Platform Overview

Architecture overview of After Action — three portals, five user roles, Supabase auth, and the engine modules that power readiness scoring and deliverable generation.

After Action is built on Next.js 14 with the App Router, backed by Supabase for authentication and Postgres with Row Level Security on every table. The platform is organized into three distinct portals.

Three Portals

Ops Portal (/app/ops)

The internal command center for facilitators and staff. Includes engagement management, exercise builder, facilitator control room, AAR editor, deliverable generation, pipeline kanban, lead management, and all scoring dashboards.

Client Portal (/app/client)

The external-facing portal for corporate security teams. Provides read-only access to their engagements, exercises, readiness scores, gap tracker, deliverables, and compliance evidence packs. Clients can also run self-service exercises with AI facilitator guidance.

Carrier Portal (/app/carrier)

A dedicated view for insurance carrier partners. Displays client readiness posture, insurance certificates with grades A through F, and risk reduction estimates that support underwriting decisions.

User Roles

| Role | Portal Access | Capabilities | |---|---|---| | owner | Ops | Full access including org management and billing | | admin | Ops | Full operational access, cannot delete the organization | | ops | Ops | Read/write on engagements, exercises, and reports | | client | Client | Read-only portal for their organization's data | | carrier | Carrier | Insurance carrier readiness view |

Internal roles (owner, admin, ops) can also access the Client Portal in preview mode to see exactly what the client sees.

Authentication

Authentication is handled by Supabase Auth with support for magic link and email/password flows. Route protection is enforced at the middleware layer — individual page components never contain auth logic.

Engine Modules

The platform's analytical power comes from pure-function engine modules with no database dependencies:

  • AI Facilitator — Rule-based coaching aligned to NIST 800-61 phases, zero LLM dependency
  • Readiness Scoring — 8-dimension weighted scoring with dynamic industry benchmarks
  • Deliverables — Generates IR playbooks, triage checklists, crisis comms plans, RCA reports, and gap remediation docs
  • Decision Analytics — Participant leadership profiles, decision quality metrics, confidence trends
  • Compliance Frameworks — Maps gaps to SOC 2, NIST CSF, ISO 27001, HIPAA, PCI-DSS, and CIS Controls
  • Threat Intelligence — MITRE ATT&CK and CISA KEV feed ingestion filtered by industry

Database

The schema spans 42 tables organized across core entities, exercise system, templates, scoring, business operations, and threat intelligence. All tables enforce Row Level Security.