# Conference team — administrator setup

The frontend is hosted; database schema, approved accounts, and live saving still require this setup. The browser publishable key cannot provision them. Do not send passwords, admin tokens or service-role keys in chat.

## 1. Schema (can be done before choosing team emails)
Open this Supabase project in its dashboard: kxekqaqamocjvmpimcnu. Open **SQL Editor**, paste the entire downloaded **setup.sql**, and Run. It creates namespaced conference tables, assignment catalog, RLS, revision-checked save function and the Realtime publication entry. No existing non-conference tables are touched. Run once, or rerun idempotently for this release. Do not expose service-role credentials in the frontend.

## 2. Accounts, privately
In **Authentication → Providers → Email**, enable email/password login. Disable public new-user signup (recommended); even if left enabled, signup NEVER grants team access. In **Authentication → Users → Add user → Create new user**, manually create each of the four real teammates using their own email and a strong unique password. Auto-confirm each email in the dashboard so no SMTP email is required. Deliver credentials privately to the correct person, never through this chat or public site. The site does not offer signup, magic links, or password-reset email; an administrator handles resets in the dashboard. Do not share one login among P1–P4.

## 3. Approved membership
Download **membership.sql**. Replace the four REPLACE_Pn_EMAIL placeholders with the exact four existing account emails. Run it separately in SQL Editor. It maps each auth.users UUID to exactly one unique P1–P4 role. Missing placeholders/accounts abort the entire transaction. No signup metadata can grant membership. No real emails are embedded in the public app or downloadable scripts.

## 4. Verify with two real browsers (not yet performed)
- Sign in P1 in browser A and P2 in browser B. Both must show their mapped role and “Live · subscribed”.
- P1 saves a note/visited on a P1 assignment. Browser B should update automatically. P2 can read but cannot edit P1; P2 can edit P2.
- Refresh both: saved state must persist. Export only from an approved member session.
- Use two sessions for the same approved account: edit the same record without saving, save in the other. The first draft must stay intact and show conflict. Compare the server copy, then explicitly load latest or keep draft against latest revision before saving.
- Disconnect/reconnect: see connection status; reconnect and returning to the tab refetch saved rows without replacing dirty drafts.
- Anonymous and a manually created but UNMAPPED test account must be unable to read ANY notes or write. Test via the client and API, not just disabled buttons. Public direct table writes must fail even for mapped accounts; only conference_save RPC writes.
- Test revoked membership: database/API must deny access; the app clears notes when its periodic/focus membership refresh detects revocation. Previously seen/exported information cannot be remotely recalled.

All approved members can read ALL team notes. Each member can write ONLY their own mapped assignments. All notes and visits save together using optimistic revision checks; stale writes fail, not overwrite. Maximum note length: 12,000 characters. No hard-delete control is provided. Drafts are only in memory: save/export/copy them before leaving. Signing out clears in-memory team notes and session storage credentials. Prefer trusted personal devices; sessions use sessionStorage, not persistent localStorage.

## Troubleshooting
- “Schema pending”: run setup.sql, confirm the conference tables and function exist in public schema.
- “Membership pending”: sign-in succeeded but UUID has no conference_members row; complete phase 3.
- “Login failed”: verify the manually created account, password and email confirmation in the dashboard. Never paste credentials into a support chat.
- “Reconnect…”: check internet and Realtime publication for conference_notes. Automatic 30-second reconciliation remains available and labeled; don't claim live subscription is working until “Live · subscribed” appears.
- “Revision conflict”: compare latest saved copy with your retained draft. Do not blindly overwrite.

The public timetable is a faithful conversion of the two supplied concise reports, NOT the entire official conference paper inventory. Original links, schedules, optionality and caveats are preserved, including uncertain reception attendance and the October 14 overlap. Confirm timetable freshness onsite.
