Briefing
J2R Solutions · Internal Briefing
Where we are, what's left, and what we need from each owner to take this from sandbox to production.
Status
Sandbox complete · awaiting prod approval
Author
Jonathan Spigler
Date
Apr 28, 2026
A live, applicability-aware training & compliance dashboard, built end-to-end in the sandbox. Tracks org-wide compliance, partner-tier attainment, and per-employee certification lifecycles. Per-user OAuth (no service account); each viewer sees what their Salesforce role allows. Hosted on AWS with custom domain.
What's left to go to production: deploy the schema to the prod org, set up a prod Connected App, backfill real applicability + tier-target rules, point a prod URL, and assign access. Outlined below.
Live URL: home.html · Cost (AWS): ~$2/month
Salesforce — schema
Training__c: Framework, Required, Account, ProgramTraining_Program__c (catalog)Vendor_Tier_Target__c (target tier per vendor)Compliance_Requirement__c (rules with applicability)Contact.Training_Role__c (multi-select)Training_Dashboard_SchemaSalesforce — data
AWS
Frontend (live in sandbox)
Confirm applicability rules + tier targets with vendor managers
Review the seeded defaults (in docs/dot-two-design.md) and replace placeholders with the real list. Specifically:
Training_Role__c assignments for each of the 13 employeesOwner: Jonathan + vendor relationship owners · ~3–5 days of part-time work
Deploy schema to production org
Same metadata that's in force-app/main/default/ now in the sandbox. One sf project deploy command targeting prod.
Owner: Salesforce admin · ~1 hour
Create production Connected App
Same OAuth Authorization Code + PKCE pattern as the sandbox, separate Connected App in prod. Step-by-step in docs/salesforce-connected-app-setup.md. Use https://<prod-domain>/auth/callback.
Owner: Salesforce admin · ~15 minutes
Decide production URL + provision AWS
Stand up a parallel AWS stack pointed at prod (separate S3 bucket, CloudFront distribution, Lambda function, Secrets Manager secret with prod OAuth client). Suggested URL: training.j2rsolutions.com or similar.
Owner: AWS admin · ~1 day
Backfill applicability + requirement records in prod
Populate Contact.Training_Role__c, create Vendor_Tier_Target__c + Compliance_Requirement__c records, and link existing Training__c records to Training_Program__c via Program__c lookup. Apex anonymous block can do this in ~10 min if we know the rules from step 1.
Owner: Salesforce admin · ~2–3 hours including QA
Assign permission sets
Assign Training_Dashboard_Schema + the Connected App permission set to anyone who should see the dashboard. Bulk-assign via Setup → Permission Sets → Manage Assignments.
Owner: Salesforce admin · ~30 min
Verify in prod, then announce
Walk through every page as a few different users (admin, sales, technical) to confirm sharing rules + FLS work as expected. Brief the team on the URL + how to use the drill-downs.
Owner: Project lead · ~half day
1. Production URL
Suggestion: training.j2rsolutions.com. Could also be compliance.j2rsolutions.com or stay under aws.j2rsolutions.com. Whoever owns DNS for the apex needs to approve.
2. Who gets access
Just the partner-ops + leadership team? Everyone? Sales reps would only see their own data anyway (per-user auth), so opening it widely is low-risk.
3. Owner for compliance requirements + tier targets
Once data lives in Compliance_Requirement__c and Vendor_Tier_Target__c, someone needs to keep them current. Vendor reps update tier prereqs annually; compliance officer keeps universal requirements aligned with regulations.
4. RAG thresholds
Default: green ≥95%, yellow 80–94%, red <80%. Tier: 100%/50%/<50%. Comfortable, or want stricter/looser?
| Risk | Mitigation |
|---|---|
| Tier prereqs change yearly | Quarterly review with each vendor relationship owner; data lives in records, not code. |
| Stale Training_Role assignments | Treat role assignment as part of onboarding; trigger a review when someone changes title. |
| Renewal lapses unnoticed | "Expiring 90d" KPI on home page; can wire a weekly digest email later. |
| Sandbox refresh wipes customizations | All schema lives in force-app/ in git; redeploy in <5 min. Seed scripts replay data. |
| OAuth Connected App secret rotation | Rotate quarterly via "Rotate Client Secret" button; update Secrets Manager in one CLI command. |
Critical path: getting the applicability rules confirmed (step 1). Everything else is mechanical once we have the rules.
docs/dot-two-design.md — applicability + tier-target design with all defaultsdocs/salesforce-connected-app-setup.md — Connected App setup, step-by-stepdocs/salesforce-oauth-framework.md — portable OAuth framework playbook (for future projects)docs/salesforce-dashboard-design.md — alternatives considered (LWC, CRM Analytics, etc.)seed/generate.py — generates the seed Apex from imports/