Workbook

Platform Developer

You own: the GeneFlow / GeneData platform itself. You extend it, debug it, extract services from it, and ship new dashboards. Platform Developer is the only see-everything-AND-write role — pair it with tenantRole=editor or admin.

NOT the same as "Developer"

FunctionWhoSeesWrites
developer (legacy)Customer building custom connectors / agents / plugins on top of GeneDataDeveloper + SDK + Marketplace sections onlyYes, in their tenant
platform_explorerExecutive / sales / trainer / evaluatorEverythingNo — read-only
platform_developerEngineer building the GeneData platform itselfEverythingYes, with editor/admin tier

Who should hold this

AudienceWhy
Internal platform engineering staffShipping new dashboards, extending services, fixing bugs
On-call rotation membersNeed full visibility + write to remediate incidents
Senior contractors with full-stack platform accessDebug + extend without scope friction
ADR authorsDesigning changes that touch multiple subsystems

Demo credentials (built-in seeded account)

FieldValue
Sign-in URL/signin
Emailplatform-dev@genedata.demo
Passworddemo1234
TenantGENEDATA
Role tieradmin (full write access)
Job functionplatform_developer

Or click the Platform Developer (read + write) card on the sign-in page.

To sign out: sidebar bottom-left user panel on every dashboard page, or the Sign Out button in the top-right of /dashboard/welcome.

Day-1 setup (for real users)

A tenant admin (or super_admin) assigns it via /dashboard/admin/users:

  1. Find the user
  2. Click Edit functions
  3. Under See Everything group, tick Platform Developer
  4. Also ensure the user's tenant role is editor or admin (settings page)
  5. Save

Or via API:

curl -X PATCH https://api.genedata.io/api/tenant/users/$USER_ID \
  -H "Authorization: Bearer $ADMIN_PAT" \
  -H "X-Tenant-Id: ACME" \
  -H "Content-Type: application/json" \
  -d '{"jobFunctions": ["platform_developer"], "role": "admin"}'

What you see

Every sidebar section. Future sections automatically appear because the filter short-circuits on this function.

Workflow 1 — Extend a service (strangler-fig)

Follow the ADR-0002 recipe — already used 10 times:

# 1. Mirror engine code
mkdir -p services/<name>-service/src
# 2. Dockerfile that COPYs both apps/api/src AND services/<name>-service/src
# 3. src/index.ts (~30 lines) imports router from @data-intelligence/api
# 4. Add to service-proxy.ts with env toggle
# 5. Add to helm/values.yaml services array (ServiceMonitor auto-generated)
# 6. Smoke test

Workflow 2 — Add a new dashboard page

See docs/ADDING_A_FEATURE.md. Quick:

# 1. New page
mkdir -p apps/platform/src/app/dashboard/<feature>
# 2. page.tsx (use useApi + apiPost from @di-platform/shared)
# 3. Backend route in apps/api/src/routes/<feature>.ts
# 4. Mount in apps/api/src/index.ts
# 5. Add to packages/platform-ui/src/nav-sections.ts with status "production"
# 6. Tag jobFunctions to the relevant roles
# 7. tsc clean → ship

Workflow 3 — Debug an endpoint in production

# 1. /dashboard/ops — see service-side health
# 2. /dashboard/ops/performance — top by p95 latency / cost
# 3. /dashboard/geneflow/ml/endpoints — drill into a specific endpoint
# 4. kubectl logs deploy/gf-ep-<id> -n genedata
# 5. SELECT * FROM gf_endpoint_revisions WHERE endpoint_id='ep_…' ORDER BY applied_at DESC LIMIT 5;
# 6. Audit trail: SELECT * FROM genedata_audit_log WHERE resource_id='ep_…' ORDER BY ts DESC LIMIT 20;

Workflow 4 — Run the soak before merging anything substantial

export GENEFLOW_TRACKING_URI=https://api.staging.genedata.io
export GENEDATA_PAT=$(genedata auth token)
export GENEFLOW_TENANT_ID=SANDBOX-pre-release

python scripts/soak-tests/geneflow-end-to-end.py
# Exit 0 → safe to merge

Workflow 5 — Verify a migration deploys cleanly

# 1. Postgres
psql -f infrastructure/postgres/migrations/00NN_<name>.sql

# 2. Helm template (no apply yet)
helm template genedata ./infrastructure/k8s/helm/genedata --debug | less

# 3. Apply to staging
helm upgrade --install genedata-staging ./infrastructure/k8s/helm/genedata \
  --set image.tag=$SHA --namespace genedata-staging

# 4. Smoke
gfctl experiments list

Common gotchas

  • Don't conflate roles. developer (customer building plugins) and platform_developer (engineer building the platform) are intentionally different. Mixing them confuses tenant-admin UI and seat caps.
  • platform_developer without editor/admin tier is dead weight. The user sees everything but can't change anything. Always pair.
  • Don't put platform_developer on a customer-facing PAT. It exposes internal pages (roadmap, capacity, audit).
  • Always tsc-clean before pushing. The new pages I built in earlier rounds had apiPost imports without the export existing — caught only after I added a typecheck pass. Run npx tsc --noEmit from apps/platform and apps/api before merge.

Where to go next