Production Order Workflow

RadioFlow — radio spot production lifecycle & security overview

Forward path
Revision loop
Cancel / end
Draft
Sales / Sales Asst
PO created, editable by Sales
Sales submits
Submitted to Traffic
Sales → Traffic
Traffic reviews cart & contracts
Traffic / Admin advances
Submitted to Production
Traffic / Admin
Production triages the spot
Production routes to
Needs Produced
Production / Producer
Needs Dubbed
Production / Producer
Needs Writing
Production
SPEC
Production
Show
Production
Live
Production
Produced / ready for review
Script Review
Production ↔ Sales
changes
Needs Produced
Production / Producer
approved
Spot Review
Production ↔ Sales
If issues arise
Needs Attention
Production / Producer
Routed back to Production
Resolved & approved
Completed
Production / Sales
Spot delivered, cart assigned
Sales extends flight
Extended
Sales / Sales Asst
Re-enters cycle
Admin archives
Archived
Admin
End of lifecycle
Cancelled — reachable from Needs Produced, Needs Dubbed, Script/Spot Review, Needs Attention, or Needs Writing. Admin can restore a Cancelled PO back to Draft.

Complete Action Matrix — Every Status Transition

From StatusWho Can ActAllowed Next Statuses
DraftAdmin, Sales, Sales Asst, Traffic
Submitted to Traffic
Submitted to TrafficAdmin↩ back: Admin
Submitted to ProductionDraft
Submitted to ProductionAdmin, Production
Needs ProducedNeeds DubbedScript ReviewNeeds WritingSPECShowLive
Needs ProducedAdmin, Production, Producer
Spot ReviewNeeds AttentionNeeds DubbedCompletedCancelled
Needs DubbedAdmin, Production, Producer
CompletedNeeds ProducedNeeds AttentionCancelled
Script ReviewAdmin, Production
Needs ProducedNeeds WritingNeeds AttentionCancelled
Spot ReviewAdmin, Production, Producer
CompletedNeeds ProducedNeeds AttentionCancelled
Needs AttentionAdmin, Production, Producer
Needs ProducedSpot ReviewNeeds DubbedCancelled
Needs WritingAdmin, Production
Needs ProducedCancelled
CompletedAdmin, Sales, Sales Asst
Extended
CancelledAdmin
Draft
ExtendedAdmin, Sales, Sales Asst
Submitted to Traffic

Role Responsibilities

Sales / Sales AssistantCreates the PO, writes script copy, submits to Traffic, can extend completed spots.
TrafficReviews cart numbers & contracts, advances to Production, assigns producers.
ProductionTriage & routing, produces spots, manages dubbing, approves scripts/spots.
ProducerAssigned per rotation spot — produces audio, uploads, marks dubbed.
Admin / Super AdminFull access across all markets, can cancel/restore/archive, manage users & markets.

Security Overview

RadioFlow enforces security at multiple layers. The controls below are applied server-side and cannot be bypassed by client-side manipulation.

Row-Level Security (Server-Side)

Every entity enforces market isolation at the database level. Users can only read, create, or update records within their assigned market — enforced server-side, not just in the UI. Cross-market access is impossible even via direct API calls.

Role-Based Access Control (RBAC)

Administrative routes (/users, /markets) are guarded server-side. User management requires Admin or Super Admin; market configuration requires Super Admin only. Non-authorized users receive 403 Forbidden.

Field-Level Security

Sensitive fields are protected: user role assignments can only be written by platform admins (prevents privilege escalation). WideOrbit API keys and endpoints are readable/writable by Super Admin only — never exposed to regular users.

Backend Function Verification

The email notification backend function verifies that a Production Order actually exists before processing any payload. Direct endpoint calls with fabricated data are rejected — no emails can be triggered without a real PO.

Email Injection Prevention

All email recipient addresses are validated against a strict email format before sending. Users cannot redirect system notifications to arbitrary external addresses.

Authentication Required

All application routes require authenticated sessions. Unauthenticated requests have no user context, so Row-Level Security denies all data access by default. Token-based session management with automatic expiry.

Data Isolation Model

• Each radio market operates as an isolated tenant — users in Market A cannot see or modify Market B's data.

• Market assignment is stored on the user's authenticated session and verified on every database query.

• Super Admins (platform-level) can access all markets for support; Market Admins are scoped to their own market only.

• Production Orders, History, Chat, and Notifications are all scoped to the user's market at the database level.

base44
Edit with Base44