TFD Domain Entity Relationships

Current entity families and the Delivery, Engagement, and Clinical flows represented by the product-development mind map

TFD Domain Entity Relationships Current entity families and the Delivery, Engagement, and Clinical flows represented by the product-development mind map AWS Cognito · authentication identity · Architecture component · external AWS Cognito authentication identity external StaffUser · RBAC · user type · linked VIT · Architecture component · identity StaffUser RBAC · user type · linked VIT identity UserProfile · future VIP portal identity · Architecture component · identity UserProfile future VIP portal identity identity VipProfile · membership · goals · preferences · activity · Architecture component · identity schema / VIP context VipProfile membership · goals · preferences · activity identity schema / VIP context VITProfile + Assignment · capacity · specialties · VIP totals by package · Architecture component · identity schema / staff ops VITProfile + Assignment capacity · specialties · VIP totals by package identity schema / staff ops Program Catalog · Definitions · shared media references · Architecture component · delivery Program Catalog Definitions · shared media references delivery ProgramStructureVersion · immutable structure snapshot · Architecture component · delivery ProgramStructureVersion immutable structure snapshot delivery ProgramRun + responsibility links · VIPs · Analysis VITs · AddPipe level whitelist · Architecture component · delivery runtime ProgramRun + responsibility links VIPs · Analysis VITs · AddPipe level whitelist delivery runtime SessionOccurrence · scheduled session · copied run configuration · Architecture component · delivery runtime SessionOccurrence scheduled session · copied run configuration delivery runtime Integrations: Links + Source Video · Zoom MP4/evidence · AddPipe private MP4 · Architecture component · integrations Integrations: Links + Source Video Zoom MP4/evidence · AddPipe private MP4 integrations Live + On-demand Attendance · attendance · relocation · invalidation evidence · Architecture component · delivery Live + On-demand Attendance attendance · relocation · invalidation evidence delivery Session Analysis · request · project · media · feedback · delivery · Architecture component · delivery Session Analysis request · project · media · feedback · delivery delivery Delivery Engine · session → participation → feedback · Architecture component · business flow Delivery Engine session → participation → feedback business flow Engagement Facts + Snapshot · session details · weekly/monthly status · Architecture component · engagement Engagement Facts + Snapshot session details · weekly/monthly status engagement Engagement Engine · participation → follow-up → communication · Architecture component · business flow Engagement Engine participation → follow-up → communication business flow Notification + Subscription + Event · role-aware inbox · preference · outbound outbox · Architecture component · notifications Notification + Subscription + Event role-aware inbox · preference · outbound outbox notifications Clinical · Notes + workspace · Architecture component · Persisted owner Clinical Notes + workspace Persisted owner Clinical records · ClinicalNote + revisions · Workspace · Architecture component · clinical schema Clinical records ClinicalNote + revisions · Workspace clinical schema Audit evidence · Entry + idempotency receipt · Architecture component · Platform · no content Audit evidence Entry + idempotency receipt Platform · no content active Assignment enrolled VIPs live evidence · stored video available explicit request · stable video id Legend Security Backend Database External Message bus

How to read this map

  • • Solid paths are current durable relationships or approved processing paths
  • • VIP experience ownership is read and changed only through the active Assignment; workload and package totals join those assignments to active VipProfiles
  • • Dashed paths are projections, future identity, or conceptual boundaries
  • • The original sample JSON was replaced by current schema-backed entity summaries
  • • SalesMembershipCapture has many SalesMembershipSilver rows and one SalesMembershipGold row. The unique day/revision selects an auditable observation; capture/VIP is unique. Silver technical VIP and subscription references are evidence, not cross-context database relations; source fields arrive through Identity and Engagement public contracts.
  • • Assets library shares private media across Program Assets and Studio; routines and VIT/VIP documents stay on ProgramAsset

Delivery flow

  • • ProgramAsset references shared media by tfd-media:library:id; saved programs retain their own versioned definitions
  • • A run generates SessionOccurrences and owns VIP, time-slot-specific Session Analysis VIT rosters, and an AddPipe level-code whitelist
  • • Only stored AddPipe videos whose normalized session code is whitelisted by the run enter its first future occurrence; every recording remains in the Integrations catalog
  • • Every Program Run VIP is eligible before live attendance finalizes; evidence records on-demand-only, missed-live, or run-assignment reasons
  • • Automatic and occurrence-scoped manual links persist OnDemandAttendance atomically; grouped invalid uploads leave the pending queue together
  • • Before analysis exists, live attendance may move or be invalidated with durable staff evidence
  • • Staff explicitly create Session Analysis from saved attendance; automatic distribution uses only active VITs configured for the occurrence start time

Engagement and Clinical

  • • Engagement derives session-granular report facts after Delivery persists attendance
  • • The Engagement projection preserves occurrence, day, status, participation mode, and assigned VIT dimensions for report drill-downs
  • • Notifications keeps per-staff inbox, event preferences, and outbound delivery separate
  • • Effective subscriptions gate future inbox materialization without changing source facts
  • • Clinical remains a planned isolated context and does not own general VIP operations

Audit P0 and P1 coverage

  • • Identity, Clinical, Sales, Delivery and Integrations retain their state; Audit receives bounded facts through the synchronous public contract
  • • Staff/RBAC, Clinical and attendance/evidence changes commit with Audit. Private media and sensitive VIP concessions await durable evidence before disclosure
  • • Integrations owns MediaDeletionJob: committed intent blocks playback, leased bounded retries remove private objects, completion and Audit commit together; terminal failure has an authorized repair path
  • • Audit HTTP queries use explicit independent read, restricted-metadata and export grants, server organization scope and validated unsigned pagination; every page reapplies authorization and query limits. No Audit secret is required. Retention is held without automatic purge or receipt expiry
  • • P1 adds manual VIP changes, VIT assignment decisions, Program Run creation, manual attendance and named soft archives; existing video decisions retain one P0 fact and owner histories remain independent