hosted_redirect_resend_verification_reset_password_localhost_repair_rate_limit_no_token_export_and_no_preview_data_visible_before_credentials
Plan and portalProfessional Passport Registerpublic_plan_portal_chooser_keeps_professional_login_register_corporate_login_register_pricing_first_database_write_corporate_database_boundary_recovery_and_no_preview_data_visible_before_credentials
Selected priceProfessional - freeNo payment collection for the professional pilot plan.First writeprofile + personal Passport workspaceprofiles, personal organizations, organization_memberships, trust_recordsLanding portalProfessional PassportVerify email if prompted, then login here to start the live Passport workspace.Database boundaryOwner controlledProfessional owns sharing and consent.
Professional users own their Passport, evidence, consent, and sharing decisions.
Choose routeCreate a Professional PassportProfessional users create a private Passport, add real records, then approve each company sharing request.
RouteProfessional registerProfessional PassportPricingProfessional - freeNo payment collection for the professional pilot plan.Required fields2 fieldsemail, passwordFirst database writeprofile + personal Passport workspaceprofiles, personal organizations, organization_memberships, trust_recordsHosted verificationHostedhttps://trustgraph.5-75-224-110.sslip.io/Corporate data ruleOwner approvedCompanies see Passport rows only after the professional approves a scoped grant.
Professional users own their Passport and decide what each company can review.
Start hereProfessional Passport accountOne clear path for login, registration, pricing, recovery, and the first live database write before any dense proof panels.
Selected routeProfessionalNew account registrationPricingProfessional - freeNo payment collection for the professional pilot plan.First database writeprofile + personal Passport workspaceCreates Passport owner context after authLanding portalProfessional PassportVerify email if prompted, then login here to start the live Passport workspace.
Professional users own the Passport record, evidence, recovery route, and sharing approvals before a company can see scoped rows.
Credential stepComplete required fieldsauth_credential_command_keeps_selected_route_submit_readiness_hosted_redirect_recovery_pricing_first_database_write_landing_corporate_boundary_and_next_click_visible_immediately_before_credentials
RouteProfessional registrationProfessional PassportSubmitNeeds fieldsEmail and password.RecoveryEnter emailReset and verification resend use the hosted redirect.RedirectHostedhttps://trustgraph.5-75-224-110.sslip.io/
Professional Passport rows stay owner-controlled until a scoped Access Grant is approved.
Access hubCreate your Professional PassportUsers own their records, evidence, consent, and every company sharing decision.
PricingProfessional - freeNo payment is collected for the professional pilot.Databaseprofile + personal Passport workspaceprofiles, personal organizations, organization_memberships, trust_recordsLandingProfessional PassportVerify email if prompted, then login here to start the live Passport workspace.RecoveryEnter email to enable recoveryPassword reset, resend verification, and hosted-link repair stay on this form.
01 / Choose routeUser registerThe selected route controls pricing, required fields, and landing portal.02 / Enter credentialsEmail + passwordUse hosted verification, not localhost links.03 / First database writePassport ownerprofile + personal Passport workspace04 / LandingProfessional PassportVerify email if prompted, then login here to start the live Passport workspace.05 / Corporate data ruleOwner approvalCompanies see your records only after you approve a scoped grant.
User database rule: your Passport is private until you approve scoped sharing.
Account setupCreate your private Professional PassportPick the account type and action, confirm pricing, then use the email and password fields below.
PriceProfessional - freeNo payment collection for the professional pilot plan.First database writePassport ownerprofile + personal Passport workspaceAfter loginProfessional PassportVerify email if prompted, then login here to start the live Passport workspace.
Start hereCreate Professional PassportChoose the account path first. Pricing, first database write, landing portal, recovery, and corporate access boundary stay visible before credentials.
PriceProfessional - freeNo payment collection for the professional pilot plan.First writeprofile + personal Passport workspaceprofiles, personal organizations, organization_memberships, trust_recordsLandingProfessional PassportVerify email if prompted, then login here to start the live Passport workspace.RecoveryEnter emailResend, reset, or repair hosted email links from this card.
Corporate boundaryNo open user browseServercheckingPreview dataRejected
Auth rescue checklistEnter email before resend or resetUse one resend or reset, then wait 60+ minutes if Supabase reports an email rate limit.
1. RouteProfessional registrationProfessional - free
2. EmailEnter emailRequired for login, resend verification, and reset.
3. Hosted URLHostedhttps://trustgraph.5-75-224-110.sslip.io/
4. ResendEmail neededSend once, then wait if rate limited.
5. ResetEmail neededRecovery email returns to the hosted app.
6. Repair linkPaste linkConvert localhost verification or recovery links to hosted TrustGraph.
Landing portalProfessional PassportCorporate dataScoped rows onlyPreview dataRejected
public_auth_rescue_checklist_keeps_route_email_hosted_redirect_resend_reset_localhost_repair_rate_limit_landing_portal_scoped_database_boundary_and_no_preview_data_visible_before_credentials
Start hereCreate Professional PassportPick the exact route first. Pricing, database write, recovery, hosted server status, and corporate scope are visible before credentials.
Selected routeProfessional registrationCreate Professional PassportPricingProfessional - freeNo payment collection for the professional pilot plan.Databaseprofile + personal Passport workspaceprofiles, personal organizations, organization_membershipsLandingPassport portalProfessional Passport records and sharingRecoveryEnter email to enable recoveryHosted reset, resend, and localhost-link repair stay in this flow.ServercheckingGitHub is source; VPS needs release-stamp proof before final live testing.
Live rows onlyCorporate users request a professional by email and review only approved consent-scoped rows.
public_portal_entry_desk_keeps_four_routes_pricing_first_database_write_landing_recovery_server_status_corporate_scope_boundary_and_submit_visible_before_credentials
Access studioRegister Professional PassportProfessional and Corporate users choose the portal, action, price, first database write, and recovery path before credentials.
PlanProfessional - freeNo payment collection for the professional pilot plan.First writeprofile + personal Passport workspaceprofiles, personal organizations, organization_membershipsLandingPassport portalProfessional Passport records, evidence, consent, and sharingServercheckingGitHub is source of truth; VPS freshness is checked before pilot acceptance.
Before submitProfessional registrationpublic_submit_path_checklist_shows_credentials_hosted_verification_live_database_write_landing_portal_corporate_scope_recovery_and_no_preview_data_before_submit
CredentialsNeeds fieldsEmail and password.Hosted verificationHostedhttps://trustgraph.5-75-224-110.sslip.io/Live database writeprofile + personal Passport workspaceprofiles, personal organizations, organization_memberships, trust_recordsLanding portalProfessional PassportVerify email if prompted, then login here to start the live Passport workspace.Corporate scopeOwner consentCorporate sees only approved scoped user rows; no open user database browse.RecoveryEnter emailReset password and resend verification use the hosted redirect.
Public portal route shellRegister Professional PassportChoose Professional or Corporate, confirm pricing and the first live database write, then use hosted recovery if email verification or login needs repair.
PriceProfessional - freeNo payment collection for the professional pilot plan.First writeprofile + personal Passport workspaceprofiles, personal organizations, organization_membershipsLandingPassport portalProfessional Passport records, evidence, consent, and sharingServer savecheckingGitHub Pages is deployable; VPS requires the save secrets before it is accepted as fresh.
Registration routeRegister as Professional userpublic_auth_form_starts_with_plain_registration_route_planner_showing_account_type_action_price_first_database_write_next_dashboard_and_recovery
1. AccountProfessional userPrivate Passport owned by the user.2. ActionRegisterEnter email and password. Passport setup starts after verification.3. PriceProfessional - freeNo payment collection for the professional pilot plan.4. First rowprofile + personal Passport workspaceprofiles, personal organizations, organization_memberships, trust_records5. LandingProfessional PassportVerify email if prompted, then login here to start the live Passport workspace.
Public auth front deskCreate Professional PassportVerify email if prompted, then login here to start the live Passport workspace.
Access deskRegister Professional Passportpublic_access_desk_shows_professional_or_corporate_login_register_price_required_fields_first_database_write_landing_and_recovery_before_email_fields
PortalProfessional PassportPersonal Passport, private records, evidence, consent, and grants.ActionRegisterRegister Professional PassportPricingProfessional - freeNo payment collection for the professional pilot plan.First database writeprofile + personal Passport workspaceprofiles, personal organizations, organization_memberships, trust_recordsRequired fields2 fieldsemail, passwordAfter successPassport portalProfessional Passport records, evidence, consent, and sharing
Start hereCreate the Professional Passport account, then add owned records and evidence.public_portal_launch_answer_keeps_professional_register_professional_login_corporate_register_corporate_login_pricing_recovery_server_status_first_database_write_and_no_open_user_database_visible_before_credentials
PricingProfessional - freeNo payment collection for the professional pilot plan.First database writeprofile + personal Passport workspaceprofiles, personal organizations, organization_membershipsLanding portalProfessional PassportVerify email if prompted, then login here to start the live Passport workspace.RecoveryEmail neededEnter email to enable reset and verification actionsServercheckingLooking for the release stamp on the current host.Corporate dataScoped rows onlyCorporate users request access by professional email and see only approved scoped rows. No open user database browse.
Professional PassportCreate accountPassport setup starts after email verification and login.
Professional userRegisterVerify email if prompted, then login here to start the live Passport workspace.
AccountProfessional userProfessional - freeActionRegisterEnter email and password. Passport setup starts after verification.First live writeprofile + personal Passport workspaceprofiles, personal organizations, organization_memberships, trust_records, evidence_documentsLandingPassportRecords, evidence, consent, and sharing.
SelectedPersonal portalProfessional Passport creates profile, records, evidence, consent, and sharing rows.SignupRegister accountUse hosted verification email, then return here to login.ProfessionalOpen PassportAfter login, open Passport and add real database records.
Selected pathRegister for Professional userlogin_register_card_shows_account_type_pricing_first_database_write_landing_and_required_fields_before_user_types
AccountProfessional userCreate Professional PassportPricingProfessional - freeNo payment collection for the professional pilot plan.First database writeprofile + personal Passport workspaceprofiles, personal organizations, organization_membershipsAfter successProfessional PassportVerify email if prompted, then login here to start the live Passport workspace.
Portal acceptance5/6 portal acceptance steps readypublic_portal_acceptance_requires_account_choice_hosted_auth_pricing_first_database_write_landing_portal_scoped_access_and_saved_server_build_before_live_pilot_acceptance
Choose accountProfessional userUse Professional Passport when you own the record.
Hosted verificationVerify emailEmail links must return to https://trustgraph.5-75-224-110.sslip.io/; localhost links are repaired before proof.
Portal landingPersonal PassportVerify email if prompted, then login here to start the live Passport workspace.
Pricing boundaryProfessional - freeNo payment collection for the professional pilot plan.
Database accessprofile + personal Passport workspaceCreate records and decide which company receives each Access Grant.
Proof and saveGitHub savedGitHub Pages is current; VPS pull remains the server save handoff.
Server save checkpointGitHub is saved; verify the VPS release stamp before login testinglogin_registration_form_shows_github_source_pages_smoke_vps_release_stamp_and_vfix_boundary_before_user_or_corporate_signup
Saved sourceGitHub mainmirzaraheel99/trustgraph mainHosted buildPages smokehttps://mirzaraheel99.github.io/trustgraph/?smoke=live-scriptServer targetVPS verifyhttps://trustgraph.5-75-224-110.sslip.io/trustgraph-release.jsonVFIX guardProtectedhttps://5-75-224-110.sslip.io/CRM-client-demo/login
Current server buildThis GitHub build is not accepted on the VPS until the server proves itcurrent_build_server_gate_requires_github_green_pages_smoke_vps_release_stamp_commit_json_bundle_marker_and_vfix_route_unchanged
GitHub sourceGreen mainUse the latest passed build, deploy, and smoke workflow as source.
VPS stampNeeds synchttps://trustgraph.5-75-224-110.sslip.io/trustgraph-release.json
Bundle markerRequiredThe VPS page must serve the latest TrustGraph UI marker, not an older build.
VFIX routeUntouchedhttps://5-75-224-110.sslip.io/CRM-client-demo/login
Manual VPS synccd /opt/trustgraph && git fetch origin main && git checkout main && git pull --ff-only origin main && bash tools/update-vps-from-github.sh
Manual server syncCopy the VPS command before server login testingpublic_manual_vps_sync_launcher_requires_copyable_update_command_release_stamp_json_commit_match_pages_smoke_and_vfix_route_unchanged_before_server_login_testing
CopyUpdate commandRun from the authenticated server shell in /opt/trustgraph.
VerifyRelease JSONThe stamp must return commit JSON, not the app HTML shell.
ProtectVFIX unchangedhttps://5-75-224-110.sslip.io/CRM-client-demo/login
Verify after syncgit -C /opt/trustgraph rev-parse --short HEAD && curl -I https://trustgraph.5-75-224-110.sslip.io/ && curl -fsSL https://trustgraph.5-75-224-110.sslip.io/trustgraph-release.json
Start hereCreate user PassportChoose Professional or Corporate access, see the pilot price, understand the first live database write, then continue to the right login or registration form.
Selected priceProfessional - freeFirst database writeprofile + personal Passport workspaceLanding portalProfessional PassportCorporate databaseNo open browse
Entry sequenceProfessional registration: one clear path before submitpublic_entry_sequence_requires_choose_route_credentials_hosted_verification_correct_portal_landing_corporate_scoped_database_request_and_no_preview_data_before_submit
01Choose routeProfessional registrationProfessional and Corporate users start from separate register/login paths.
02Enter credentialsCreate Professional PassportEnter email and password. Passport setup starts after verification.
03Verify emailHosted linkVerification and recovery links must land on the hosted TrustGraph URL.
04Open portalProfessional PassportVerify email if prompted, then login here to start the live Passport workspace.
05Corporate accessApprove sharingCorporate reviewers do not browse the full user database.
PriceProfessional - freeFirst database writeprofile + personal Passport workspaceVerificationHosted URL onlyCorporate databaseNo open browse
Choose your pathProfessional Registerpublic_portal_switchboard_keeps_professional_login_corporate_login_professional_registration_corporate_registration_pricing_and_recovery_visible_before_dense_receipts
Current planProfessional - free
Corporate access pathCompanies can only see your Passport after you approve a requestcorporate_access_route_preview_shows_workspace_pricing_access_request_professional_approval_scoped_rows_and_no_open_user_database_before_signup
1Professional PassportRegister the user, save profile and owner-controlled Passport rows.profiles + trust_records
2Pricing ledgerCorporate Verify uses the $149 pilot ledger; Stripe payment remains human-gated.organization_subscriptions
3Access requestCorporate reviewer requests access by professional email. No open user database is available.corporate_access_grant_requests
4Professional approvalThe professional approves, declines, or revokes the scoped Access Grant.access_grants + consent_authorizations
5Scoped reviewCorporate Verify sees approved metadata and shared Passport rows only for the active RBAC context.shared trust_records + corporate_access_reviews
No open user databaseCorporate reviewers request by email and see approved, scoped rows only.Live rows onlyCompletion needs Supabase rows, not static preview data.
Professional userRegister into Professional PassportCreate the right account type first; live database proof starts only after hosted verification and login.
AccountProfessional userCreate Professional PassportPricingProfessional - freeNo payment collection for the professional pilot plan.First database writeprofile + personal Passport workspaceprofiles, personal organizations, organization_membershipsAfter successProfessional PassportVerify email if prompted, then login here to start the live Passport workspace.
Submit readinessFinish the required fields before submitpublic_submit_readiness_shows_submit_enabled_state_required_fields_first_database_write_completion_status_recovery_and_no_preview_data_before_auth_submit
SubmitNeeds fieldsEmail and passwordDatabaseprofile + personal Passport workspaceprofiles, personal organizations, organization_memberships, trust_recordsCompletionpassport initialized after hosted loginProfessional Passport, records, evidence, consent, and sharingRecoveryEnter emailPassword reset and hosted verification repair stay on this card.
Selected portal commandCreate Professional PassportEnter email and password. Passport setup starts after verification.
emailpassword
Portal submit receiptProfessional user portalProfessional proof is accepted only after signed-in Passport rows load from Supabase.
Submit actionRegister new accountEmail and passwordLive writeprofile + personal Passport workspaceprofiles, personal organizations, organization_memberships, trust_records, evidence_documentsDashboardProfessional PassportProfessional Passport, records, evidence, consent, and sharing
Pre-submit checklistConfirm the live database path before creating the accountregistration_form_shows_required_fields_first_database_write_pricing_next_dashboard_and_preview_rejection_before_submit
Required fields2email, passwordFirst database writeprofile + personal Passport workspaceprofiles, personal organizations, organization_memberships, trust_recordsPricing pathProfessional - freeNo payment collection for the professional pilot plan.After submitPrivate PassportProfessional Passport, records, evidence, consent, and sharing
Registration pricing gateRegister with Professional - freepublic_registration_pricing_gate_requires_selected_portal_register_or_login_price_plan_first_database_write_registration_intent_stripe_boundary_server_save_and_no_preview_data_before_credentials
PortalProfessional PassportCreates the matching live registration intent first.PriceProfessional - freeprofessional-free-pilotFirst rowprofile + personal Passport workspaceregistration_intentsStripeNo checkoutnot_required_for_professional_pilotServerGitHub savedRun the VPS sync command after GitHub goes green.
Server proof neededServer page is live, but the saved build is not proven currentA 200 page can still be the app shell. Verify trustgraph-release.json returns commit JSON before treating this VPS as updated.
VPS page200 is not enoughhttps://trustgraph.5-75-224-110.sslip.ioRelease stampJSON requiredhttps://trustgraph.5-75-224-110.sslip.io/trustgraph-release.jsonCommitnot_provenMust match latest green GitHub main commit.VFIXProtectedhttps://5-75-224-110.sslip.io/CRM-client-demo/login
Registration credentialsProfessional Passport accessCreate or login to your private Passport account. You control evidence, records, consent, and company sharing.
Selected pathRegister - ProfessionalProfessional - free
PreflightProfessional registration needs required fieldsCorporate registration needs company fields before Supabase signup. Hosted email verification and recovery use the active TrustGraph redirect.
Required2 fieldsemail, password
Missingemail, passwordComplete these before submit.
First database writeprofile + personal Passport workspaceprofiles, personal organizations, organization_memberships
Hosted emailrequired before loginEmail links must return to https://trustgraph.5-75-224-110.sslip.io/
Corporate scopeOwner controlledProfessional Passport rows stay private until sharing is approved.
RecoveryEnter emailResend verification and reset password stay on this card.
Professional credentialsComplete required fieldsMissing: email, password.
Hosted redirectReadyFirst writeprofile + personal Passport workspaceRecoveryEmail needed
credential_action_bar_keeps_selected_public_route_missing_fields_submit_button_hosted_redirect_recovery_first_database_write_landing_and_scoped_corporate_boundary_visible_before_credentials
EmailRequiredPasswordRequiredWorkspaceNot neededFirst database writeprofile + personal Passport workspace
Account helpEnter email to unlock recovery actionsReset password, resend verification, or repair a localhost email callback without leaving the login path.
Paste a localhost verification link in the recovery panel if Supabase sends the wrong callback.
Registration outcome commandCreate account routes to Professional Passportregistration_outcome_command_requires_selected_portal_mode_required_fields_price_registration_intent_completion_landing_portal_recovery_server_freshness_and_no_preview_data_before_submit
You are doingProfessional registrationCreates or prepares account access.First database resultprofile + personal Passport workspaceprofiles, personal organizations, organization_membershipsRequired fields2 fieldsemail, passwordPricingProfessional - freeProfessional Passport starts free.Completion rowpassport initialized required after hosted loginRegistration intent status must be reconciled from Supabase after hosted login.After successProfessional PassportVerify email if prompted, then login here to start the live Passport workspace.Server and recoverycheckingEnter email to enable recovery controls.
Completion handoffProfessional signup must finish with a Passport contextregistration_completion_handoff_requires_hosted_verification_registration_intent_completion_professional_or_corporate_landing_dashboard_next_action_and_no_preview_data
Hosted verificationRequiredEmail confirmation must return to the hosted TrustGraph URL.Completion rowpassport_initializedregistration_intents.status = passport_initialized after the owner Passport context is loadedLandingProfessional PassportLogin after hosted verification, create Passport records and evidence, then approve scoped sharing only when ready.AcceptanceLive rows onlyPreview, browser-only, or unverified rows do not satisfy portal completion.
Live database handoff proofprofile + personal Passport workspace then Passport setup
Live database handoffProfessional Passport pathRegister, verify, login, then build the private Passport.
LoginVerified professional signs in on the hosted TrustGraph URL.PassportPrivate Passport workspace opens for records, evidence, references, consent, and Access Grants.SharingCorporate teams see only records approved through scoped Access Grants and consent.
Selected pathProfessional PassportProfessional - free
profile + personal Passport workspacePrimary database write5 tablesprofiles, personal organizations, organization_memberships, trust_records, evidence_documents
Verify email if prompted, then login here to start the live Passport workspace.No payment collection for the professional pilot plan.
Hosted auth redirect verification receiptEmail links must return to the production TrustGraph appsupabase_site_url_and_redirect_urls_include_github_pages_and_trustgraph_vps_and_email_links_return_to_hosted_app_not_localhost
Current browserHostedserver-render
Return URLTrustGraph hostedhttps://trustgraph.5-75-224-110.sslip.io/
Allowed redirects3 requiredhttps://trustgraph.5-75-224-110.sslip.io/, https://mirzaraheel99.github.io/trustgraph/, https://trustgraph.5-75-224-110.sslip.io
Link repairWaitingPaste a localhost email link to convert it.
Confirm Supabase Site URL and allowed redirects before resending email.
Email troubleshootingBefore requesting another Supabase email, choose the right recovery pathauth_email_troubleshooting_strip_keeps_rate_limit_wait_smtp_localhost_link_repair_reset_password_hosted_redirect_and_no_preview_data_visible_before_more_email_requests
Rate limitWait 60+ minSupabase built-in email can pause after 2 messages per hour project-wide; wait 60+ minutes or configure SMTP.Do not keep resending
Localhost linkPaste linkPaste the localhost email link in the repair field before requesting another email.Copy hosted link
Reset pathEmail neededEnter email before requesting resend or reset.Reset password
Auth recovery command centerVerification emails must return to hosted TrustGraphhttps://trustgraph.5-75-224-110.sslip.io/
Auth recovery database receiptSave recovery proof after hosted loginPersists hosted redirect, selected portal, email rate-limit guidance, localhost link repair status, and owner-scoped recovery proof.
0Receipt rowsprofessionalPortalNoLocalhost repairHostedRedirect
Hosted callback acceptance proofno callback detectedserver_render callback via none; TrustGraph records only callback metadata and redacts tokens.
NoneAccess token signalNoneRefresh token signalHostedBrowser origin
Open the hosted TrustGraph app before requesting verification or recovery email.
Verification, recovery, and link repairUse after rate limits, localhost links, or password recovery issues
Auth recovery decision pathPick the recovery action by what happenedKeep the email field filled before using verification or password recovery actions.
New account verificationResend verificationUse when signup succeeded but the email has not arrived or still points to an old redirect.
Existing account recoveryReset passwordUse when the user already exists, forgot the password, or cannot complete login.
Localhost link repairCopy hosted linkPaste Supabase links that point to localhost and convert them to the hosted TrustGraph URL.
Registration auth readiness packetExports hosted redirect status, selected portal, pending corporate setup, repaired-link readiness, and Supabase Auth action items.
Create an account. Email verification may be required; Supabase built-in email allows 2 messages per hour.Hosted Supabase Auth is configured. Allowed redirect URLs must include GitHub Pages and the VPS TrustGraph URL, not localhost. Active redirect: https://trustgraph.5-75-224-110.sslip.io/Supabase built-in email is limited to 2 emails per hour project-wide; custom SMTP is needed for heavier testing.