Deterministic allocation
Cases route to an agency and an agent by capacity, specialisation and performance history — the same inputs always produce the same decision, and every decision is logged.
The FedEx DCA Control Tower governs collection cases across every agency, region and role — with machine-led intake, an immutable audit trail, and boundaries the database itself enforces.
Enforced intake path
SYSTEM ingestion
X-Service-Auth verified
actor_type=SYSTEMIdempotency check
external_case_id unique
UNIQUE indexRegion resolution
Boundary locked at write
region_id IMMUTABLEDCA + agent allocation
Capacity · specialization
no human overrideSLA bind
Breach monitor armed
auto-escalationAudit trail
append-only96.4%
SLA on track
12
Breaches open
1,284
Queue depth
Illustrative view of the ingestion pipeline. Sample data.
9 active · 2 legacy aliases
Checked server-side
Cases · users · regions
RBAC · auth · ingestion
Design scale target
Most platforms describe their guardrails in a policy document. The Control Tower encodes them in Postgres: intake is machine-led, governance columns are immutable at the row level, and every mutation writes an actor-identified audit record.
Cases enter through an authenticated upstream service token, with schema validation, idempotency and region resolution all running before a row exists. Exactly one human role — FEDEX_ADMIN — may open a case by exception, and only with written justification recorded against it. Seniority buys nothing here: SUPER_ADMIN, every manager and every collection agent are refused outright.
Database triggers reject any update to the fields that define jurisdiction, identity and provenance.
region_idJurisdiction cannot be moved after write
external_case_idUpstream identity is permanent and unique
source_systemProvenance survives every downstream edit
actor_typeWho acted can never be rewritten
Row-level security policies scope every query to the caller's region, agency and role. An agent sees assigned cases; a DCA admin sees their agency; nobody sees across a boundary they do not own.
Upstream billing systems, RPA bots and legacy platforms all enter through the same authenticated endpoint. The only alternative is a FEDEX_ADMIN exception that demands a written justification and writes its own audit record — there is no third path and no silent bypass.
POST /api/v1/cases/system-createX-Service-Auth: Bearer ••••••••••••Content-Type: application/json { "case_type": "INVOICE", "source_system": "ERP_BILLING", "source_reference_id": "FX-4471902", "region": "EMEA", "currency": "EUR", "principal_amount": 17250.00, "tax_amount": 1170.00, "total_due": 18420.00, "customer_id": "ACC-88213", "customer_name": "Northwind Logistics BV"}201 Created{ "success": true, "data": { "case_id": "8f2c…", "case_number": "CASE-2026-004471902", "sla_id": "b1e7…", "ai_score": { "risk_level": "MEDIUM", "priority_score": 68 } }}Requests without a valid service credential are rejected, and an impersonation attempt is written to the security log before the 403 is returned. The exception endpoint refuses SYSTEM actors just as firmly.
The upstream reference becomes a unique key on the row. Retry the same message as often as your queue needs to — the repeat is refused as a duplicate rather than becoming a second case.
Schema, currency, amounts and region resolve before anything is persisted, so a malformed message never becomes a partially-governed case.
Automation is only safe when the boundaries underneath it hold. Each capability runs inside the same permission, region and audit model.
Cases route to an agency and an agent by capacity, specialisation and performance history — the same inputs always produce the same decision, and every decision is logged.
Targets bind at intake. Breach detection runs continuously and escalates on its own, so a missed clock is an event in the system rather than a discovery in a meeting.
A dedicated ML service predicts recovery difficulty and suggests priority. Scores inform the queue; they never silently reassign work or override a governed rule.
Every mutation writes actor type, actor identity, action, resource and timestamp to an append-only log — the evidence an auditor asks for, already assembled.
Case status, assignment changes and breach alerts propagate live through Supabase subscriptions, so every workbench shows the same truth at the same moment.
Recovery trends, cohort analysis and agency scorecards, with exportable reports scoped to whatever region and role the requester is permitted to see.
Not one dashboard with features greyed out — separate workbenches, each scoped to what that role is permitted to see and do. What is blocked is blocked in the API, not merely hidden in the UI.
The highest authority on the platform, and deliberately the least operational. It shapes the rules everyone else works inside — and cannot touch a single case.
128
Agencies
14
Regions
0
Case writes
Permitted
Blocked by design
Every case moves through the same governed states, and each transition is validated server-side against both the current state and the caller’s role. Machine transitions and human transitions stay distinguishable forever.
Primary recovery path
PENDING_ALLOCATION
SYSTEMRow created from an authenticated upstream service call.
ALLOCATED
SYSTEMAssigned to an agency, awaiting first contact.
IN_PROGRESS
DCA_AGENTActive collection under way.
CUSTOMER_CONTACTED
DCA_AGENTInitial contact made with the customer.
PAYMENT_PROMISED
DCA_AGENTCustomer has committed to a payment.
FULL_RECOVERY
DCA_AGENTBalance recovered in full.
CLOSED
TERMINALNo transitions permitted out of this state.
Exception states
DISPUTED
ESCALATED
PARTIAL_RECOVERY
LEGAL_ACTION
WRITTEN_OFF
The controls below are properties of the system rather than operating procedures. They hold whether or not anyone is watching the dashboard.
Multi-factor authentication is enforced for administrators, not offered as a setting they can decline.
Thirty-six permissions are evaluated in the API layer, and sensitive routes re-check the role on top. A hidden button is a courtesy; the denial happens on the server.
Postgres policies scope reads and writes to the caller’s region, agency and role — even for direct queries.
A unique index on the upstream identifier means a replayed message can never become a second case.
Audit rows carry actor type and identity, and the creation timestamp is protected from modification.
A suite of 109 security-focused tests covers RBAC, authentication, region isolation and the ingestion boundary on every change.
Every layer inherits the same boundaries
Interface
Next.js 14 · App Router · TypeScript
Design system
Tailwind CSS · Radix primitives
State & data
React Query · Zustand · realtime subscriptions
Authorisation
Custom RBAC · 11 roles · 36 permissions
Data
Supabase PostgreSQL · RLS · immutability triggers
Identity
Supabase Auth · MFA for privileged roles
Intelligence
Dedicated ML service · advisory scoring only
Sign in to your workbench. Every action you take from here is permission-checked, region-scoped and written to the audit trail.