Phase 171FAEDA-ROLE-FUNCTIONAL-READINESS-001demo credential shell

Role Demo Credential Shell

A safe demo-only credential launcher for checking FAEDA as Supplier, Manufacturer, Wholesaler, Retailer, Customer, Rider, and Founder/Admin without claiming production authentication.

Demo personas

7

supplier to founder/admin

Route launches

21

dashboard, workbench, primary route

Real secrets

0

no production passwords or OTPs

Demo tenant

1

chiniot source-to-sale seed

Select role

Demo personas

Selected persona

Raw Material Supplier

This demo user can inspect its role-scoped records and open assigned routes only.

live guarded

Demo phone

+92 300 000 1601

Demo OTP

111111

Tenant

demo_chiniot_source_to_sale

Can create

Supplier profileMaterial offerRFQ quote response

Cannot create

PO commitmentGRNInventory movementSupplier invoicePayment settlement

How to use

Credential shell steps

01

Choose demo persona

Select Supplier, Manufacturer, Wholesaler, Retailer, Customer, Rider, or Founder/Admin.

Selected role context is visible before any page launch.

02

Review demo credential

Show demo phone and demo OTP only. These are not real passwords, OTPs, wallet PINs, or production credentials.

Tester understands this is a demo shell, not a real auth grant.

03

Open role surfaces

Launch dashboard, workbench, and primary role route with one tap.

Every role can be checked quickly from one place.

04

Verify permission boundary

Confirm what the role can create and what remains blocked.

No role overclaims payment, inventory, ledger, PO, GRN, or settlement authority.

05

Record demo QA result

Future gate can store pass/fail notes after route smoke testing.

Phase 172 can become a role-route smoke test board.

Selected route matrix

Raw Material Supplier

All route launchers

Dashboard, workbench, and primary route by role

Safety rules

What this shell is not

Demo credentials only

Phone and OTP values are fake demo fixtures. They must never be treated as production login secrets.

No backend session claim

This shell does not create JWTs, cookies, sessions, auth records, or user accounts.

Backend remains authority

When real auth arrives, backend permissions decide all access. UI role switching is not security.

No regulated finance shortcut

Wallet, payout, settlement, ledger, and Upaisa/SBP partner execution remain gated.

Smoke checklist

What we verify next

1

Open each demo persona and confirm phone, OTP, scope, tenant, and role match.

2

Open each dashboard and confirm the route returns 200.

3

Open each workbench and confirm allowed actions are role-specific.

4

Open each primary route and confirm it matches the role's chain position.

5

Confirm non-admin roles do not see founder-only finance or cost controls.

6

Confirm customer persona does not see other-customer data or internal ledger details.

7

Confirm payment ops remains licensed-partner evidence only.

8

Confirm no page claims production authentication, real wallet, final payout, or live settlement.

Credential packet

JSON preview

{
  "credentialShellId": "role_demo_credential_shell_171",
  "phase": "Phase 171",
  "sourceGate": "FAEDA-ROLE-FUNCTIONAL-READINESS-001",
  "route": "/business-pro/role-demo-credential-shell",
  "demoOnly": true,
  "productionAuth": false,
  "createsSessions": false,
  "createsUsers": false,
  "demoTenant": "demo_chiniot_source_to_sale",
  "personas": [
    {
      "roleId": "supplier",
      "title": "Raw Material Supplier",
      "phone": "+92 300 000 1601",
      "otp": "111111",
      "scope": "supplier_demo_user",
      "dashboard": "/business-pro/supplier-dashboard",
      "workbench": "/business-pro/supplier-action-workbench",
      "primaryRoute": "/business-pro/supplier-manufacturer"
    },
    {
      "roleId": "manufacturer",
      "title": "Manufacturer",
      "phone": "+92 300 000 1602",
      "otp": "111111",
      "scope": "manufacturer_demo_user",
      "dashboard": "/business-pro/manufacturer-dashboard",
      "workbench": "/business-pro/manufacturer-action-workbench",
      "primaryRoute": "/business-pro/manufacturer-source-map"
    },
    {
      "roleId": "wholesaler",
      "title": "Wholesaler / Distributor",
      "phone": "+92 300 000 1603",
      "otp": "111111",
      "scope": "wholesaler_demo_user",
      "dashboard": "/business-pro/wholesaler-dashboard",
      "workbench": "/business-pro/wholesaler-action-workbench",
      "primaryRoute": "/business-pro/wholesaler-stock-intake-gate"
    },
    {
      "roleId": "retailer",
      "title": "Retailer / Shopkeeper",
      "phone": "+92 300 000 1604",
      "otp": "111111",
      "scope": "retailer_demo_user",
      "dashboard": "/business-pro/retailer-dashboard",
      "workbench": "/business-pro/retailer-action-workbench",
      "primaryRoute": "/business-pro/retail-listing-publication-gate"
    },
    {
      "roleId": "customer",
      "title": "Customer / Family",
      "phone": "+92 300 000 1605",
      "otp": "111111",
      "scope": "customer_demo_user",
      "dashboard": "/business-pro/customer-dashboard",
      "workbench": "/business-pro/customer-action-workbench",
      "primaryRoute": "/business-pro/customer-demand-signal-gate"
    },
    {
      "roleId": "rider",
      "title": "Rider / Logistics Provider",
      "phone": "+92 300 000 1606",
      "otp": "111111",
      "scope": "rider_demo_user",
      "dashboard": "/business-pro/rider-dashboard",
      "workbench": "/business-pro/rider-action-workbench",
      "primaryRoute": "/business-pro/logistics-booking-gate"
    },
    {
      "roleId": "admin",
      "title": "Founder / Admin Ops",
      "phone": "+92 300 000 1607",
      "otp": "111111",
      "scope": "founder_demo_operator",
      "dashboard": "/business-pro/admin-dashboard",
      "workbench": "/business-pro/admin-action-workbench",
      "primaryRoute": "/business-pro/source-to-sale-control-room"
    }
  ],
  "nextAllowedGate": "phase_172_role_route_smoke_test_board"
}

Hard rules

No production auth claim

1

Phase 171 is a demo credential shell only.

2

Do not create real auth, JWT, session, password, OTP service, user account, wallet PIN, or provider credential here.

3

Do not store real CNIC, phone owner identity, bank details, payment secrets, or personal data.

4

Do not imply that role switching replaces backend RBAC.

5

Next gate should smoke-test role routes before real authentication work starts.

Next build gate

Phase 172 is role route smoke test board

Now that persona launch links exist, the next safe move is a board that checks all role routes, expected labels, and boundary warnings in one place.

Open smoke board