Audiences
3
Investors, vendors/service providers, and internal L3 admins/editors.
L3 dataroom candidate
This candidate scaffold is intentionally not a generic File Browser or vanilla Nextcloud install. It scopes a VPS-deployable dataroom for investors, vendors/service providers, and internal L3 admins/editors.
Audiences
3
Investors, vendors/service providers, and internal L3 admins/editors.
Canonical entities
15+
Required domain model plus source/import/session support tables.
Access stance
Deny
Default deny with explicit grants and deny override.
Dashboards
External
Linked through environment-backed launch cards for now.
Product boundary
Projects, collections, documents, versions, requests, Q&A, and dashboards are first-class objects. Dropbox remains source/reference, not the investor/vendor UI.
Access control
Every project, document, dashboard card, upload request, file request, and Q&A thread is governed by explicit grants with deny override.
File security
Document binaries remain private. Preview/download requests must pass authorization and receive short-lived signed access.
Audit
Audit events are append-only, hash-chained, redacted, and exportable so L3 can prove who accessed what and when.
Dashboard gateway
The database stores safe app keys. Runtime URLs remain outside source and are resolved only after authorization and audit.
L3_OVERVIEW
External dashboard launch is governed by portal grants; the runtime target stays in environment configuration.
VENDOR_STATUS
Vendors see only explicitly granted launch cards. Launch events are audited before redirection.
Internal controls
These are route placeholders for the real modules: users, organizations, projects, grants, audit, and dashboard app registry.