# Organizer access handoff

BP can run first from personal/public read-only signals, then upgrade to organizer-approved feeds without changing the mission engine.

Generated: 2026-06-18T21:00:00+07:00

## Access Asks

### Devpost Profile
- Permission: Already demo-ready / public or participant-visible
- Purpose: Understand skills, team state, draft/submission readiness, and project direction.
- Read-only fields: profile skills, team status, project draft state, track and submission readiness
- Boundary: Uses only data the signed-in builder can already see; official export/webhook requires organizer approval.

### Discord Signals
- Permission: Participant-visible read-only bridge
- Purpose: Catch blockers, team-formation asks, workshop confusion, and urgent announcements.
- Read-only fields: announcements, team-formation posts, workshop questions, self-reported blockers
- Boundary: No posting, DM reading, or moderation actions without explicit permission and an approved bot.

### AABW Schedule
- Permission: Already demo-ready / public or participant-visible
- Purpose: Keep venue, workshop, deadline, and track guidance accurate.
- Read-only fields: venues, workshops, deadlines, tracks, public event updates
- Boundary: Treats public schedule as source material; private speaker/contact details stay out unless published.

### Luma / Check-ins
- Permission: Participant-visible read-only bridge
- Purpose: Separate onsite/remote routing and venue presence during hybrid event flow.
- Read-only fields: personal RSVP state, event schedule, venue reminders
- Boundary: Personal mode reads only the builder's own RSVP/schedule view. Full attendance and check-in signals require organizer approval.

### Organizer Roster
- Permission: CSV/API provided by GenAI Fund
- Purpose: Enable private routing, support triage, and aggregate organizer insight.
- Read-only fields: registration fields, approved roles, optional contact routing metadata
- Boundary: Never exposes raw personal records in public UI; powers private routing and aggregate operations only.

## Rollout

- Start with public schedule plus participant-provided Devpost/Discord/Luma snapshots.
- Run BP as a read-only observer during the first event block.
- Ask organizers for approved Discord bot, Devpost export/API, and Luma/check-in export only after value is visible.
- Keep public UI anonymized; expose raw records only to approved organizer operators if needed.

## Safety Rules

- No posting, DMs, email sends, or profile changes without explicit human approval.
- No personal user tokens for Discord; use approved bot/export flows.
- Secrets live only in local .env or VPS environment variables.
- Builder-facing views show guidance and anonymized routing, not raw rosters.
