FredericRepair IT Services

FREDERICREPAIR IT SERVICES

Business Operating System

FRBOS Documentation

Version
3.1
Last updated
2026-09-02
Status
CONTROLLED PILOT
Document owner
FredericRepair IT Services

The PDF is generated from this same documentation source, with a table of contents, section numbering, page numbers and the generation timestamp. It contains no passwords, tokens or credentials.

Every section states what is actually implemented. A capability is marked LIVE only when it works end to end in FRBOS today; anything depending on infrastructure that has not been deployed is marked accordingly.

Part I — Role Guides

Written for the person doing the work. Each guide states what that role can actually do in FRBOS today.

1. FRBOS Overview

LIVE

FRBOS is the internal operating system of FredericRepair IT Services: customers, repairs, service requests, quotes, technicians, inventory, organizations, internships, security and internal AI in one authenticated environment.

2. Administrator Guide

LIVE

One root Owner / Administrator bootstraps the installation at /setup/administrator, then invites every other user. The Administrator controls who has access, which organization, which role and which modules. The Administrator never sees another person's password.

  • • Root identity: enforced by a database invariant, not by the interface.
  • • Sensitive actions are written to the audit log.

3. Manager Guide

LIVE

Managers run the daily operation: service desk, quotes, technician assignment, approvals, reporting and organization records, within the permissions the Administrator granted.

4. Technician Guide

LIVE

Repairs, service requests, evidence photos, parts, time logs, customer acceptance and remote-support participation. Technicians see the work assigned to them.

5. Reception Guide

LIVE

Call next, intake, queue folders, customer history and assignment from /support-queue/reception.

6. Supervisor Guide

LIVE

Interns, daily and weekly reviews, task and evidence approvals, evaluations and employment recommendations. Every supervisor relationship uses a real authenticated user UUID.

7. Intern Guide

LIVE

Orientation, assigned tasks, daily reports, evidence, skills and self-assessment. Training and supervised production are separated; interns never see unrestricted internal information.

8. Customer Guide

LIVE

The customer portal covers service requests, repair status, quotes and approvals, devices, technology health and remote-support consent. Customers can never create a staff account.

9. Remote Support Guide

CONTROLLED PILOT

Authorization, endpoint agent, connection, granular permissions, troubleshooting and termination. Effective access is always grant ∩ endpoint capability ∩ live transport.

  • • Signed production agent: NOT CONFIGURED
  • • Rendezvous service: NOT DEPLOYED
  • • TURN / relay: NOT DEPLOYED
  • • Two-machine field acceptance: NOT COMPLETED
  • • Status stays CONTROLLED PILOT / NOT FIELD PROVEN until all four are done.

10. Security Guide

LIVE

Authentication and MFA through the authentication provider, role-based access, row-level security, audit logging, the Threat Centre and incident response. Private configuration, secrets and credentials are never published.

  • • External threat-intelligence provider: NOT CONFIGURED
  • • SMS / push security notifications: NOT CONFIGURED
  • • In-app and email notifications: LIVE

11. Internal AI Guide

CONTROLLED PILOT

Access tiers, knowledge approval, human approval before action and confidential-information handling for the FRBOS internal assistant.

12. Organization Guide

LIVE

The internal FRBOS organization is distinct from customer organization workspaces. Organization data is isolated by row-level security and never shared across tenants.

Part II — Module & Policy Reference

Module-by-module reference, system status and the security and privacy principles FRBOS is built on.

13. Administrator & Identity Management

LIVE

FRBOS has exactly one root Administrator. The single-root rule is enforced by a database invariant (a partial unique index on the owner role), not by the interface, so it cannot be bypassed from a browser. First-run setup at /setup/administrator creates that identity through the authentication provider and records the real authentication UUID. Every later account is created by the Administrator, either by invitation — the employee sets a password FRBOS never sees — or, where the business requires it, with a temporary credential handed over in person.

  • • Temporary credentials are passed straight to the authentication provider; they are never stored, displayed after provisioning, emailed, logged or written to the audit trail.
  • • An account opened with a temporary credential must replace it at first sign-in before any module is reachable.
  • • Employees manage their own permanent password, recovery and MFA. The Administrator can never view them.
  • • The Administrator assigns roles, module permissions, organizations and departments, and can suspend, revoke or reactivate accounts.
  • • The Administrator cannot create a second active root Administrator, and the root account has no self-delete option.
  • • Administrator recovery uses the authentication provider's secure recovery mechanism.
  • • Role, permission and account-lifecycle changes are written to the audit log.

14. Command Centre

LIVE

/command-centre aggregates what needs attention now: new security events, failed and suspicious authentication activity, permission violations, cross-organization access attempts, account changes, invitations, suspensions, support queue pressure, quotes awaiting approval and remote-support activity. It includes SECURITY EVENTS SINCE LAST REVIEW and a WHILE YOU WERE AWAY digest built only from stored events.

15. Team & Employee Management

LIVE

/team lists staff with status, role and presence. Administrators invite employees, provision temporary credentials where authorized, assign roles and module permissions, and suspend, archive, restore or revoke accounts. History is never deleted.

16. Customers & Organizations

LIVE

Customer records, devices and asset management, plus multi-tenant organization workspaces for businesses, schools, churches and agencies with departments, locations, shared assets and approval workflows. Tenant data is isolated by row-level security.

17. Support Queue

LIVE

Intake, reception call handling, queue folders, triage, assignment and review from /support-queue. Requests carry their origin, customer history and the technician responsible.

18. Repairs & Service Requests

LIVE

The unified service workflow: request, queue, dispatch, assessment, quote, customer approval, repair, completion, invoice and customer history. Work in progress and invoicing are blocked by a database rule until the customer approves a sent quote.

19. Remote Support

CONTROLLED PILOT

The intended workflow is See → Authorize → Connect → Control → Troubleshoot → Document → Terminate. The customer requests assistance, the technician requests access, and the customer authorizes each capability separately: screen view, mouse, keyboard, clipboard, file transfer and application launch. Authorization is attended, time-limited and revocable at any moment by the customer. Effective access is always grant ∩ endpoint capability ∩ live transport, evaluated on the server.

  • • Status: CONTROLLED PILOT / NOT FIELD PROVEN.
  • • Browser screen sharing is view-only. It is not, and must not be described as, full operating-system control.
  • • Operating-system control requires the native endpoint agent, and only for capabilities the endpoint actually reports and the customer has authorized.
  • • Signed production agent: NOT CONFIGURED — REQUIRES EXTERNAL INTEGRATION (code-signing certificate).
  • • Rendezvous service and TURN / relay: NOT CONFIGURED — REQUIRES EXTERNAL INTEGRATION (hosted infrastructure).
  • • Two-machine, cross-ISP field acceptance: NOT COMPLETED.
  • • FRBOS does not claim production-ready remote control until all of the above are complete.

20. Security & Threat Centre

LIVE

/security/threat-centre records observable technical information about security-relevant events and lets an authorized reviewer classify, annotate and resolve them. Recorded evidence, where technically available, includes: timestamp; source IP; country; approximate location; region or city; ASN; network or provider; application or client; browser; operating system; user agent; target route, API or resource; event type; requested action; result; reason; authentication state; user UUID when legitimately known; organization when legitimately known; correlation or session information; and related events.

  • • Evidence is presented in three clearly separated tiers: OBSERVED FACT, THREAT INTELLIGENCE and ANALYST INTERPRETATION.
  • • External threat intelligence: NOT CONFIGURED — REQUIRES EXTERNAL INTEGRATION. Until connected, the THREAT INTELLIGENCE tier shows NOT CONFIGURED.
  • • SMS / push security notification delivery: NOT CONFIGURED. In-app and email notifications: LIVE.

21. Identity Protection

LIVE

An IP address, country, ASN, ISP, browser or operating system does not by itself establish the identity of a person. These are network and client indicators only. FRBOS never invents a person's name, a person's photograph, a criminal identity or a threat-actor identity, and never builds a dossier on a private individual.

  • • Where legitimate external threat intelligence provides an attribution, FRBOS shows the attribution together with its source, its confidence and its timestamp.
  • • Where no such attribution exists, FRBOS shows: Identity: UNKNOWN.

22. Careers & Hiring

LIVE

/careers publishes openings; the hiring dashboard runs the pipeline from application through interview to selection. A selected candidate is converted to an employee through the Administrator invitation flow, which produces a real authentication identity. Advancement through Candidate → Intern → Trained Intern → Supervised Technician → Employee → Senior Technician → Supervisor is a management decision and is never automatic.

23. Internships

LIVE

A standardized internship and supervision system covering applications, orientation, assignment, supervision, daily and weekly reports, tasks, evidence, skills, evaluations, final reports and employment recommendations, with reusable templates for IT support, infrastructure, networking, cybersecurity, repair, help desk, web and software, CCTV, business administration, marketing and AI positions. Training and supervised production are separated; supervisor access is relationship-scoped.

24. Financial / Tax Management

LIVE

Quotes, invoices, payments, recurring revenue and membership subscriptions, with Canadian provincial tax presets (Ontario 13% HST by default) and CAD, USD and EUR currency support. Verified end-to-end billing is confirmed for Canada today.

25. System Status & Integrations

CONTROLLED PILOT

FRBOS publishes an honest status for every capability rather than an aspirational one. A capability is LIVE only when it works end to end in FRBOS today.

  • • Core operations (identity, customers, service requests, repairs, quotes, invoicing, organizations, internships, audit): LIVE.
  • • Remote Support: CONTROLLED PILOT / NOT FIELD PROVEN.
  • • Internal AI: CONTROLLED PILOT.
  • • SMS and push notification delivery: NOT CONFIGURED — REQUIRES EXTERNAL INTEGRATION.
  • • External threat intelligence: NOT CONFIGURED — REQUIRES EXTERNAL INTEGRATION.
  • • Signed remote-support agent distribution, rendezvous and TURN/relay infrastructure: REQUIRES EXTERNAL INTEGRATION.

26. Acceptance Testing

LIVE

/admin/acceptance is the official Root Administrator acceptance-testing surface. It defines the A–S test framework: first-run root setup, root login, employee invitation, employee verification, password creation and change, MFA where configured, real UUID receipt, role assignment, permission assignment, authorized module access, unauthorized module blocked, password recovery, logout, second-device login, suspension, revoked access denied, second root creation denied, audit events verified and cross-organization access denied.

  • • A recorded run must contain a real tester, date and time, device, browser, operating system, environment, evidence, result and, on failure, the exact error information.
  • • A test with no recorded run remains NOT VERIFIED. FRBOS never generates evidence and never converts NOT VERIFIED into PASS.
  • • At the time of this revision no acceptance run records exist, so all A–S tests are NOT VERIFIED.

27. Security & Privacy Principles

LIVE

FRBOS is designed around least privilege, server-side authorization, database-level row-level security, organization isolation, auditability, explicit customer authorization, credential protection, secure authentication, revocation, expiration and fail-closed controls. Authorization is never decided in the browser: role, permission and tenant checks are evaluated on the server and in the database, so modifying browser requests, local storage, React state, URL parameters or payload identifiers cannot grant access.

  • • FRBOS maintains no password table. Passwords, reset tokens, MFA secrets and session secrets stay under the authentication provider's control.
  • • Passwords and secrets never appear in audit logs, application logs, analytics, emails, browser responses or this document.
  • • Remote access is attended, explicitly authorized, granular, time-limited, revocable and fully audited.
  • • FRBOS does not provide, and will not provide, covert monitoring, credential collection or unauthorized remote access.

28. Future / Planned Capabilities

PLANNED

Capabilities that are intended but not implemented today are listed here so that no reader mistakes an intention for a feature.

  • • Signed production remote-support agent with hosted rendezvous and relay: PLANNED — REQUIRES EXTERNAL INTEGRATION.
  • • Managed (unattended) device access as a separate, explicitly contracted product: PLANNED.
  • • SMS and push notification channels: PLANNED — REQUIRES EXTERNAL INTEGRATION.
  • • External threat-intelligence enrichment: PLANNED — REQUIRES EXTERNAL INTEGRATION.
  • • Spanish, Portuguese, Arabic and Swahili interface coverage: PLANNED.
  • • Verified end-to-end billing outside Canada: PLANNED.

This document contains no passwords, tokens, API keys, environment variables or authentication credentials, and never will. Authentication secrets remain under the control of the authentication provider.

FredericRepair IT Services — Your Concern. Our Solution.