MissionGraph Reference Model V2 — live API

Unified nonprofit operations, typed temporal graph, governed agent workflows, evidence trail. Synthetic data only — two demo tenants, server-enforced roles.
Not signed in — pick a reviewer login below.

Synthetic demo — reviewer logins

Demo-only credentials for two synthetic tenants (not real accounts). Pick tenant + role above; passwords auto-fill.

TenantExecutiveProgram LeadViewer
harbor-westexec / demo-exec-hwlead / demo-lead-hwviewer / demo-view-hw
lakeside-eastexec / demo-exec-lelead / demo-lead-leviewer / demo-view-le

Start reviewer tour: 1) Sign in as Executive (harbor-west) → 2) Overview (live tenant counts) → 3) Entity Graph: set the date to 2026-05-01, then back to 2026-10-04, and watch the expired assignment vanish → 4) AI Agent: ask a question, then try "Pay $5000 from the fund" and watch it refuse with a receipt → 5) Proof view for the adversarial test record.

Executive Operating View

Architecture principle

Every operational object is an entity. Every important relationship is typed, time-bound, source-linked, and tenant-scoped. Agents may propose or execute only within explicit policy, and every action produces an evidence record. Counts above are live from /api/entities for the signed-in tenant.

Programs & Geographies

ProgramRegionOwnerStatusMilestonesOutcome

People, Volunteers & Donors

EntityType / RoleDetailTenant

Typed, Time-Bound Entity Graph

Why this matters: a donor can fund a program, a volunteer can serve a geography, a grant can restrict a fund, and all relationships can expire without deleting history. Try 2026-05-01 (Sam Patel still serves Pierce County) vs 2026-10-04 (expired — gone from current graph). Agent retrieval respects tenant, role, consent, and validity window.

Knowledge & Multimodal Ingestion

Ingested records (citable)

Ingest a new record (Program Lead+)

Ingestion writes a citable record and an audit event.

Governed Operations Agent

No run yet. Every claim must carry a resolvable citation (CITE-001) or the answer is withheld; financial writes are refused with a receipt (FIN-001).

Finance & Compliance

FundTypeBalanceControlEvidence

Attempt a financial write

Server gate: Executive role + approval flag required. Rejections return 403 and write an evidence receipt you can see in Governance.

Propose → approve workflow (money moves only on Executive approval)

A proposal does NOT move money. An Executive approves or rejects it; approval applies the balance change and writes an evidence receipt.
ProposalFundAmountPurposeStatusCreated byDecision

Governance & Audit

Policy gates

✓ Tenant isolation (server-side, token-scoped)

✓ Role-based access (Viewer read-only, 403 enforced)

✓ Time-valid relationships (?at= query-time evaluation)

✓ Human approval for financial writes (FIN-001)

✓ Source-linked AI outputs (CITE-001)

✓ Append-only action evidence (no update/delete routes)

Evidence timeline (live, append-only)

Sign in to load the audit timeline.

Evidence pack

Tenant-scoped JSON export: entity counts, relationship count, evidence receipts, audit events, and the latest stored proof-suite record.

Build / Buy / Integrate

CapabilityDecisionReason
Canonical entity graphBUILDStrategic data model and portability layer
Identity / SSOBUYCommodity security surface; integrate proven provider
Fund accountingINTEGRATEDo not recreate accounting system of record
Donor paymentsINTEGRATEUse existing processor/CRM adapter
Knowledge/RAGBUILDGoverned retrieval across operational domains
Agent evidence layerBUILDAuditability and policy enforcement are differentiators
BI exportsINTEGRATEExpose APIs/views; avoid dashboard lock-in

Scale path

Scale by tenant isolation, stateless APIs, queues for ingestion/automation, indexed retrieval, object storage, async workers, and measured hot paths. Avoid premature microservices. (Architecture brief: revival_reference_model/ARCHITECTURE.md. This V2 app is a reference model with synthetic data — not production scale evidence.)

Proof — Adversarial Test Results

HTTP-level tests against the running server: cross-tenant read/write, role 403, expired-vs-historical relationships, financial-write rejection + receipt, uncited-claim rejection. Results below are read from the stored run record (tests/last-run.json) — never faked in the UI. Re-run: node tests/proof-suite.mjs.

Not loaded yet.