# Operations log

Open `/admin/operations` as a platform admin. Filter by the last 30 minutes, 24 hours, or 7 days; choose an area or search for a trip reference such as `HH-20102137`. The page combines the existing trip, email, security, intake, company, role, pilot, broker, permit-cost, moderator-access, and review-ticket audit tables. It shows UTC timestamps. Each source returns at most 150 recent records within the selected window, so a busy 7-day search is a recent view, not a complete export.

Apply `supabase/migrations/0042_operation_events.sql` after `0041_permit_processing.sql` to enable the new operational outcomes, then run `node scripts/verify-migration-0042.mjs`. The pulled migration 0038 and its verification script belong to historical profiles and remain unchanged. If you already applied the earlier local operations-log migration, check migration history before applying its renamed version; see `WORKSPACE_PERMIT_PROCESSING.md`. The migration is additive and does not backfill historical events. `operation_events` has row-level security with no client policy; writes and reads go through server-side service-role code, and the page is restricted to platform admins.

New outcomes include:

- Permit processing started, succeeded, was superseded, or failed and queued for retry.
- Each dimension-alert check, including no mismatch, no eligible contacts, imported contacts excluded, duplicate or suppressed delivery, sent, and failed delivery.
- Terminal AI chat and trip-sync results. The existing request-level JSONL log remains available for deeper AI debugging.

Email `sent` means the provider accepted the message. `delivered` means a later provider webhook confirmed delivery. `recorded_not_delivered`, `suppressed`, and `failed` do not mean the recipient received it.

The logger stores short outcome codes and counts. It redacts sensitive field names and never stores uploaded files, request bodies, credentials, AI questions, or AI answers in `operation_events`. If that table is unavailable, the workflow continues and a structured server error identifies the unrecorded event.
