Developers
Extend Core. Do not replace it.
Ciright Core is the engine. Ciright ADM is the experience. No significant table is added until Core, the owning application, and Subscription ID are identified.
Domains
cirightadm.com is the public site. app.cirightadm.com is the operating environment. admin.cirightadm.com presents Connect. API, developer, docs, support and status use their own hosts. Product areas prefer a path on the app host.
Core extension map
This is the implementation reference. Database and API cells say “Inspect Core” until engineering confirms the live object. A new table requires a written reason.
| ADM capability | Existing product | Existing object | Existing database | Existing API | System of record | Subscription ID | ESID required? | New UI? | New API? | New table? | New Core extension? | AI access? | Agent access? | On The Line event? | Keyra required? |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Identity and sign-in | Keyra | Keyra UID | Inspect Core before any schema | Existing Keyra authorization | Keyra, then Ciright Core | Required | No | ADM sign-in experience | No | No | No | Resolve identity before any request | Bound to the same identity | Login | Yes |
| World scope | Ciright Core | Subscription ID | Inspect Core before any schema | Existing subscription resolution | Ciright Core | Canonical | No | World switcher | No | No | No | World is part of context | World limits scope | World switch | Yes |
| Administration | Connect | Users, teams, roles, applications | Inspect Core before any schema | Existing Connect services | Connect | Required | Where an external system is linked | ADM-branded Connect | No second admin platform | No | Only if Connect lacks the object | Governed | No permission by default | Permission changes | Yes |
| People and companies | CRM | Contact and company | CRM database | CRM API | CRM | Required | When an external CRM is connected | Yes | Projection only | No | No | Summarize the relationship | Explicit grant | Record opened and changed | For high-risk actions |
| Opportunities | Pipeline | Opportunity | Pipeline database | Pipeline API | Pipeline | Required | When an external pipeline is connected | Yes | Projection only | No | No | What changed this week | Explicit grant | Stage and amount changes | For high-risk actions |
| Calendar | MyCalendar | Event | Calendar database or external calendar | Calendar API | MyCalendar or the connected calendar | Required | Yes for external calendars | Yes | No | No | No | Meeting brief | Explicit grant | Meeting started and summarized | No |
| Work | Works | Project and task | Works database | Works API | Works | Required | No | Yes | No | No | No | What is late | Explicit grant | Status changes | No |
| My Day | Projection across applications | None owned by ADM | None | Read authorized services | Each source application | Required | Inherited from the source | Yes | Read projection only | No | No | Morning brief | Status only | Viewed | No |
| History | On The Line | Activity event | On The Line | Existing history API | On The Line | Required | No | Yes | No separate audit system | No | No | Read authorized history | Actions are recorded | This is the history system | For sensitive events |
| External systems | Connected system | External object | External | Integration via ESID | The external system | Required above the ESID | Yes | Reference only | No canonical copy | No duplicate master | Only a Core link if none exists | Classified and permissioned | Explicit grant | Link and sync events | For privileged connections |