Build record

Co-owner & administrator oversight update - 6 October 2026

1. Two owners (full co-owner model)

  • •A company can now have a primary owner plus an optional second co-owner, so the property can be run when the primary owner has a day off.
  • •The second owner is recognised as a full co-owner across the property: the Wave board, Pulse, the employer dashboard and employee invites.
  • •A denormalized secondary_owner_email field is stamped on every owner-gated record (WaveSession, WaveRoom, WaveTeam, WaveRoomStage, WaveReport, CporScore, RpsScore) and the row-level security on those entities grants the co-owner equal create, read, update and delete access.
  • •Company registration accepts an optional second owner email, and the Organisations admin screen has a "Second owner (co-owner)" card to set or change it at any time.
  • •Ownership transfer automatically clears the secondary slot if the new primary owner was the co-owner (a user cannot hold both roles).

2. Administrator can view any property

  • •The platform administrator can open any organisation's live dashboards as if they were the owner, for full interactive troubleshooting access.
  • •The Organisations overview has a "View this property" card with buttons to open the Employer dashboard, Wave board or Pulse for the selected organisation.
  • •While viewing, a cyan banner reads "Viewing as administrator - full interactive access" with a one-click Exit back to Organisations.
  • •Writes made during an admin view are stamped with the property's owner email (not the admin), so the data stays owned by the organisation.
  • •The administrator bypasses all row-level security, so every record across the app is reachable for audit and repair.

3. Administrator access model

  • •The sole platform administrator is rena_nz@hotmail.com. Everyone else is role "user".
  • •User-role accounts are locked by row-level security to their own organisation's data; they cannot reach admin screens or other organisations.
  • •Code editing is a builder/dashboard action separate from the admin role, so no app user (even an admin-role account) can change the app's code.
  • •Admin-only surfaces include Organisations (every company), per-org Overview and Configuration tabs, the data-integrity audit and repair suite, and full interactive access to each property.

4. What was changed (build record)

  • •Entities updated (added secondary_owner_email + RLS): Company, WaveSession, WaveRoom, WaveTeam, WaveRoomStage, WaveReport, CporScore, RpsScore.
  • •Backend functions updated: createCompany, transferOrgOwnership, startWaveStage, completeWaveStage, uncompleteWaveStage, completeMidServiceRoom, getWaveRoster, syncWaveMembership.
  • •Frontend updated: CompanySignup, EmployerDashboard, WaveAdmin, WaveReportsTab, Pulse, OrgOverviewTab, OrgDetail, useMyCompany (new), useWaveViewer, useOperationsAddon, WaveCporPanel, WaveRpsPanel, waveReportArchive.
  • •New shared hook: useMyCompany resolves the acting company (admin view override, or primary/secondary owner) in one place.