Shared workspace — synthetic state study
One account, explicit permissions.
The common Capricorncorp workspace lets a customer move between products with one login — but a valid session never grants access to every business or product. Switch the four states below to see the exact behaviour each must prove before any live integration is claimed.
Inbox Sample data
Keyboard note: in the real product, claiming a conversation is one keypress with collision protection — two agents can never both own a send.
You are signed out
On the live workspace this is the common Capricorncorp login — the same account used for sms-ocean. Deep links return you here first, then back to your intended screen after authentication.
No real authentication exists in this preview. Nothing here proves SSO works — that requires the separately verified identity contract.
No access to Sample Business B
Switch denied. Your session is valid, but membership is granted per business by an administrator. A shared login never implies access to every organization.
Protected views above remain hidden — the inbox is not merely greyed out.
Activate ConvoTide for Sample Business A
You share an account with sms-ocean — activation adds this product for your business, not a new login. WhatsApp-only businesses onboard here without any SMS purchase or DLT setup.
- Your numbers, routes and billing stay untouched
- Contact linking happens later, only with explicit consent
- Billing is separate per product — always
Compatibility reference: the existing authenticated SMS application keeps its own theme (its source calls it “Midnight Terminal”). This study deliberately does not reproduce or modify it — production shell integration is a separately scoped task against a verified contract.
What each state must prove before it ships
Signed out
Deep links survive authentication; expired/revoked sessions land here, never inside protected data; logout works from both products.
Permitted
Navigation shows only authorized, actually available features; business context is explicit in every screen.
Denied
Organization switching is membership-gated at the API, not just hidden in UI. This preview only illustrates the behaviour.
Unactivated
Products appear as activations, not walls of irrelevant screens. No duplicate identity is ever created.
Content reviewed October 2026 · owner: Zcode (implementation) · independent factual review: Codex QC, pending.