Production Order Workflow
RadioFlow — radio spot production lifecycle & security overview
Production Order Workflow & Security — RadioFlow
Radio spot production lifecycle, status transitions & access controls
Complete Action Matrix — Every Status Transition
| From Status | Who Can Act | Allowed Next Statuses |
|---|---|---|
| Draft | Admin, Sales, Sales Asst, Traffic | Submitted to Traffic |
| Submitted to Traffic | Admin↩ back: Admin | Submitted to ProductionDraft |
| Submitted to Production | Admin, Production | Needs ProducedNeeds DubbedScript ReviewNeeds WritingSPECShowLive |
| Needs Produced | Admin, Production, Producer | Spot ReviewNeeds AttentionNeeds DubbedCompletedCancelled |
| Needs Dubbed | Admin, Production, Producer | CompletedNeeds ProducedNeeds AttentionCancelled |
| Script Review | Admin, Production | Needs ProducedNeeds WritingNeeds AttentionCancelled |
| Spot Review | Admin, Production, Producer | CompletedNeeds ProducedNeeds AttentionCancelled |
| Needs Attention | Admin, Production, Producer | Needs ProducedSpot ReviewNeeds DubbedCancelled |
| Needs Writing | Admin, Production | Needs ProducedCancelled |
| Completed | Admin, Sales, Sales Asst | Extended |
| Cancelled | Admin | Draft |
| Extended | Admin, Sales, Sales Asst | Submitted to Traffic |
Role Responsibilities
Security Overview
RadioFlow enforces security at multiple layers. The controls below are applied server-side and cannot be bypassed by client-side manipulation.
Row-Level Security (Server-Side)
Every entity enforces market isolation at the database level. Users can only read, create, or update records within their assigned market — enforced server-side, not just in the UI. Cross-market access is impossible even via direct API calls.
Role-Based Access Control (RBAC)
Administrative routes (/users, /markets) are guarded server-side. User management requires Admin or Super Admin; market configuration requires Super Admin only. Non-authorized users receive 403 Forbidden.
Field-Level Security
Sensitive fields are protected: user role assignments can only be written by platform admins (prevents privilege escalation). WideOrbit API keys and endpoints are readable/writable by Super Admin only — never exposed to regular users.
Backend Function Verification
The email notification backend function verifies that a Production Order actually exists before processing any payload. Direct endpoint calls with fabricated data are rejected — no emails can be triggered without a real PO.
Email Injection Prevention
All email recipient addresses are validated against a strict email format before sending. Users cannot redirect system notifications to arbitrary external addresses.
Authentication Required
All application routes require authenticated sessions. Unauthenticated requests have no user context, so Row-Level Security denies all data access by default. Token-based session management with automatic expiry.
Data Isolation Model
• Each radio market operates as an isolated tenant — users in Market A cannot see or modify Market B's data.
• Market assignment is stored on the user's authenticated session and verified on every database query.
• Super Admins (platform-level) can access all markets for support; Market Admins are scoped to their own market only.
• Production Orders, History, Chat, and Notifications are all scoped to the user's market at the database level.