Platform Developer
You own: the GeneFlow / GeneData platform itself. You extend it, debug it, extract services from it, and ship new dashboards. Platform Developer is the only see-everything-AND-write role — pair it with
tenantRole=editororadmin.
NOT the same as "Developer"
| Function | Who | Sees | Writes |
|---|---|---|---|
developer (legacy) | Customer building custom connectors / agents / plugins on top of GeneData | Developer + SDK + Marketplace sections only | Yes, in their tenant |
platform_explorer | Executive / sales / trainer / evaluator | Everything | No — read-only |
platform_developer | Engineer building the GeneData platform itself | Everything | Yes, with editor/admin tier |
Who should hold this
| Audience | Why |
|---|---|
| Internal platform engineering staff | Shipping new dashboards, extending services, fixing bugs |
| On-call rotation members | Need full visibility + write to remediate incidents |
| Senior contractors with full-stack platform access | Debug + extend without scope friction |
| ADR authors | Designing changes that touch multiple subsystems |
Demo credentials (built-in seeded account)
| Field | Value |
|---|---|
| Sign-in URL | /signin |
platform-dev@genedata.demo | |
| Password | demo1234 |
| Tenant | GENEDATA |
| Role tier | admin (full write access) |
| Job function | platform_developer |
Or click the Platform Developer (read + write) card on the sign-in page.
To sign out: sidebar bottom-left user panel on every dashboard page, or the Sign Out button in the top-right of /dashboard/welcome.
Day-1 setup (for real users)
A tenant admin (or super_admin) assigns it via /dashboard/admin/users:
- Find the user
- Click Edit functions
- Under See Everything group, tick Platform Developer
- Also ensure the user's tenant role is
editororadmin(settings page) - Save
Or via API:
curl -X PATCH https://api.genedata.io/api/tenant/users/$USER_ID \
-H "Authorization: Bearer $ADMIN_PAT" \
-H "X-Tenant-Id: ACME" \
-H "Content-Type: application/json" \
-d '{"jobFunctions": ["platform_developer"], "role": "admin"}'
What you see
Every sidebar section. Future sections automatically appear because the filter short-circuits on this function.
Workflow 1 — Extend a service (strangler-fig)
Follow the ADR-0002 recipe — already used 10 times:
# 1. Mirror engine code
mkdir -p services/<name>-service/src
# 2. Dockerfile that COPYs both apps/api/src AND services/<name>-service/src
# 3. src/index.ts (~30 lines) imports router from @data-intelligence/api
# 4. Add to service-proxy.ts with env toggle
# 5. Add to helm/values.yaml services array (ServiceMonitor auto-generated)
# 6. Smoke test
Workflow 2 — Add a new dashboard page
See docs/ADDING_A_FEATURE.md. Quick:
# 1. New page
mkdir -p apps/platform/src/app/dashboard/<feature>
# 2. page.tsx (use useApi + apiPost from @di-platform/shared)
# 3. Backend route in apps/api/src/routes/<feature>.ts
# 4. Mount in apps/api/src/index.ts
# 5. Add to packages/platform-ui/src/nav-sections.ts with status "production"
# 6. Tag jobFunctions to the relevant roles
# 7. tsc clean → ship
Workflow 3 — Debug an endpoint in production
# 1. /dashboard/ops — see service-side health
# 2. /dashboard/ops/performance — top by p95 latency / cost
# 3. /dashboard/geneflow/ml/endpoints — drill into a specific endpoint
# 4. kubectl logs deploy/gf-ep-<id> -n genedata
# 5. SELECT * FROM gf_endpoint_revisions WHERE endpoint_id='ep_…' ORDER BY applied_at DESC LIMIT 5;
# 6. Audit trail: SELECT * FROM genedata_audit_log WHERE resource_id='ep_…' ORDER BY ts DESC LIMIT 20;
Workflow 4 — Run the soak before merging anything substantial
export GENEFLOW_TRACKING_URI=https://api.staging.genedata.io
export GENEDATA_PAT=$(genedata auth token)
export GENEFLOW_TENANT_ID=SANDBOX-pre-release
python scripts/soak-tests/geneflow-end-to-end.py
# Exit 0 → safe to merge
Workflow 5 — Verify a migration deploys cleanly
# 1. Postgres
psql -f infrastructure/postgres/migrations/00NN_<name>.sql
# 2. Helm template (no apply yet)
helm template genedata ./infrastructure/k8s/helm/genedata --debug | less
# 3. Apply to staging
helm upgrade --install genedata-staging ./infrastructure/k8s/helm/genedata \
--set image.tag=$SHA --namespace genedata-staging
# 4. Smoke
gfctl experiments list
Common gotchas
- Don't conflate roles.
developer(customer building plugins) andplatform_developer(engineer building the platform) are intentionally different. Mixing them confuses tenant-admin UI and seat caps. platform_developerwithouteditor/admintier is dead weight. The user sees everything but can't change anything. Always pair.- Don't put
platform_developeron a customer-facing PAT. It exposes internal pages (roadmap, capacity, audit). - Always tsc-clean before pushing. The new pages I built in earlier rounds had
apiPostimports without the export existing — caught only after I added a typecheck pass. Runnpx tsc --noEmitfromapps/platformandapps/apibefore merge.
Where to go next
- 11-data-platform-engineer.md — adjacent, but more storage-focused
- 12-devops-engineer.md — adjacent, CI/CD focus
- 04-ai-platform-engineer.md — adjacent, AI-platform-tenancy focus
- ADR-0002: Further service extraction — the next big architectural decision
- 27-platform-explorer.md — read-only sibling