Jonathan Kirkwood ae967494bd 0.2.42: external Administrator role with entity-scoped management
The external fund_administrator role (relabeled Administrator) now signs
into the full admin interface, fenced to the funds and SPVs granted to
it via EntityAccess:

- Partners, capital accounts, documents (upload and delete), entity
  edits, and eNAV imports for its own funds only; no fund creation,
  valuation sign-off, audit log, or investor view.
- Scoped user management: sees and manages only investors tied to its
  funds; creates investor accounts only; updates preserve grants on
  funds outside its scope.
- New DELETE /api/users/{id} (in-app Delete user button) with the
  cascade cleanup factored out of the CLI; Service Admin and self are
  protected, and an Administrator can only delete an investor who
  belongs solely to its funds.
- Internal fund_admin relabeled 'Staff (all funds)' and dropped from
  the create picker to end the two-similar-names confusion.
- Version badge removed from the UI (sidebar and portal header); the
  build version now logs to the browser console instead.
- deploy/.startos (signing key) added to .gitignore.
2026-08-10 15:38:39 -05:00
2026-06-07 19:23:26 +00:00

Ten31Portal

Internal system of record for Ten31 entities, holdings, positions, and quarterly valuation sign-off.

Accounts and access

Two kinds of accounts:

  • Internal staff (approver, cfo, fund_admin, viewer) — the full back-office app (entities, holdings, valuations, import, audit). approver and cfo also get the admin screens below.
  • External accounts (investor, fund_administrator) — a separate, entity-scoped portal. An external account only sees the entities granted to it.
    • Investor — sees, per fund, their latest capital-account value and history, plus documents shared to the fund or addressed privately to them (e.g. their K-1).
    • Fund administrator — sees assigned entities and can upload documents for them (shared or addressed to a specific investor).

Admin screens (Users / Documents / Capital Accounts, visible to approver and cfo) let you create an account with a username and password, check off which entities it can view, upload documents, and enter each investor's capital-account figures.

Login accepts a username or an email. The first admin is created from the CLI:

ten31portal-cli create-user --name "You" --username admin --role cfo --password '...'
# --email is optional; external accounts are normally created from the Users screen.

Prerequisites

  • Python 3.11+
  • Node.js 20+

Backend

cd backend
python -m venv .venv
source .venv/bin/activate
pip install -e .
uvicorn ten31portal.main:app --reload --port 8000

Health check: GET http://localhost:8000/api/health

Frontend

cd frontend
npm install
npm run dev

Opens at http://localhost:5173. Proxies /api to the backend on port 8000.

Project structure

ten31portal/
  backend/
    ten31portal/       # FastAPI application
      main.py          # App object and health endpoint
      config.py        # Env-based configuration
    pyproject.toml
  frontend/
    src/
      App.tsx          # Main component
      main.tsx         # Entry point
    vite.config.ts
  deploy/              # StartOS packaging (Issue 17)
  SPEC.md              # v1 issue specs
S
Description
mirror of gitea.ten31.ai Ten31AI/Ten31-Portal
Readme MIT
575 KiB
Languages
TypeScript 49.6%
Python 48.2%
Makefile 0.9%
Shell 0.4%
JavaScript 0.4%
Other 0.5%