L3 dataroom candidate

A bespoke self-hosted publication portal

This candidate scaffold is intentionally not a generic File Browser or vanilla Nextcloud install. It scopes a VPS-deployable dataroom for investors, vendors/service providers, and internal L3 admins/editors.

Audiences

3

Investors, vendors/service providers, and internal L3 admins/editors.

Canonical entities

15+

Required domain model plus source/import/session support tables.

Access stance

Deny

Default deny with explicit grants and deny override.

Dashboards

External

Linked through environment-backed launch cards for now.

Product boundary

Publication, not raw file browsing

Projects, collections, documents, versions, requests, Q&A, and dashboards are first-class objects. Dropbox remains source/reference, not the investor/vendor UI.

Access control

Default-deny grants

Every project, document, dashboard card, upload request, file request, and Q&A thread is governed by explicit grants with deny override.

File security

Signed document access

Document binaries remain private. Preview/download requests must pass authorization and receive short-lived signed access.

Audit

Immutable evidence trail

Audit events are append-only, hash-chained, redacted, and exportable so L3 can prove who accessed what and when.

Dashboard gateway

Environment-backed launch cards

The database stores safe app keys. Runtime URLs remain outside source and are resolved only after authorization and audit.

L3_OVERVIEW

L3 Overview Dashboard

External dashboard launch is governed by portal grants; the runtime target stays in environment configuration.

DASHBOARD_L3_OVERVIEW_URLNot configured

VENDOR_STATUS

Vendor Status Dashboard

Vendors see only explicitly granted launch cards. Launch events are audited before redirection.

DASHBOARD_VENDOR_STATUS_URLNot configured

Internal controls

Admin/editor modules to build

These are route placeholders for the real modules: users, organizations, projects, grants, audit, and dashboard app registry.