| Document Control | |
|---|---|
| Document Title | Backend Architecture and Enterprise Standards SOP |
| Document ID | HWB-QMS-7.6 |
| Version | 3.1.0 |
| Status | APPROVED |
| Author | George (Systems Architect) |
| Approved By | Humberto Dominguez, CEO |
| Date | 09/21/2026 |
| ISO 9001 Clause | 8.1 Operational Planning & 8.5.1 Service Provision / ISO 27001:2022 ISMS |
Standard Operating Procedure: Backend Architecture, RBAC Gateway & PII Cryptography
1.0 Purpose
This procedure establishes the Zero-Hotfix Enterprise Mandate and cryptographic security standards across all software systems at HWB Cleaning Services LLC. The purpose is to eliminate quick patches, temporary workarounds, and on-the-fly code. Every engineering change must be designed to enterprise standards, protecting company data and preventing defects from recurring.
2.0 Scope
This standard applies to all software engineers, autonomous AI agents, technical contractors, and administrative systems operating within the HWB ecosystem, including the web application, background workers, databases, and APIs.
3.0 The Zero-Hotfix Enterprise Mandate
From September 18, 2026 onward, only enterprise-level solutions are permitted in the HWB codebase. Ad-hoc hotfixes, local workaround scripts, and quick patches are strictly prohibited.
When an issue or security gap is discovered, developers must find the root cause in the architecture and fix the system as a whole, rather than patching a single screen or endpoint.
4.0 The 6 Pillars of Enterprise Architecture
| Pillar | Core Requirement | Industrial Purpose |
|---|---|---|
| 1. Root Cause Engineering | Solve systemic causes, never mask symptoms with local if statements. |
Prevents identical bugs from emerging in adjacent modules. |
| 2. Centralized Gateway | Enforce access control at the request gatekeeper (@app.before_request). |
Fail-safe default: new endpoints are secure by default. |
| 3. Declarative Contracts | Use explicit decorators like @roles_required on endpoints. |
Code is readable, self-documenting, and impossible to bypass. |
| 4. Defense-in-Depth | Triple protection: Database checks + Backend interceptors + Clean UI rendering. | Even if a user bypasses the UI, backend locks stop unauthorized requests. |
| 5. Automated Testing | Mandatory test scripts verifying both authorized and blocked paths. | Proves code works before deployment with zero guesswork. |
| 6. Immutable Audit Trail | Log every access violation to GlobalActivities in PostgreSQL. |
Provides full accountability and traceability for ISO audits. |
5.0 Role-Based Access Control (RBAC) Quarantine Standard
User access is partitioned into distinct operational zones based on verified roles:
- Executive & Admin: Global system access, Warchest financial controls, user provisioning, and strategy modules.
- Manager: Operations oversight, accounts, and SOP manual. Restricted from user provisioning and financial Warchest.
- Operator: Daily cleaning dispatch, work orders, and commercial lead pipeline.
- Sales: Strict isolation to the Field Sales Desk (
/admin/sales-desk), assigned facility queue, 1-tap dialer/maps, and walkthrough quoting. All bulk data exports, payroll summaries, and sensitive workforce endpoints are blocked with HTTP 403.
6.0 Sensitive PII Vault & Cryptographic Architecture (SEC-001)
All sensitive worker identifiers and financial credentials are protected by the SigmaFidelity™ Cryptographic Core (core/security.py):
- AES-256 Fernet Cipher: Social Security Numbers, ITINs, and direct deposit checking/savings accounts are encrypted at the column level before writing to PostgreSQL (
ssn_encrypted,direct_deposit_account_encrypted). - Deterministic Key Derivation: The cipher key is derived deterministically via SHA-256 hashing of system environment secrets (
PII_ENCRYPTION_KEY/SECRET_KEY), guaranteeing persistence across container restarts without key drift. - Zero Plaintext API Exposure: All general endpoints (
GET /api/v1/hr/employeesandGET /api/v1/hr/employees/<id>) strip encrypted ciphertext blobs and transmit only masked strings (***-**-####and••••••••####). - Audited Timed Reveal Protocol: Authorized personnel requesting unmasked views must use
POST /api/v1/hr/employees/<id>/reveal-ssn. The gateway checks credentials, records an immutable audit log to"GlobalActivities"(stamping user ID, username, and IP address), and returns the decrypted value with a strict 30-second client-side lifetime. - Automatic Security Violation Logging: If unauthorized roles (e.g. Sales) attempt to call sensitive reveal endpoints, the gateway returns HTTP 403 Forbidden and writes an automatic
SECURITY_VIOLATIONevent to the audit ledger.
7.0 Verification (Zero-Defect Check)
- All admin routes must declare explicit role requirements using
@roles_required. - The centralized gatekeeper (
@app.before_request) must automatically intercept out-of-bounds requests. - Templates must receive permissions through
nav_accesscontext engine without scattered manual role checks. - All employee queries must sanitize output dictionaries, ensuring no raw ciphertexts or unmasked bank accounts exist in memory.
- Automated test suite verifying RBAC quarantine and PII encryption must pass 100% prior to any container deployment.
8.0 Revision History
| Date | Version | Description of Change | Approved By |
|---|---|---|---|
| 09-21-2026 | 3.1.0 | Added Section 6.0 Sensitive PII Vault and Cryptographic Architecture (SEC-001): AES-256 Fernet encryption, deterministic key derivation, zero-plaintext API serialization, 30s timed reveal, and GlobalActivities audit logging. Approved by Humberto Dominguez, CEO. | Humberto Dominguez, CEO |
| 09-18-2026 | 3.0.0 | Codified the Zero-Hotfix Enterprise Mandate and Centralized RBAC Gateway Architecture following CEO decree. | Humberto Dominguez, CEO |
| 05-21-2026 | 2.0.0 | Modernized to post-May 1st, 2026 baseline. Standardized under Everyday Words. | George (Systems Architect) |