Path: Platform ops provision
Audience: platform operators in the PRESHai org (org_id = 1, platform_ops role). Internal audience. Time: about 30 minutes plus provisioning wait. Prerequisite: org-1 membership with the platform_ops role.
By the end of this path a customer tenant exists, is core-ready, ran its first governed session, and handed off to steady state with open items ticketed.
Work the steps in order. Each step links the Build page that shows how; this path adds no new reference of its own.
Step 1: orient (5 min)
Section titled “Step 1: orient (5 min)”- Read the Ops overview.
- Know the access model cold: Provisioning and internals — org 1 as control plane,
requirePlatformOps,org_id=1on API calls, what never goes in this wiki.
Check: you can state why org 1 cannot be suspended and where object defaults publish from.
Step 2: create and provision (10 min plus wait)
Section titled “Step 2: create and provision (10 min plus wait)”- Run the concrete sequence: New-tenant checklist phases 1 to 3 — Create tenant in
/admin/tenants(Kind Customer, slug, hostname), theprovision-tenantworkflow, the readiness gate (GET /api/v1/admin/tenants/[id]/provisioningplusevaluateTenantReadiness, never guessing). - Keep the runbooks open for intake, failure, and escalation handling.
Check: tenant core-ready (includes vercel_alias); hostname serves the right deployment; at least one Agent Environment exists or is explicitly scheduled pre-invite.
Step 3: invite to Day-0 (5 min)
Section titled “Step 3: invite to Day-0 (5 min)”- Owner accepts the invite on the tenant hostname and walks Day-0:
/preparingif seen, onboarding wizard (org name required), dashboard, Settings. - Multi-tenant operators reach the tenant through My tenants.
Check: owner signed in at the correct hostname; org identity confirmed in Settings.
Step 4: verify first value (10 min)
Section titled “Step 4: verify first value (10 min)”- One governed session to a recorded outcome in an appropriate environment: Your first session.
- At least one approval decision observed (or a clear reason none fired): Approving agent actions.
- Record retrievable under the right org scope: Observability.
Check: first-value verification recorded (hostname, org, session outcome, approval observation).
Step 5: hand off (ongoing)
Section titled “Step 5: hand off (ongoing)”- Enroll partner admins via
/admin/tenants/[id]Members; publish object defaults preview-then-apply (checklist phase 6). - Point the admin at the Day-0 admin path and the Tenant admins section; track the tenant (hostname, org, phase, open requests) with open items ticketed, none verbal.
Check: handoff complete, posture reviewed, tenant tracked.
What next
Section titled “What next”- Field builds on the new tenant run through the FDE path.
- Day-to-day supervision rhythm is the User sessions path.

