Public Review CandidateBuild 15 · SIW / Canon Reader integrationReview guidenoindex · staged, not linked
Scientist profile · institution profile · keys & provider access

GGKS profiles and provider access

These screens are real UI, wired to check for a signed-in identity before showing anything. They are not yet backed by a persisted, authenticated service — see the honest status below rather than a form that would silently collect and discard what you enter.

Sign-in required — service not yet configured for this browser

Individual and institution profiles, roles, and provider-access settings are designed to run through Genesis's Cloudflare Access-backed identity service. That service requires a one-time sign-in by an authorized administrator (Richard Lynes) directly on this machine, using a one-time email PIN — a step this deployment cannot perform on your behalf.

Until that sign-in has been completed, this page correctly shows every field below as unavailable rather than presenting a working-looking form that would collect details it cannot save, enforce, or protect.

1 · Individual

Scientist profile

Personal details
Unavailable — sign-in required
Affiliation
Unavailable — sign-in required
Research interests
Unavailable — sign-in required
Workspace / project references
Unavailable — sign-in required
Assigned roles
Unavailable — sign-in required
Provider-access status
Unavailable — sign-in required

When connected: editing your own profile will never let you grant yourself a role or institutional membership — those changes require a separate, authorized administrator action, enforced server-side.

2 · Institution

Institution profile

Institution details
Unavailable — sign-in required
Authorized administrators
Unavailable — sign-in required
Membership & roles
Unavailable — sign-in required
Associated projects
Unavailable — sign-in required
Usage limits
Unavailable — sign-in required

Each institution's records are isolated by design; administrative actions are available only to that institution's authorized administrators once the identity service is connected.

3 · Credentials

Keys & provider access

Credential ownership
Unavailable — sign-in required
Provider & scope
Unavailable — sign-in required
Status
not configured · awaiting approval · ready · invalid · revoked — none available until sign-in

No key-entry field is shown here. A missing secure backend must not collect a secret it cannot protect. Provider API keys and receipt-signing keys are always kept distinct and always stay server-side — never in prompts, browser storage, logs, receipts, or exports.

What "connected" will require

The prepared guided-service setup binds this workspace to Cloudflare Access (team small-fog-baf5), a one-time email-PIN sign-in for an explicitly authorized address, and a 30-day synthetic-workspace policy with researcher/custodian roles. It does not enable live AlphaGenome execution. Institutional provider access is only ever the institution's own configured credential — sharing one scientist's personal key is never treated as institutional access.