Incident entry / authorized

Start a real incident or rejoin one.

Operators can open either bundled scenario. Invited live-trial judges can open webhook-race only.

Credentials remain in this browser tab

Access tokens are kept in session storage, never local storage and never bundled into the web build.

Same-origin requests only
No incident credential

Choose a real access path

Operators and invited live-trial judges enter with separately issued credentials. No credential is bundled into this page.

New controlled run

Open either bundled scenario

Operators can open either bundled scenario. Invited live-trial judges can open webhook-race only. Opening starts real isolated victim data and the five-seat analysis path. It does not approve a repair.

Concurrent valid deliveries can enqueue duplicate work. Explicitly starts the shipped webhook-race reproduction and writes only isolated victim test data. It does not approve a patch or alter a candidate worktree.

Existing authorized room

Join without opening another run

The access token opens the room. CSRF and step-up credentials unlock approval controls only.

The access token opens the room. CSRF and step-up tokens are required only for approval controls. Credentials stay in this browser tab and are never bundled into the web build.