Deal Room · Operator Runbook · Working Draft

Deal Room — Usage & Test Plan

How to run the Deal Room from the admin panel — no terminal, no code. Six click-through workflows, a six-phase test plan you can walk through in an afternoon, and a plain-English troubleshooting list for the things counterparties actually report.

Version 2.1 Updated 2026-08-10 Status Working Draft — Internal Audience Operators & Reviewers

§ 00New Features

Recent additions to the Deal Room, newest first. Full how-to for each lives in its own workflow card below — this is just the "what's new and why" log.

2026-08-13 — Sessions last 90 days (was 24 hours)

A signed-in viewer now stays signed in for 90 days instead of one day, and Manual Access Grant links stay usable for up to 30 days before first use (default 7 days, was 1 hour). Architect direction: access needs to be convenient — a bank working through weeks of diligence should not be requesting a fresh emailed code every single morning.

What this changes for operators: expiry is no longer what removes access. Revocation is. That makes the new 90-day access review (workflow K) the control that actually matters — walk the Attendees, Share Links, and Manual Access Grants panels and revoke what should be closed. Nothing reminds you; it is a manual process.

Also fixed the same day: re-clicking an already-used grant link no longer shows "Link not available" to someone who still holds a valid session — they are simply let into the room. If the session really is gone, the message now points at the room link and the normal access-code flow.

2026-08-10 — Manual Access Grant (no email/OTP)

New admin action for the case where a recipient's own email security — a bank or institution running Proofpoint/Mimecast-style filtering, say — silently blocks or quarantines the OTP code email before it ever reaches an inbox. Resending doesn't help in that case; it's their infrastructure filtering it, not a Carbotura delivery failure.

After verifying the recipient's identity out-of-band (a call, a counsel-attended session), an admin can now issue a single-use link from the room's Share Links row (🔑 Manual grant) that signs the recipient straight into a real viewer session — no code generated or transmitted at all, ever. The link is plain HTTPS, so it doesn't trip the same "6-digit code" filters. Fully audited (who granted it, why, when, and when it was opened) and reversible (an unused grant can be revoked; a consumed one becomes a normal viewer session, revocable the normal way via Attendees). See workflow J.

§ 01Overview

The Deal Room is Carbotura's counterparty-facing document distribution system. Instead of emailing PDFs one-off, you build a room per counterparty, attach documents from the master library, and send a share link. The recipient signs in with a one-time code, clicks through the NDA, and views what you've granted them — every view is logged, every PDF is watermarked with their email, and downloads are gated per room — a single room-level "Download allowed" toggle, not a per-document setting.

Access levels — universal across all audiences

Every document has a tier, and a tier means the same thing for every recipient — there is no per-audience matrix. You set one tier ceiling per room, attach the documents that belong in that room, and hide or remove anything inappropriate. A recipient sees every attached document up to the room's ceiling, subject to the three floors below. Appropriateness is handled by curation (what you attach), not by a profile.

Tier 0
Public
No gating. Shown on the landing page before sign-in. The investor pitch deck lives here.
Tier 1
Confidential
OTP + NDA. The bulk of a room — CSA terms, regulatory, technical summary, financials-as-attached, ESG, risk, legal.
Tier 2
Vault
OTP + NDA + a per-doc grant with named scope. Full financial model, capital structure, deep technical.

Three hard floors — never relaxed by universal levels:

  1. NDA required for every audience to reach T1+ content — Tier 0 public content is shown on the landing page pre-OTP with no NDA. A paper/out-of-band NDA is recorded as an audited per-room override (with a reference to the executed paper), never a silent per-audience default.
  2. Every Tier 2 doc still needs its per-doc grant (audited reason, revocable) — a room ceiling of T2 alone does not reveal vault docs.
  3. Permanent exclusions — vendor identities, full FMEA, URVS methodology inputs — are never disclosed at any tier. No override.

Full model: admin/dr/DEAL_ROOM_MODEL.md.

What's live today

  • Master library: 6 documents, latest is the Pitch Deck v4 (Tier 0, Public), added 2026-07-01.
  • Audience profiles: 7 — investor, municipality, bank, partner, regulator, vendor, senior lender/ITA.
  • Deal rooms: One test room (alw-selftest-1). No production counterparty rooms yet.
  • Admin panel: Live at admin.carbotura.com/admin/dr/.
  • Status: Pre-release. Nothing sent to an outside counterparty yet. Test-drive it end-to-end (§4) before we open the first door.

§ 02How to get in

One URL, one sign-in. What you can do depends on the role you're granted.

Sign in

  1. Open admin.carbotura.com/admin/dr/ in your browser.
  2. Cloudflare Access will send you a one-time login link by email. Click it.
  3. You land on the Deal Room dashboard.
Bookmark the dashboard URL. Cloudflare Access remembers your session for ~24 hours on the same browser. You'll typically re-authenticate once a day.

Roles & what they can do

RoleCan do
OwnerEverything, including delete rooms, revoke links, purge recipient records
ApproverApprove screenings, grant tier-2 access, edit any recipient, resolve threads
RequesterCreate rooms, add documents to the library, send share links, screen recipients
CommenterRead all admin views, leave internal notes on rooms and recipients
ViewerRead-only — see the panel, no action buttons

Roles are additive. Higher tiers include everything below. If you're not sure what your role is, look at the top-right of the dashboard — it shows your email and role badge.

Getting yourself or someone else added

The Architect (Allen) controls the access list. Email [email protected] with:

  • The email address to add
  • The role level you're requesting (Approver / Requester / Commenter / Viewer)
  • Why (one line — "co-leading the Q3 investor outreach", "verifying legal packet", etc.)

Turnaround is usually same day. Once added, wait ~30 seconds after Allen confirms, then reload the dashboard — your role badge should update.

§ 03Ten core workflows

Every routine operation maps to one of these. All click-through from the dashboard — nothing else required.

AAdd a document to the library

Every document enters the system once through the library. From there you can attach it to any number of rooms.

  1. Dashboard → Library in the left nav.
  2. Click + New document at the top of the library table.
  3. Fill in the metadata: title, doc type (Offering Memo, Financial Model, Diligence Report, etc.), section, and confidentiality level.
  4. Upload the PDF. It uploads directly from your browser to the document store.
  5. Review the page count and file size the system reports back. If it looks off, cancel and re-upload.
  6. Click Publish to make the document available for attachment to rooms. Documents in Draft state can't be attached yet.
Version bumps: to release a revised version of an existing doc, open the library row, click + New version, and upload the new PDF. The prior version is auto-marked "superseded" but retained for audit — rooms that pinned to it keep serving it until you re-attach.
Library folder tree. The Library's list view is the same hierarchical folder tree as room documents — nest with / in a document's Library folder (set it at create, via the 📁 button on a row, or by dragging the row onto a folder header; Rename on a header batch-updates the folder's documents; drag a folder header onto another folder’s middle to move the whole subtree, or to a sibling’s top/bottom edge to reorder at the same level). A document’s Library folder is also the default room folder wherever the doc is attached (add-doc prefill, standard set at room creation, bulk folder attach) — rooms mirror the Library unless you curate a room differently. This tree is admin-side organization only: viewers never see it, and it's independent of both the Section taxonomy and the per-room folders you assign when attaching (workflow C). → Room on a folder header bulk-attaches the folder's documents to a room — see the callout in workflow C.
New Folder / Delete. + New Folder at the bottom of the tree declares an empty folder ahead of any document — it renders and can be dragged into/onto exactly like any other folder, and persists empty until you either file something in it or explicitly Delete it (Delete only succeeds when the folder — and every sub-folder — is genuinely empty; otherwise it tells you how many documents are still there).
Library folders are master folders — opt-in cascade. When you rename, re-parent, or re-file a Library folder (or a single document's folder), and one or more rooms still mirror that folder (i.e., the room's copy was left at its Library-derived default, never hand-edited), a checklist modal appears — every linked room pre-checked. Uncheck any room you want to leave alone; those get unlinked (won't be offered again for this folder) rather than silently resynced later. Checked rooms get their folder overwritten to match the Library's new placement. A room where you've ever hand-typed a different folder name is never offered — that's your opt-out, decided once at attach time.
Placeholder flag. The Upload New Version form has a "This is a placeholder" checkbox — check it for a stand-in file that still needs the real document. Flagged versions show a ⚠ Placeholder pill everywhere the document appears (Library, any room it's attached to, the version-history table) until a real version replaces it. Use this liberally — an unflagged placeholder is invisible until someone opens it and finds a stub, or (worse) a version row pointing at a file that was never actually uploaded.
Replacing with a differently-named document (links preserved): every link in the system — room attachments, share links, pins, grants — follows the permanent Document ID, never the title or the PDF's filename. So to swap in a replacement doc with a completely different name: (1) upload the new file as a + New version (any filename works), and (2) click Edit details on the document page to update the title/section to match. Viewers in unpinned rooms see the new document immediately at the same links. Never create a new library record for a rename — that would orphan the links.

BCreate a deal room

One room per counterparty (or per named prospect group).

  1. Dashboard → Rooms in the left nav.
  2. Click + New room.
  3. Give the room a name (used for your reference — the recipient never sees the slug, only the display title). Something like Acme Capital Q3 diligence.
  4. Pick the audience profile — the category that best matches the recipient (Investor, Bank, Municipality, Regulator, Partner, Vendor, Senior Lender/ITA). This sets the section ceilings for the room.
  5. Add recipient emails. One per line. Only these emails can access share links minted from this room.
  6. Leave Attach the standard document set checked (default) to auto-include your canonical docs, and/or pick a Template to snapshot a named bundle. Both copy docs in at creation; you can add/remove per room afterward.
  7. Click Save. The confirmation tells you how many docs attached (and how many were skipped).
Standard set only pulls in PUBLISHED docs. Flagging a library doc as "standard" (Library → doc → Standard document — offer on every new room) does nothing until that doc is Published — a Draft flagged standard is skipped, because a draft has no servable version. If a new room comes up missing its standard docs, check the create confirmation for "N standard docs skipped (unpublished)" and publish them in the Library; then they flow into every future room (existing rooms don't retro-fill — add them via workflow C).

CAttach documents to a room

Pull documents from the library into the room, arrange them in the order the recipient should see, and optionally pin to a specific version.

  1. Open the room from the Rooms list.
  2. In the Documents tab, click + Attach.
  3. Search or scroll the library. Click each doc you want to add. The panel shows the doc's tier next to its title — if it's above the room's ceiling, you'll see a warning icon.
  4. Click Attach selected. The docs appear in the room's list.
  5. Drag rows to reorder. This is the order the recipient sees.
  6. Optionally, click a doc's row → Pin version to freeze the room on a specific version (useful when a doc's library entry keeps evolving but you want this room to stay on what you already sent).
Tier-above-ceiling warning: if you see a warning icon on a doc, the audience profile's section ceiling is lower than the doc's tier. Recipients will 403 when they click. Either move the doc to a higher-tier room, grant tier-2 (workflow D), or drop the doc from this room.
Folder tree. Room documents render as a hierarchical folder tree. Nest with / in the folder path — Legal/Contracts/2026 is a three-level tree. Every level expands/collapses (remembered per room). Move a document by dragging it onto a folder header (or the "move out of all folders" strip), or via Move to Folder with any path; drag ⋮⋮ to reorder within a folder. Folders move as units too — drag a folder header onto another folder’s middle to re-parent the whole subtree (never into itself), or to a sibling’s top/bottom edge (blue insert line) to reorder folders at the same level; the viewer follows the same order. Rename on a folder header batch-updates every document inside. A folder normally exists only while a document is in it — + New Folder at the bottom of the tree overrides that, declaring an empty folder that persists (admin-side) until you Delete it (only allowed when genuinely empty). A declared-empty folder is admin-side staging only — the viewer's own tree still derives purely from actual documents, so an empty folder has nothing to show them and simply doesn't appear until you file something in it; at that point the viewer sees it exactly like any other folder.
Attach a whole Library folder. 📁 Add library folder in the room's Quick Actions (or → Room on a folder header in the Library tab) attaches every document in a Library folder — subfolders included — carrying the structure into the room's viewer folders. Tier rules run per document: Tier 2 vault docs come back flagged as needing their per-document grant (add those individually to record the audit reason), above-ceiling and permanently-excluded docs are refused, and a result summary tells you exactly what landed. A folder is never a bypass of the tier system.

DGrant tier-2 access

Some documents at Tier 2 need an extra grant, even after they're attached — typically the financial model or capital structure documents for lender/ITA rooms. The grant records the engagement scope so there's an audit trail of what the recipient was told they could see.

  1. In the room's Documents tab, find the doc marked "Grant required" (yellow badge).
  2. Click the doc's row → Grant tier-2 access.
  3. In the reason field, paste the engagement letter scope verbatim (e.g., "Engagement letter §3.2: FMEA Stage IV–VI summary, KPI history, insurance/reserve structure only"). Write it as if a lawyer will read it later — because they might.
  4. Pick the specific recipient email if the grant is per-person (leave blank if it applies to all recipients on the room).
  5. Click Grant. The yellow badge turns green — the doc is now accessible.

ESend a share link

Share links are the only way a recipient reaches the room. Each link is bound to a specific recipient email, has an expiry date, and caps the number of times it can be opened.

  1. Open the room. Go to the Share Links tab.
  2. Click + New link.
  3. Pick the recipient (or "all recipients") and set the expiry — 7 days is a reasonable default for warm leads; 30 days for signed diligence engagements.
  4. Set the max-view budget — 50 views is the default; caps a leaked link from being scraped forever.
  5. Confirm the NDA and screening requirements shown (both should be inherited from the audience profile).
  6. Click Generate. The link URL appears — copy it.
  7. Send it to the recipient by email. The system does NOT send the email for you — you paste it into your own email client. That way you get an inbox record and can add context.
What the recipient sees: they click the link, get a one-time-password by email, enter it, click through the NDA, then land in the room. Every PDF they open is watermarked with their email on every page. Downloads are off by default; turn on Download allowed on the room (Edit Room) if they need self-serve offline copies — a real Download button then appears in their viewer, producing a watermarked PDF automatically. No manual file-minting needed.
Access code column + Resend. Each link row shows the state of the recipient's current access code — live · exp HH:MM UTC, used, expired, or no code issued — and a Resend code button that emails a fresh code (invalidating the old one). For security the code itself is never shown — it's stored hashed; if a recipient can't find their email, Resend, don't read a code out.

FApprove a recipient (screening)

Recipients of a Rule 506(c) surface (Tier 1 or above) are screened for accredited-investor status. Under the deferred-screening policy (see the callout below) this no longer blocks starting diligence — it gates closing. New recipients start as Pending; you resolve them to Clear, Flagged, or Blocked.

  1. Dashboard → Screenings in the left nav.
  2. Filter to "Pending" — these are the recipients waiting on your review.
  3. Click a row. Review the verification documents the recipient uploaded (accredited-investor letter, verifier attestation, etc.).
  4. Click one of: Clear (recipient is verified), Flag (hold for human review — they can't access yet), or Block (hard 403 forever).
  5. Add a short note explaining your decision. This is preserved in the audit trail.
  6. Click Save. For Clear, the recipient can immediately access rooms they've been added to. For Blocked, any existing share links they hold are revoked at the same moment.
Regulators are the one exception. Regulators come in under their existing statutory authority, not under 506(c), so their rooms don't require accredited-investor screening (a paper/statutory basis is recorded via the per-room NDA override). Don't run the screening flow on regulator rooms unless the Architect asks you to.
Screening is deferred to closing (Architect policy, 2026-07-28). Formal verification no longer blocks starting diligence. When you generate a share link for a recipient who isn't yet Clear (never screened / pending / expired), you (owner/master admin) get an Approve + Issue Link prompt — add a note and issue; the recipient is auto-queued Pending for the closing punch-list. A Flagged or Blocked recipient still hard-blocks (architect override only). Closing gate: documents in the CLOSING_DOCS section won't open for a viewer until that viewer is Clear — so formal sanctions/CFIUS/PEP verification is required before closing documents are accessible. Put subscription agreements / closing checklists in CLOSING_DOCS. See admin/dr/DEAL_ROOM_MODEL.md §4b.

GProvision a room from an access request

When someone asks for access through a gate's request-access form (the request lands in Admin → Gates → Access Requests as pending), you can turn that request into a live deal room and share link in one step — no need to build the room, add the recipient, and mint the link as three separate chores. This is the bridge between the inbound "they ask" path and the outbound "you send a link" path (workflows B + E).

  1. Admin panel → Gates tab → the request list. Find the pending request.
  2. Click → Deal Room on that row.
  3. Choose Create new room (prefilled title + slug from their org/name; pick the tier ceiling — T1 is the default) or Add to existing room (pick a room; their email is merged into its allow-list). New rooms default to NDA required.
  4. Set the link expiry (14 days default) and label, then click Provision & mint link.
  5. If the room's profile requires a screening deferral, the modal asks for an approval note — add it and provision again (this is the same deferred-screening approval as workflow F; a flagged/blocked recipient still hard-blocks).
  6. Copy the share link the modal shows and send it to the recipient from your own email client. The request is automatically marked approved with an audit note recording the room and link.
What this does under the hood: exactly workflows B (create room / add recipient) and E (mint share link) — it just runs them together from the request row and reuses the same server-side checks (screening gate, tier ceiling, NDA default, permanent exclusions, audit). It attaches no documents — open the room in the Deal Room tab afterward to curate its document set (workflow C) and issue any Tier 2 grants (workflow D).

HSee & manage attendees

Two different questions, two different places:

  1. Who is permitted — the room's recipient allow-list. Open the room → ✎ Edit roomRecipient emails (comma-separated). Add or remove people here. Remember the two-gate rule: a viewer must be on the room recipient list and on the specific share link's allow-list to get in.
  2. Who has actually entered — the Attendees panel on the room page. It lists every viewer who verified with an access code, with their screening status, whether their session is active or expired, whether they accepted the NDA, session and view counts, and first / last seen.

To remove someone who is already in, click Revoke on their attendee row. That ends their live session immediately, drops them from the recipient allow-list so they can't request a new code, and revokes any share link scoped only to them.

Revoke is per-person, and surgical. A shared share link (one link listing several emails) is left intact when you revoke one attendee — the allow-list removal is what keeps them out — so you don't accidentally cut the other people on that link. It's also different from the two neighbouring actions: Screening (workflow F) clears or blocks an identity; Revoke link (workflow E) kills a link; Revoke attendee removes one person's access to one room.
Didn't get a code? The Access-code attempts card on the same room page shows every access-code request and its outcome — sent (with the mail-provider id), rejected — email not on allow-list (wrong address for that link), rate-limited, or send failed — so a "the code never arrived" report is diagnosable at a glance instead of being invisible.
Code shows "sent" but they still never get it? That's their own email security, not us — common at banks/institutions running Proofpoint/Mimecast-style gateways that flag a "6-digit code" email pattern outright. Resending won't help; it'll get filtered again. Instead: on that share-link row, click 🔑 Manual grant — but only after you've verified the recipient's identity out-of-band (a call, a counsel-attended session). It creates a single-use link with no code in it at all; send it over whatever channel actually reaches them. See workflow J.

K90-day access review

Viewer sessions last 90 days (raised from 24 hours on 2026-08-13 — a counterparty in a multi-week diligence cycle should not be re-requesting an access code every day). The trade is that expiry is no longer what removes access — you are. Roughly every 90 days, or whenever a deal changes state, walk the rooms and revoke what should no longer be open.

  1. Open each active room → Attendees. This is everyone who actually got in, with their last-seen date.
  2. Revoke anyone who should no longer have access — deal died, person changed roles or left the counterparty, or they simply never came back. Revoke ends their live session immediately and drops them from the allow-list, so they cannot re-request a code.
  3. Check Share Links on the same room and revoke stale or duplicate links. Retry loops leave several live links pointing at the same room — each one is a working front door.
  4. Check Manual Access Grants for any still pending that are no longer needed, and revoke them.
  5. If a whole engagement is over, set the room itself to inactive — that closes every link and session at once, which is faster and safer than revoking person by person.
Nothing automates this. There is no reminder, no expiry sweep, no report that tells you a review is due. If the review does not happen, every session simply persists for its full 90 days. Put it on a calendar.

JGrant access without email/OTP (Manual Access Grant)

For the specific case above — a recipient's own email security is confirmed to be blocking the OTP code, and you've verified who they are some other way. This is a deliberate, audited exception to the normal email-verified flow, not a general-purpose shortcut — use it only when resending genuinely won't help.

  1. Confirm it's actually their side blocking it: check Access-code attempts shows sent, not send failed or rejected.
  2. Verify the recipient's identity out-of-band — a phone/video call, a counsel-attended session, whatever your process for that counterparty already requires.
  3. On the room page, find their share link and click 🔑 Manual grant.
  4. Fill in their email, a short reference to how you verified identity (required — this is the audit trail), and pick how long the unused link stays usable (4 hours to 30 days, default 7 days). That timer only governs the link before first use — it still burns the moment it's opened, and their session then lasts 90 days.
  5. Click Create grant. Copy the resulting URL and send it to the recipient over any channel — it's a plain link, not a code, so it doesn't trip the same filters. It works once; opening it signs them straight in.
Reversible, same as everything else here. An unused grant can be revoked from the Manual Access Grants panel before it's opened. Once opened, it's already become a normal viewer session — revoke that the normal way, from Attendees.

IOpen a document without downloading it

Every document row — Library or a room — has a 👁 View button that opens the file inline (PDF only; other types still fall back to download).

  1. From a room's document list: 👁 View opens the document exactly as pinned in that room — if it's version-pinned, you see the pinned version, not necessarily the Library's current one.
  2. From the Library: 👁 View opens the current version. To check a specific past version (including a withdrawn one), open the document's detail page and click 👁 View on that version's row in the history table.
This is an internal audit view, not the recipient's viewer. No comments/messaging/AI panel, no watermark (you already have full access — watermarking traces external recipients, not staff), and no engagement telemetry (an admin preview doesn't inflate investor-engagement metrics). It's the same underlying PDF viewer as the recipient's, just a stripped-down admin mode.

JPromote or demote an investor's access level

Every visitor who verifies through the Finance Portal's email gate (or signs in via CF Access) resolves to one investor identity — the same row this workflow manages. There's no separate "deal room investor" concept; access_level is the single ladder every check in the portal reads.

  1. Dashboard → Investors in the left nav (/admin/investors/).
  2. Find the row (search by email or name) and click it, or its Promote / demote button.
  3. Pick the new level from the ladder: 0 Public · 1 NDA · 2 Qualified · 3 Accredited · 4 Lead · 5 Closing · 6 Post-close · 7 Trustee/Bondholder · 8 Board · 9 Architect.
  4. Add a reason (recommended, not required) — it's the audit trail, shown in that investor's grant history right below the form.
  5. Click Save level.
This is the front-door "how far in" level, not a Deal Room tier grant. It's separate from a room's Tier-2 vault grant (workflow D) — a Tier-2 document inside a specific room still needs its own per-document grant regardless of an investor's overall level. Also separate from Rule 506(c) accredited-investor verification — this ladder tracks where someone is in the relationship, it doesn't itself certify accreditation for a securities offering.

§ 04Test plan

Six phases you can walk through end-to-end in a single afternoon. Checkboxes save your progress in your browser — close the tab, come back later, pick up where you left off. Use the throwaway room alw-selftest-2 so the historical test room (alw-selftest-1) stays untouched.

0/0 tasks
Phase 1

Master library sanity

Goal: prove every document actually opens
  • 1.1Open the library. Dashboard → Library. Confirm you see the 6 documents listed, each with a title, tier badge, and "Published" status.
  • 1.2Preview every doc. Click each row → Preview. The PDF should render in-browser. If any preview shows "File not found" or hangs, note the doc ID and flag it — the library metadata and the actual file are out of sync.
  • 1.3Check version parity. For any doc showing "v2" or higher, click Versions and confirm the "Current" version matches what the preview showed. Superseded versions should be marked with a grey badge.
  • 1.4Confirm confidentiality labels. Every doc should show a tier badge (Tier 0 through Tier 4) and a confidentiality label (PUBLIC, NDA_REQUIRED, INVESTOR_CONFIDENTIAL, etc.). Anything showing "Unset" is a bug — flag it.
Phase 2

Room setup on a fresh test room

Goal: build a room end-to-end with a mix of tiers
  • 2.1Create the test room. Rooms → + New room → name it alw-selftest-2, pick audience profile Investor, add your own email as the recipient. Save.
  • 2.2Attach a Tier 0 doc. Documents tab → + Attach → pick the Investor Overview — Pitch Deck v4 (Public tier). Should attach with no warnings.
  • 2.3Attach a Tier 1 doc. Attach the RevCon™ Mechanics 2027 document. Should attach — investor profile allows Tier 1 in TECHNICAL_DILIGENCE.
  • 2.4Attach a Tier 2 doc. Attach the Cornerstone Preferred Financial Model. Panel should show a yellow "grant required" badge — that's expected. No error yet.
  • 2.5Grant tier-2 access. Click the Cornerstone Preferred Model row → Grant tier-2 access → reason: Test grant — runbook Phase 2.5. Save. Badge turns green.
  • 2.6Check final state. Reload the room. You should see 3 documents attached in order T0 → T1 → T2. Drag to reorder if needed. Your recipient email is listed in the room header.
If alw-selftest-2 already exists from a prior test — archive it first (room detail → Archive), or use alw-selftest-3 for this pass. Don't reuse a room slug — audit trails don't survive slug reuse.
Phase 3

Recipient dry-run

Goal: prove the outside-world path works
  • 3.1Send yourself a share link. Room → Share Links → + New. Expiry: 2 days. Max views: 10. Recipient: your own email. Click Generate. Copy the URL.
  • 3.2Open in an incognito window. Paste the URL. You should see an OTP prompt, not the room. Check your email — the OTP code should arrive within 30 seconds.
  • 3.3Enter the OTP. Eight alphanumeric characters. You should now see the NDA click-through screen.
  • 3.4Acknowledge the NDA. Click through. You land in the room. Confirm all 3 documents are visible with correct titles.
  • 3.5Open the RevCon™ Mechanics doc. Every page should show your email as a watermark in a corner. If the watermark is missing or shows a different email, flag it.
  • 3.6Confirm the download button matches the room's setting. If the room's Download allowed is off, the viewer toolbar has no Download button (right-click Save may still work in some browsers — the watermark travels with the file, which is by design). If it's on, a real ⬇ Download button appears; click it and confirm a genuine save happens (not just the inline PDF.js view) and the saved file shows the watermark on every page.
  • 3.7Check the view log. Back in the admin panel, reload the room. The Views tab should show your session with timestamp, IP country, and which pages you scrolled through.
  • 3.8Hit the view cap. Reload the doc 10+ times. On the 11th, you should see "session budget exhausted", not the doc. If you can keep viewing past 10, the cap is broken — flag it.
Phase 4

Screening flow

Goal: exercise pending → clear → blocked
  • 4.1Add a pending recipient. Room → Recipients → + Add — use a second email you can access. Screening state defaults to Pending.
  • 4.2Try to mint a link for them. The panel should refuse: "recipient pending screening — link cannot be minted".
  • 4.3Approve them. Screenings → filter Pending → find the row → Clear → note "Test clear — Phase 4.3".
  • 4.4Re-try the share link. Now succeeds. Confirm the recipient can open the room and see the docs.
  • 4.5Block them. Screenings → find the row → Block → note "Test block — Phase 4.5".
  • 4.6Confirm hard 403. Reload the recipient's share link in incognito. Expect an immediate hard-block screen — no OTP, no NDA, just "access denied".
Phase 5

Version bump

Goal: prove version pinning holds when the library rolls forward
  • 5.1Pin the current version. In alw-selftest-2, find the RevCon™ Mechanics row → click Pin version → select the current version. Save.
  • 5.2Add a test new version to the library. Library → RevCon™ Mechanics → + New version → upload the same PDF (renamed as v1.3 for the test — this is a dry-run). Mark it Active.
  • 5.3Verify the library rolled forward. The library row's "Current version" should now show v1.3.
  • 5.4Verify the room still holds the pinned version. Back in alw-selftest-2, the RevCon™ row should still show the pinned version, not v1.3. If you re-open the share link, the recipient sees the pinned version.
  • 5.5Clean up. Library → RevCon™ Mechanics → v1.3 row → Mark superseded (or delete, if it's the only version you added just for testing).
Phase 6

Cleanup

Goal: leave the system in a clean state
  • 6.1Revoke test share links. Room → Share Links → for each link created during phases 3–4, click Revoke.
  • 6.2Remove test recipients. Room → Recipients → remove the throwaway emails added during phases 3 and 4.
  • 6.3Remove test grants. Room → Documents → Cornerstone Preferred Model row → Revoke grant. (Keeps the audit record but marks the grant inactive.)
  • 6.4Archive the test room. Room detail → Archive. Don't delete — archiving keeps the audit history but hides the room from the default Rooms list.
  • 6.5Report the run. Email the Architect (or drop in Teams) with: which phases you ran, any failures you saw, and any UX friction that felt confusing. Even "no failures" is worth reporting.

Ship gate: before we open the Deal Room to the first outside counterparty, Phases 1–4 must be all-checked. Phase 5 (version pinning) is nice-to-have. Phase 6 (cleanup) is just hygiene. Any Phase 1 or Phase 3 failure is a hard stop.

§ 05Common problems & what to do

The failures counterparties actually report, and how to fix them from the admin panel.

Recipient issues

SymptomWhat to check / do
"I didn't get the access code" Open the room and read the Access-code attempts card — it shows what actually happened to their request:
  • sent (with a provider id) — the email left Carbotura. Have them check spam; wait a couple of minutes for delivery lag.
  • rejected — email not on allow-list — they typed an address that isn't on that link's allow-list (or the room recipient list). Confirm the exact address and that they're using the link minted for them.
  • send failed — a mail-provider error (the reason is shown); escalate.
  • No row at all — their request never reached us. Almost always the wrong link: make sure they're opening the public carbotura.com/dr/s/… link (use Copy URL on the link row, which always copies the public host).
You can push a fresh code yourself with Resend code on the link's row (Share Links) — it emails a new code and invalidates the old one. Codes are single-use, expire in 10 minutes, and are stored hashed — you cannot view or forward a code; the recipient enters it from their email.
"The link says expired" Room → Share Links → mint a new one for that recipient. Old links can't be un-expired.
"I clicked the link and got 'access denied'" Check three things, in order: (1) their screening status — must be Clear, not Pending or Blocked. (2) their email is on the room's recipient list — a link generated for recipient A doesn't work when opened by B. (3) their audience profile ceiling — if all the room's docs are Tier 2 and their profile caps at Tier 1, they'll see zero docs.
"I see the room but a doc says access denied when I click" That doc is above the audience profile ceiling, or requires a tier-2 grant. Go to the room → doc row → grant tier-2 access with a reason (workflow D).
"The watermark isn't showing" Reload the doc. If still missing, check the library entry — the doc's "Watermark required" flag might be off. Anything above Tier 0 should have it on; Tier 0 docs are unwatermarked by design.
"I need to download this — can I have the file?" Never send the R2 file directly. Go to Room → Edit Room → check Download allowed. Every PDF in that room then shows a real Download button that self-serves a watermarked copy — no manual file-minting or emailing required. Every download is logged in the room's Views tab (viewer email, IP, timestamp).

If they should get most documents but not all, leave the room switch on and block the exceptions individually: room document list → ⬇ Block DL on each document to withhold. A blocked document stays readable in the viewer, just not savable.
"I see an old version — you sent me a new one but it's not showing" The room is version-pinned. Room → doc row → Pin version → select the new version (or Clear pin to follow current). Then re-send the share link.

Operator issues

SymptomWhat to do
"I can't see the + New room button" Your role is Commenter or Viewer. Ask the Architect to bump you to Requester (workflow §2.3).
"I can't approve a screening" Your role is Requester or below. Only Approvers and Owners can flip screening status to Clear or Blocked.
"The Documents tab shows a red exclamation on a doc" The doc is attached but its tier is above the audience profile ceiling. Either detach it, or upgrade the room to a higher-tier profile (may require the Architect).
"Upload keeps failing" File size: max ~50 MB. If yours is larger, contact the Architect — some docs need out-of-band handling. Also check the PDF isn't password-protected — encrypted PDFs are rejected on upload.
"I made a mistake — how do I undo?" Almost every action is reversible. Attached the wrong doc? Detach it. Sent a link to the wrong person? Revoke it. Blocked someone by accident? Flip them back to Clear. The only irreversible action is hard delete — use Archive instead of Delete whenever possible.
"The dashboard is empty" Sign out and sign back in. If it stays empty, your role probably dropped to Viewer during a config change — ping the Architect.

§ 06Reference

Quick lookups for the things you'll ask about while working in the panel.

Audience profiles

Moving to universal levels (see §01 and admin/dr/DEAL_ROOM_MODEL.md). Access levels are the same for every audience — the per-audience section matrix is being retired. A profile now supplies only room defaults (tier ceiling, NDA, watermark, download), which you set per room; appropriateness is handled by curation, and the three hard floors (NDA, T2 grant, permanent exclusions) always apply. The table below is the historical per-audience ceiling for reference during the transition:

ProfileWhoDefault ceilingNDA default
InvestorAccredited investors, family offices, fundsTier 2Yes
MunicipalityCommunity / city / county officialsTier 1Yes
Bank / project financeCommercial banks, lenders (initial)Tier 2Yes
PartnerStrategic / commercial partners under LOITier 1Yes
RegulatorState / federal / agency reviewersTier 1Now Yes — set the per-room NDA override for statutory access
VendorEquipment / service suppliersTier 1Yes
Senior Lender / ITAProject-finance lender with ITA engagementTier 2 (w/ grant)Yes + counsel

Confidentiality labels

LabelTypical use
PUBLICAnyone can view. Downloadable. No NDA. (Pitch deck lives here.)
NDA_REQUIREDNamed recipient + NDA click-through
INVESTOR_CONFIDENTIALInvestor-profile rooms only; NDA + screening
QUALIFIED_INVESTORAccredited-investor verified; screening required before access
INSTITUTIONALBank / lender / partner; MNPI protocols apply
TRUSTEE_ONLYNamed trustee or counsel; sealed access, hardest tier

Library document fields

What every field on the New Library Document modal (and version upload form) means. The same definitions pop as ⓘ bubbles on the fields themselves.

FieldPurpose
Document IDPermanent identifier, never changes across versions — what rooms, grants, audit rows, and AI citations reference. Convention CTB-<AREA>-<DOC>-<SEQ> (e.g. CTB-CLN-OM-001). Cannot be renamed after creation.
Round keyOptional link to a capital round (cln, series_a) — round-scoped surfaces (portal round pages, binders) pull by this. Blank for round-independent docs.
TypeThe kind of instrument (Offering Memo, Financial Model, Trust Document, …). Drives library grouping, room templates, and binder assembly.
SectionDeal-room section it files under (CORPORATE, FINANCIALS, …). Audience profiles gate access per section — picking the section is part of the access model, not just filing.
TierHow hard the doc is to reach: T0 public (pre-OTP landing) · T1 after OTP+NDA · T2 vault (per-doc grant required in every room). See §01.
ConfidentialityThe legal/handling label. Must agree with tier: PUBLIC↔T0; NDA_REQUIRED / INVESTOR_CONFIDENTIAL↔T1; QUALIFIED_INVESTOR / INSTITUTIONAL / TRUSTEE_ONLY↔T2. Tier = how a viewer reaches it; confidentiality = what it is.
Watermark viewer copiesDefault on: every served page carries the viewer's verified email diagonally — leaks become attributable. Per-link overrides exist.
Allow downloadA global library flag driving inline-vs-attachment on the finance-portal path — the deal room does not consult it. Deal-room downloads are gated by the room's "Download allowed" switch, with per-document carve-outs on the room's own document list (⬇ Block DL), since downloadability is a per-room decision and this field is global.
Require acknowledgmentViewer must click "I acknowledge" before first view; timestamped per viewer. Use where you need provable notice, not just provable access.
Status (Draft/Published)Draft = not attachable to rooms yet. Publish once the current version is the one counterparties should see.
Version labelHuman-readable version name ("1.0", "July 2026"). Keep a consistent scheme per document.
Make currentOn upload, all rooms not pinned to a version start serving this file immediately; pinned rooms keep their pin. Uncheck to stage quietly.
Release notesOptional note recorded with the version — audit trail of what changed without diffing PDFs.

Related