Skip to content
Governance-first · machine-led case intake

Debt recovery operations, under provable control.

The FedEx DCA Control Tower governs collection cases across every agency, region and role — with machine-led intake, an immutable audit trail, and boundaries the database itself enforces.

  • 11-role RBAC
  • Postgres row-level security
  • 12 immutability triggers
  • MFA enforced for admins
  • 109 governance tests
control-tower / ingestion-pipeline
Live

Enforced intake path

  1. SYSTEM ingestion

    X-Service-Auth verified

    actor_type=SYSTEM
  2. Idempotency check

    external_case_id unique

    UNIQUE index
  3. Region resolution

    Boundary locked at write

    region_id IMMUTABLE
  4. DCA + agent allocation

    Capacity · specialization

    no human override
  5. SLA bind

    Breach monitor armed

    auto-escalation

Audit trail

append-only
  • SYSTEMcase.createdFX-4471902
  • SYSTEMcase.escalatedFX-4471640
  • FEDEX_AUDITORaudit.exportedEMEA · Q3
  • SYSTEMsla.breach_detectedFX-4471640
  • FEDEX_MANAGERcase.reassignedFX-4471815

96.4%

SLA on track

12

Breaches open

1,284

Queue depth

Illustrative view of the ingestion pipeline. Sample data.

11
Governed roles

9 active · 2 legacy aliases

36
Discrete permissions

Checked server-side

12
Immutability triggers

Cases · users · regions

109
Governance tests

RBAC · auth · ingestion

500+
Agencies in scope

Design scale target

The governance model

Controls the database enforces — not the documentation.

Most platforms describe their guardrails in a policy document. The Control Tower encodes them in Postgres: intake is machine-led, governance columns are immutable at the row level, and every mutation writes an actor-identified audit record.

Creating a case is not a privilege of rank.

Cases enter through an authenticated upstream service token, with schema validation, idempotency and region resolution all running before a row exists. Exactly one human role — FEDEX_ADMIN — may open a case by exception, and only with written justification recorded against it. Seniority buys nothing here: SUPER_ADMIN, every manager and every collection agent are refused outright.

permission · cases.createbackend-enforced
  • SYSTEMALLOWED
  • FEDEX_ADMINBY EXCEPTION
  • SUPER_ADMINDENIED
  • FEDEX_MANAGERDENIED
  • DCA_ADMINDENIED
  • DCA_AGENTDENIED

Four columns nothing can rewrite

Database triggers reject any update to the fields that define jurisdiction, identity and provenance.

  • region_id

    Jurisdiction cannot be moved after write

  • external_case_id

    Upstream identity is permanent and unique

  • source_system

    Provenance survives every downstream edit

  • actor_type

    Who acted can never be rewritten

Region × Role × Org isolation

Row-level security policies scope every query to the caller's region, agency and role. An agent sees assigned cases; a DCA admin sees their agency; nobody sees across a boundary they do not own.

enforced in Postgres, not in the client
Ingestion contract

Two doors in. The second one keeps a receipt.

Upstream billing systems, RPA bots and legacy platforms all enter through the same authenticated endpoint. The only alternative is a FEDEX_ADMIN exception that demands a written justification and writes its own audit record — there is no third path and no silent bypass.

request
POST /api/v1/cases/system-createX-Service-Auth: Bearer ••••••••••••Content-Type: application/json {  "case_type": "INVOICE",  "source_system": "ERP_BILLING",  "source_reference_id": "FX-4471902",  "region": "EMEA",  "currency": "EUR",  "principal_amount": 17250.00,  "tax_amount": 1170.00,  "total_due": 18420.00,  "customer_id": "ACC-88213",  "customer_name": "Northwind Logistics BV"}
response
201 Created{  "success": true,  "data": {    "case_id": "8f2c…",    "case_number": "CASE-2026-004471902",    "sla_id": "b1e7…",    "ai_score": { "risk_level": "MEDIUM", "priority_score": 68 }  }}

A human token cannot call this

Requests without a valid service credential are rejected, and an impersonation attempt is written to the security log before the 403 is returned. The exception endpoint refuses SYSTEM actors just as firmly.

Replays cannot duplicate

The upstream reference becomes a unique key on the row. Retry the same message as often as your queue needs to — the repeat is refused as a duplicate rather than becoming a second case.

Validation happens before the row

Schema, currency, amounts and region resolve before anything is persisted, so a malformed message never becomes a partially-governed case.

Platform

Operational capability, built on top of the guarantees.

Automation is only safe when the boundaries underneath it hold. Each capability runs inside the same permission, region and audit model.

Deterministic allocation

Cases route to an agency and an agent by capacity, specialisation and performance history — the same inputs always produce the same decision, and every decision is logged.

SLA automation

Targets bind at intake. Breach detection runs continuously and escalates on its own, so a missed clock is an event in the system rather than a discovery in a meeting.

Advisory risk scoring

A dedicated ML service predicts recovery difficulty and suggests priority. Scores inform the queue; they never silently reassign work or override a governed rule.

Immutable audit trail

Every mutation writes actor type, actor identity, action, resource and timestamp to an append-only log — the evidence an auditor asks for, already assembled.

Real-time operations

Case status, assignment changes and breach alerts propagate live through Supabase subscriptions, so every workbench shows the same truth at the same moment.

Analytics & reporting

Recovery trends, cohort analysis and agency scorecards, with exportable reports scoped to whatever region and role the requester is permitted to see.

Role-based workbenches

Everyone gets the surface their role justifies.

Not one dashboard with features greyed out — separate workbenches, each scoped to what that role is permitted to see and do. What is blocked is blocked in the API, not merely hidden in the UI.

Governance workbench

Platform-wide · non-operational

The highest authority on the platform, and deliberately the least operational. It shapes the rules everyone else works inside — and cannot touch a single case.

128

Agencies

14

Regions

0

Case writes

Permitted

  • Onboard, update and retire agencies
  • Author SLA templates and region policy
  • Manage every user, role and assignment
  • Full audit log and security settings

Blocked by design

  • Create, update or close a case
  • Assign or reassign work
  • Act operationally in any workbench
Case lifecycle

Twelve states. One state machine. No shortcuts around it.

Every case moves through the same governed states, and each transition is validated server-side against both the current state and the caller’s role. Machine transitions and human transitions stay distinguishable forever.

Primary recovery path

01

PENDING_ALLOCATION

SYSTEM

Row created from an authenticated upstream service call.

02

ALLOCATED

SYSTEM

Assigned to an agency, awaiting first contact.

03

IN_PROGRESS

DCA_AGENT

Active collection under way.

04

CUSTOMER_CONTACTED

DCA_AGENT

Initial contact made with the customer.

05

PAYMENT_PROMISED

DCA_AGENT

Customer has committed to a payment.

06

FULL_RECOVERY

DCA_AGENT

Balance recovered in full.

07

CLOSED

TERMINAL

No transitions permitted out of this state.

Exception states

DISPUTED

from
IN_PROGRESS · CUSTOMER_CONTACTED
exits
IN_PROGRESS · LEGAL_ACTION · WRITTEN_OFF · CLOSED

ESCALATED

from
Any active state, or an SLA breach
exits
IN_PROGRESS · LEGAL_ACTION · WRITTEN_OFF

PARTIAL_RECOVERY

from
PAYMENT_PROMISED
exits
FULL_RECOVERY · PAYMENT_PROMISED · WRITTEN_OFF · CLOSED

LEGAL_ACTION

from
DISPUTED · ESCALATED
exits
FULL_RECOVERY · PARTIAL_RECOVERY · WRITTEN_OFF · CLOSED

WRITTEN_OFF

from
Any unrecoverable outcome
exits
CLOSED
SYSTEM transitionHuman transitionException / escalationTerminalAn invalid transition is rejected before it reaches the row.
Security & compliance

Built to be audited, not just to pass an audit.

The controls below are properties of the system rather than operating procedures. They hold whether or not anyone is watching the dashboard.

MFA on privileged roles

Multi-factor authentication is enforced for administrators, not offered as a setting they can decline.

Authorisation checked server-side

Thirty-six permissions are evaluated in the API layer, and sensitive routes re-check the role on top. A hidden button is a courtesy; the denial happens on the server.

Row-level security everywhere

Postgres policies scope reads and writes to the caller’s region, agency and role — even for direct queries.

Idempotent ingestion

A unique index on the upstream identifier means a replayed message can never become a second case.

Append-only audit log

Audit rows carry actor type and identity, and the creation timestamp is protected from modification.

Governance suite in CI

A suite of 109 security-focused tests covers RBAC, authentication, region isolation and the ingestion boundary on every change.

Architecture

Every layer inherits the same boundaries

  • Interface

    Next.js 14 · App Router · TypeScript

  • Design system

    Tailwind CSS · Radix primitives

  • State & data

    React Query · Zustand · realtime subscriptions

  • Authorisation

    Custom RBAC · 11 roles · 36 permissions

  • Data

    Supabase PostgreSQL · RLS · immutability triggers

  • Identity

    Supabase Auth · MFA for privileged roles

  • Intelligence

    Dedicated ML service · advisory scoring only

Bring the whole recovery estate under one control tower.

Sign in to your workbench. Every action you take from here is permission-checked, region-scoped and written to the audit trail.

Enter Control TowerAccess is provisioned by your administrator