J2R Solutions

Briefing

Training Dashboard — Rollout Plan

Live Dashboard →

J2R Solutions · Internal Briefing

Training Dashboard — Rollout Plan

Where we are, what's left, and what we need from each owner to take this from sandbox to production.

Status

Sandbox complete · awaiting prod approval

Author

Jonathan Spigler

Date

Apr 28, 2026

TL;DR

A live, applicability-aware training & compliance dashboard, built end-to-end in the sandbox. Tracks org-wide compliance, partner-tier attainment, and per-employee certification lifecycles. Per-user OAuth (no service account); each viewer sees what their Salesforce role allows. Hosted on AWS with custom domain.

What's left to go to production: deploy the schema to the prod org, set up a prod Connected App, backfill real applicability + tier-target rules, point a prod URL, and assign access. Outlined below.

Live URL: home.html · Cost (AWS): ~$2/month

What this delivers

What's in place (sandbox)

Salesforce — schema

  • 4 new fields on Training__c: Framework, Required, Account, Program
  • New object Training_Program__c (catalog)
  • New object Vendor_Tier_Target__c (target tier per vendor)
  • New object Compliance_Requirement__c (rules with applicability)
  • New picklist Contact.Training_Role__c (multi-select)
  • Permission set Training_Dashboard_Schema

Salesforce — data

  • 56 catalog programs (universal compliance + 19 vendor cert families)
  • 19 Vendor Tier Targets — Core + Growth tier vendors
  • 56 Compliance Requirements (11 universal + 45 tier prereqs)
  • 13 J2R employee Contacts with role assignments
  • ~212 Training records (real from imports + amplification)

AWS

  • S3 bucket (private, BPA on, OAC-only access)
  • CloudFront distribution + ACM cert + Route53 alias
  • API Gateway HTTP API + Lambda (Node.js 20)
  • Secrets Manager (OAuth client + cookie key)
  • IAM role scoped to one secret + log group
  • Cost: ~$2/month total

Frontend (live in sandbox)

  • Home: 3 heroes + people + action items + requirements + tier cards + throughput
  • Partners: dedicated vendor grid with logos + renewal horizons
  • Category pages: HR, Compliance, IT, Cyber Security
  • Drill panels: requirement, tier, contact (with 12-month timeline)
  • Per-user OAuth via Connected App + PKCE

What we need to do to ship to production

  1. 1

    Confirm applicability rules + tier targets with vendor managers

    Review the seeded defaults (in docs/dot-two-design.md) and replace placeholders with the real list. Specifically:

    • Which roles must take CMMC / CUI / Insider Threat (currently DoD-Facing)?
    • Real Training_Role__c assignments for each of the 13 employees
    • Each Core/Growth vendor's actual target tier and required certs (from vendor partner program docs)
    • RAG thresholds — comfortable with 95/80/<80 for compliance? 100/50/<50 for tier?

    Owner: Jonathan + vendor relationship owners · ~3–5 days of part-time work

  2. 2

    Deploy schema to production org

    Same metadata that's in force-app/main/default/ now in the sandbox. One sf project deploy command targeting prod.

    Owner: Salesforce admin · ~1 hour

  3. 3

    Create production Connected App

    Same OAuth Authorization Code + PKCE pattern as the sandbox, separate Connected App in prod. Step-by-step in docs/salesforce-connected-app-setup.md. Use https://<prod-domain>/auth/callback.

    Owner: Salesforce admin · ~15 minutes

  4. 4

    Decide production URL + provision AWS

    Stand up a parallel AWS stack pointed at prod (separate S3 bucket, CloudFront distribution, Lambda function, Secrets Manager secret with prod OAuth client). Suggested URL: training.j2rsolutions.com or similar.

    Owner: AWS admin · ~1 day

  5. 5

    Backfill applicability + requirement records in prod

    Populate Contact.Training_Role__c, create Vendor_Tier_Target__c + Compliance_Requirement__c records, and link existing Training__c records to Training_Program__c via Program__c lookup. Apex anonymous block can do this in ~10 min if we know the rules from step 1.

    Owner: Salesforce admin · ~2–3 hours including QA

  6. 6

    Assign permission sets

    Assign Training_Dashboard_Schema + the Connected App permission set to anyone who should see the dashboard. Bulk-assign via Setup → Permission Sets → Manage Assignments.

    Owner: Salesforce admin · ~30 min

  7. 7

    Verify in prod, then announce

    Walk through every page as a few different users (admin, sales, technical) to confirm sharing rules + FLS work as expected. Brief the team on the URL + how to use the drill-downs.

    Owner: Project lead · ~half day

Decisions needed

1. Production URL

Suggestion: training.j2rsolutions.com. Could also be compliance.j2rsolutions.com or stay under aws.j2rsolutions.com. Whoever owns DNS for the apex needs to approve.

2. Who gets access

Just the partner-ops + leadership team? Everyone? Sales reps would only see their own data anyway (per-user auth), so opening it widely is low-risk.

3. Owner for compliance requirements + tier targets

Once data lives in Compliance_Requirement__c and Vendor_Tier_Target__c, someone needs to keep them current. Vendor reps update tier prereqs annually; compliance officer keeps universal requirements aligned with regulations.

4. RAG thresholds

Default: green ≥95%, yellow 80–94%, red <80%. Tier: 100%/50%/<50%. Comfortable, or want stricter/looser?

Risks & mitigations

Risk Mitigation
Tier prereqs change yearlyQuarterly review with each vendor relationship owner; data lives in records, not code.
Stale Training_Role assignmentsTreat role assignment as part of onboarding; trigger a review when someone changes title.
Renewal lapses unnoticed"Expiring 90d" KPI on home page; can wire a weekly digest email later.
Sandbox refresh wipes customizationsAll schema lives in force-app/ in git; redeploy in <5 min. Seed scripts replay data.
OAuth Connected App secret rotationRotate quarterly via "Rotate Client Secret" button; update Secrets Manager in one CLI command.

Estimated timeline to production

Week 1
Confirm rules + tier targets (step 1)
Week 2
Schema deploy + Connected App + AWS (steps 2–4)
Week 2–3
Backfill + permission sets + verify (steps 5–7)

Critical path: getting the applicability rules confirmed (step 1). Everything else is mechanical once we have the rules.

Reference