Goal
Add a deliberate, server-authorized Administration / Maintenance experience for inspecting and cleaning stale Classroom and collaboration data before production and during ongoing operation.
This is not an Intake experience role and must not weaken Standalone/Student/Instructor authorization.
Admin entry and authorization
- provide an Administration/Maintenance entry from the startup experience hub or another explicit app entry;
- require a high-entropy server-configured admin credential (environment-managed; never bundled in browser assets);
- keep the credential out of Intake persistence, exports, summaries, URLs, logs, and long-lived localStorage;
- prefer tab/session-scoped browser retention only after explicit entry;
- all admin responses are private/no-store/no-referrer.
Inventory view
Show separate, filterable inventories for:
Classrooms
- public class ID/title;
- status: active / revoked / expired;
- created / updated / expiry timestamps;
- most recent participant/presence activity;
- participant/workspace counts;
- current staged exercise state where relevant;
- derived idle age.
Standalone/ad-hoc collaboration workspaces
- public workspace/session identifier;
- created / updated / expiry timestamps;
- most recent presence/activity;
- participant count;
- derived idle age;
- whether the workspace is class-owned or independent.
Do not expose raw bearer capabilities.
Cleanup actions
Support explicit preview-before-delete operations:
- revoke/close a class immediately;
- purge one expired/revoked class and its class-owned subordinate records;
- bulk purge classes idle/expired beyond a selected threshold;
- purge standalone collaboration workspaces idle/expired beyond a selected threshold;
- show the exact rows/objects that will be removed before confirmation.
Cleanup must be transactional/fail-closed where practical, respect foreign-key ownership, and must never delete an apparently active workspace merely because its snapshot is old if recent presence says it is active.
Retention model
Use server timestamps as authority. Define deterministic idle rules from workspace/class update time plus most-recent presence/activity. Existing CLASS_EXPIRY_DAYS remains a creation-time expiry policy; Admin cleanup is the intentional physical purge mechanism.
Consider a future scheduled purge only after the manual Admin flow is proven. Do not introduce autonomous deletion in this slice.
Recovery
Because the pre-production compatibility reset removes the public Instructor access-code recovery form, Admin should provide an explicit class recovery action if needed (for example rotate/reissue Instructor authority) without exposing historical raw credentials.
Tests
- admin auth rejection and no capability leakage;
- class/workspace inventory isolation;
- idle/active classification;
- dry-run/preview matches committed deletion;
- cascade integrity;
- no deletion of active/recent-presence sessions;
- mobile/keyboard/axe coverage for the Admin UI;
- Serverless Function budget remains within repository limits.
Done when
An authorized maintainer can see what is occupying the database, understand why an item is considered stale, and safely clean selected or bulk idle/expired Classroom and collaboration data without direct database access.
Goal
Add a deliberate, server-authorized Administration / Maintenance experience for inspecting and cleaning stale Classroom and collaboration data before production and during ongoing operation.
This is not an Intake experience role and must not weaken Standalone/Student/Instructor authorization.
Admin entry and authorization
Inventory view
Show separate, filterable inventories for:
Classrooms
Standalone/ad-hoc collaboration workspaces
Do not expose raw bearer capabilities.
Cleanup actions
Support explicit preview-before-delete operations:
Cleanup must be transactional/fail-closed where practical, respect foreign-key ownership, and must never delete an apparently active workspace merely because its snapshot is old if recent presence says it is active.
Retention model
Use server timestamps as authority. Define deterministic idle rules from workspace/class update time plus most-recent presence/activity. Existing
CLASS_EXPIRY_DAYSremains a creation-time expiry policy; Admin cleanup is the intentional physical purge mechanism.Consider a future scheduled purge only after the manual Admin flow is proven. Do not introduce autonomous deletion in this slice.
Recovery
Because the pre-production compatibility reset removes the public Instructor access-code recovery form, Admin should provide an explicit class recovery action if needed (for example rotate/reissue Instructor authority) without exposing historical raw credentials.
Tests
Done when
An authorized maintainer can see what is occupying the database, understand why an item is considered stale, and safely clean selected or bulk idle/expired Classroom and collaboration data without direct database access.