Skip to main content
Operations · partner / staff

🌉 Bridge

📖 Welcome & Onboard ↗ 🔗 SP folder share ↗
Probing Bridge…

What Bridge does

Per-client file sharing for Tax Compliance + BPS Accounting + BPS Payroll to receive monthly fiscal input from clients. Now Hub-native — 13 internal entities (9 CLA + 4 Family Office) and 223 active client companies served through one canonical surface keyed on CUI. (Note: automated ANAF SPV submission from Bridge is currently offline post-cutover — declarations are filed manually via the desktop ANAF tool; see the SPV tab.)

📖 Welcome & Onboard ↗ → Client onboarding view

Recent change · 24-May-2026

Cutover live · 2-Iun. Bridge is now live at /bridge/. Legacy system retired. Report issues via /feedback/. Hyper-care: 7 days.

Admin · Hub-native MVP · edge-to-edge layout · permanent right rail · doc preview · category stripes · is_internal split · 17 stale companies archived · 10 P1 audit fixes (FK validation · standardised Beta responses · env-driven contacts · GIN trigram). T-062 permissions · T-063 cert UI · T-064 alert subs LIVE. T-065 OCR · T-066 Sign · T-067 e-GOV Beta (gated on SME interviews + env flags).

Owners

BI & Automation · Bogdan Buzatu (TL) · Maria Clipa · Alina Artemenko — Hub-side integration + ongoing ownership. WRITES locked to BI team + Ionut (Rule #4).
Ionuț Zeche · CLA · partner escalation + product direction
Maria Boițan · RezolvIT · M365 / SharePoint grants (Sites.ReadWrite.All granted 25-Mai · Bridge ↔ SP live-sync unblocked)
Legacy VM-side OUT: Bogdan Coșa (RezolvIT) · Cosmin Stahie (consult). VM .68 retiring 31-Iul (T-075) · cutover live since 2-Iun.

This week · post-cutover hyper-care

  • Cutover live 2-Iun · DNS flipped · Hub-native single-surface operation
  • Fix-stream live 3-4 Iun · 8+ UI commits from Laura · Cristina · Mihaela · Irina escalation feedback (download branches · per-folder upload chip · per-row Delete + Move Hub-native · dead-VM removals)
  • SP Sites.ReadWrite.All grant LIVE (Maria Boițan @ RezolvIT · 25-Mai) · /api/sp-grant-verify?site=clients returns GRANT_FULL_READWRITE_CONFIRMED · blob Copy + bidirectional Bridge ↔ SharePoint sync unblocked
  • T-066 Sign-document · UI live · server-side signing still gated on RezolvIT eIDAS provisioning (same env vars as ANAF submit · Resend b7ca0298) · until then sign-declarații via Outlook to Ionut · unblocks Laura points #4 / #6 / #11 (multi-cert sign · cert-row sign buttons · ANAF declaration submit)
  • Send bug reports + file_id to bi-automation@cla.com.ro · same-day response

Post-cutover · 30-day plan

Hub-native single surface live. Path to steady-state:

  • 2-Iun (done): cutover · DNS flip · legacy bridge.cla.com.ro deprecated (CF 525)
  • 3-4 Iun (in-flight): hyper-care · ship feedback-driven UI fixes daily
  • By 18-Iun: 3 Beta endpoints flip OK once envs land (OCR · Sign · E-GOV)
  • 30-Iun: T-067 direct-ANAF path (RezolvIT replacement infra)
  • 31-Iul: T-075 VM .68 decommission · api.cla.com.ro retirement

System status

Probing…
Auto-refreshes every 60s · click the ↻ on any row to re-probe immediately · deep-link buttons take you to the relevant logs · Activity Log · Notion runbook · Vercel deploy status.

Integration probes click any row for full runbook · what 'broken' means · who owns the fix

Loading…

Data quality & access likely cross-company misfiles + blocked sign-in attempts · review, don't auto-fix

Loading…

Internal-13 pilot probe Admin only verifies all 13 internal entities (9 CLA + 4 Family Office) are pilot-ready for Wave 0/1 onboarding · loud-on-drift on weekly cron piggyback

Click to probe live · ~1s · admin-gated

Legacy bridge.cla.com.ro probes archived · cutover live since 2-Iun · CF 525 expected on this origin

If RED on any: RezolvIT (maria.boitan@rezolvit.ro · catalin@rezolvit.ro · suport@rezolvit.ro) owns the VM .68 host. Frontend 5xx = nginx down · CORS 4xx = config drift · End-to-end 404 = FastAPI not bound (the exact 4-May failure mode that took the legacy app down for 3 hours). Tag this URL in the email: https://bridge.cla.com.ro.

Recent failures (last 24h) 5xx + 4xx from hub_audit_log · most recent first · click row for full payload

Loading…

Common failure patterns · diagnostic shortcuts

Symptom Likely cause Where to look Fix · who owns
Fisa / Vector pull fails with "0 Unknown Error"cert missing on practice (no certificatepractice row OR no certificatepracticetype fallback)Admin → Certificates · search by company · check assignments. Also: scripts/audit-firmwide-certificatepractice-2026-05-23.mjs output (CSV in repo).Cristina + Raluca · add row to bridge_legacy.certificatepractice per scripts/_fix_pmg_certificatepractice_2026_05_23.mjs pattern. Or apply via T-069 CSV when Cristina returns it.
Hub-side mutation succeeds but no audit row in hub_audit_logschema-mismatch bug (the 2026-05-23 SHA 9bf9d8a regression)Activity Log tab · filter by user-email · check rows lining up with the action. Also: node scripts/audit-postcutover-write-consistency.mjs --since "DATE".Hub agent · all bridge-v2-* writes should route through safeHubAudit() (commit ae8a5c5). If new endpoint shipped without the helper · grep for inline INSERT INTO hub_audit_log and migrate.
Recipient never gets Bridge share emailResend dispatch cron not firing · OR recipient address bouncedActive Shares panel · find the token · check email_results array. Activity Log filter action=share_extern_create. HUB_NOTIFY_LIVE env on Vercel.BI · check cron history at /api/bridge-v2-cron-send-notifications · confirm HUB_NOTIFY_LIVE=true · re-send manually via brShareExternOne if needed.
File preview shows "Binary preview not available"Legacy backend blob proxy unreachable OR file_id unknownOpen /api/bridge-v2-file-content?file_id=NNN in browser tab. 404 = file gone from legacy · 502 = legacy unreachable · 503 = BRIDGE_LEGACY_ADMIN_USER/PASS env missing on Vercel.RezolvIT if legacy unreachable. BI if env vars missing. Hub agent if file_id query returns 404 unexpectedly (data drift).
User reports "I don't see client X"Bridge ACL not granting access · OR client archived · OR is_internal=trueRun node scripts/verify-bridge-acl-matches-legacy.mjs --include-admins. Check picker · toggle Internal tab + show-archived.BI · ACL gap: assign user to company via bridge_legacy.usercompany. Internal: confirm with Ionut if the client should be in Internal bucket. Archived: restore via direct UPDATE if intentional.
Permissions toggle doesn't stickisBIWriter gate rejected the call · OR Bridge legacy not picked up the changeBrowser console → Network tab → POST /api/bridge-v2-permissions response. 403 = caller not in BI_WRITERS_HARDCODED. Activity Log filter action='Update Permissions'.Hub agent · add caller to BI_WRITERS_HARDCODED in shared/bridge-acl.js if intentional. Confirm Bridge legacy reads the same bridge_legacy.permissions table (it does · single source of truth).

Deep links · monitoring + audit + escalation

Live status
Activity + audit
Cutover artifacts
  • Pre-cutover runbook (historical) · docs/runbooks/bridge-cutover-30jun.md (now archived · actual cutover executed 2-Jun with shifted timeline)
  • Strategy · docs/notion/bridge-phase4-cutover-runbook.md
  • T-069 cert audit · data/cert-audit-2026-05-23/firmwide-cert-audit.csv
  • CUI coverage audit · data/cui-audit-2026-05-24.csv
Escalation contacts
  • RezolvIT: maria.boitan@rezolvit.ro · catalin@rezolvit.ro · suport@rezolvit.ro (always 3)
  • BI: bi-automation@cla.com.ro (DL) · bogdan.buzatu / maria.clipa / alina.artemenko @cla.com.ro
  • Partners: partners@cla.com.ro (DL · includes Ionut)
  • Tax SME: laura.munteanu@cla.com.ro (compliance) · raluca.neamtu@cla.com.ro (practice TL)
  • Cert ops: office@cla.com.ro (Cristina Arhire)
View mode:
live · loading…
Click a client + practice below to land on the file view

Documents

📘 Ghid de navigare · Guide
checking your access…
— select a company to begin —
0 selected
Index Name Created Modified By Action
↑ Pick a company to start
company → practice → folder · files appear here once you reach a folder

👤 My Bridge work last 14 days · what files you touched + activity events · per-staff view

loading…

Files I touched

My activity events

👥 Client + Staff Onboarding / Offboarding guided workflows with preflight checks · 12-step plans per action

Each button opens a form modal · runs preflight checks against client and staff data · returns step-by-step workflow with owner + deadline per step. Built after Ana Tifigiu audit · scaled the lessons firm-wide. Generates a checklist only — no automatic write-back yet. Approved onboard/offboard actions are run by the BI team (see below).

🔒 Onboarding / offboarding actions are restricted to the BI team + Ionut (2026-05-23 lockdown). Email BI with what you need and they will run the checklist.

🔁 SharePoint sync · Import scan / Export to SP Bridge ↔ SharePoint · Sites.ReadWrite.All granted (live) · architectural discipline gate enforced on every write

Import scan = recursive folder inventory read-only · 4-level deep default. Export = write XLSX practice export back to SP at chosen path. Validation gate = check a filename against 8 hard-reject patterns BEFORE upload.

🗂️ Duplicate file scanner firm-wide · files · detects (N) suffix dups + pathological filenames + worst offenders

loading…

Top duplicate clusters (canonical names with most (N) variants)

⚠ Pathological filenames

By practice

By uploader (top 15)

By company (top 15)

🔐 ANAF SPV cert waterfall 8 certs sorted by expiry · operational dependency + backup plan + data integrity flags

loading…

📊 Firm-wide ANAF filings · churn radar last 30d daily volume · top filers · stale-clients alert · all 223 active clients in scope

loading…

Daily volume (last 30d)

Top 15 filers (last 90d)

⚠ Stale clients · churn radar (≥5 historic filings · 0 in last 60d)

🏛️ Practice dashboard pick a practice · see your world in one pane · 30-day window

🔍 Search files across all Bridge files min 2 chars · searches name + path · enriched with company + practice

Bridge live · client, staff, certificate and folder data are synced from the legacy system

Bridge is live. Client, staff, certificate and folder data are synced from the legacy system. Writes are controlled through approved action buttons (Upload · Edit · Delete) which mirror to SharePoint and the underlying record store.

Technical details — sourced from bridge_legacy schema (41 tables · 935 MB · 1:1 ingest from legacy 2026-05-21 16:30 RO) · cutover live 2-Iun-2026 · Hub canonical · legacy VM .68 decom 31-Iul-2026.

Clients
Staff (active)
ANAF Certs
Cert Alerts

Clients · 223 active click client name to see folders + recent ANAF filings · 126 archived live in Archive section · 349 total · canonical source = Hub

NameCUIContactANAF CertCert StatusCert Expiry
loading…

Staff · 463 active CLA users · pwd hashes NOT returned · synced from AD nightly 03:30 UTC

EmailNameActiveInternalAdmin
loading…

ANAF SPV Certificates only 8 certs across 223 active clients · cert reuse pattern

HolderSerialStatusExpiryActive Clients UsingLast ANAF refresh
loading…

👥 Users internal staff · client users · live AD sync · ⋮ row actions to update/archive/create · inactive users live in Archive

Loading…
Users Statistics
Loading…

Bridge clients v1: live from bridge_legacy · 1:1 ingest · scope toggle + per-practice filter

NameCUIPracticesUsersE-sign tokenSP folderStatusCert expiry
Clients Statistics
Loading…

Add / update client partner-level only

SPV Messages · per company RECIPISA · RASPUNS SOLICITARE · ANAF declaration receipts · live from anaf_messages cache

Pick a company to see its ANAF SPV messages.

SPV · ANAF gateway live · sourced from bridge_legacy.certificate + Latitude

Loading…

e-gov · Latitude integration live · /api/latitude-health

Loading…

SPV inbox · ANAF Lista Mesaje live · /api/anaf-messages

Loading…

Filing actions prepare / submit · partner-level

⚠ Change request protocol

View access is firm-wide — anyone with a CLA Hub login can read Users, Clients, Practices, Health, Manual, Q&A, Audit log.
Edit access is restricted to BI Team only. Operationally only Maria Clipa and Alina Artemenko hold the keys to mutate anything in Bridge — provisioning users, archiving clients, renaming practices, editing the manual, answering Q&A.
Any change must be requested in writing via the Hub Feedback Hub (/feedback/) or by emailing maria.clipa@cla.com.ro + alina.artemenko@cla.com.ro with bogdan.buzatu@cla.com.ro (BI TL) on CC. No verbal or chat-only requests — every mutation must leave a written trail.

Permission model

CapabilityHub levelNotes
Open Bridge (read + use)staff+Anyone with a CLA Hub login
View Users, Clients, Practices, Health, Manual, Q&A, Auditstaff+Read-only · firm-wide
Edit Users / Clients / Practices / Manual / Q&ABI Team · written requestOperational owners: Maria Clipa + Alina Artemenko. All mutations gated server-side. Submit request via /feedback/ or email both + CC Bogdan Buzatu (BI TL).
Architectural escalation / new featureBI TLBogdan Buzatu approves scope before Maria/Alina execute
Cloudflare DNS / cache purgeRezolvITCatalin / Maria · escalate via Suport RezolvIT
SSH VM .68 / nginx / DockerdecommissioningVM .68 retiring 31-Iul (T-075) · Bridge already runs on Hub (Vercel + Neon) since 2-Iun cutover
Backend Bridge codeBI & AutomationOwned by BI team (Bogdan Buzatu TL · Maria Clipa · Alina Artemenko) — Hub-side codebase, all writes go through architectural discipline gate

Hub access by role read-only mirror of /admin/access-matrix/

Bridge is reachable to anyone with a CLA Hub login (staff and above). Edits are restricted to the BI Team (Maria + Alina, with Bogdan as TL). To grant or revoke specific Hub access, go to /admin/access-matrix/.

Technical Manual

Loading…

Bridge v2 · Architecture

Loading…

🚦 Bridge Cutover Runbook

Loading…

Q&A · FAQ

Add / update Q&A entry partner-level only

🏛️ Practices all CLA practices · live stats · clients · internal users · client users

Loading…

🧹 Stale clients no upload activity in the last · grouped by practice

Loading…

Bridge probe history last 30 monitor probes · /api/bridge-monitor stores one row per probe in hub_audit_log

Looking for who-did-what-when on files? That is the Activity Log (right rail · 452K filterable rows from bridge_legacy.activitylog). This tab shows monitor probe history only.
WhenVerdictFrontendAPICORSE2EIssuesActor
Loading…

✍ Sign document legacy parity · BI-only writes · server-side cert sign

⚠ Signing is offline post-cutover. This standalone Sign tab is not wired (clicking Sign document returns 503), AND automated e-GOV/SPV submission is currently paused: the link from the legacy backend to the on-prem signing agent (192.168.1.69) was severed at the 2026-06-05 cutover and is being restored (RezolvIT + Bogdan). The legacy bridge.cla.com.ro/sign page is also dead (CF 525). Interim: file ANAF declarations manually with the desktop ANAF tool (sign with the physical token, bring the recipisă back into Bridge); to sign an arbitrary file, email it to ionut.zeche@cla.com.ro. Re-enables automatically once the signing-server link + certs are restored.

Two-step signing flow that mirrors the legacy bridge.cla.com.ro/sign page. Pick a token certificate, upload a file, the server signs it with the cert and returns the signed file. Writes locked to BI team + Ionut (per Rule #4 · feedback_bridge_writes_bi_only).

Step 1 · Select token certificate
Step 2 · Upload file
Pick a certificate + file to enable

🔐 Certificate inventory

All token certificates registered on Hub. Each row shows the registered name (ID) + holder + expiry. If your name is missing or stale, ping ionut.zeche@cla.com.ro.
Loading…
🛠 Build status (2026-06-07): UI live · cert dropdown + upload field wired. Signing mechanism is known: legacy POST /api/v1/integrations/sign/{cert_id} → certSIGN Java agent at 192.168.1.69:8001 — the same live proxy bridge-v2-file-send-egov already uses. Open item (T-066): wire this endpoint to that proxy via getLegacyServiceToken() (mirror file-send-egov) · then this tab signs in-place and the Beta banner comes down. The direct-eIDAS path stays as the post-31-Iul fallback (Phase 2).

📋 Reports legacy parity · 5 report types · CSV / XLSX export

Read-only exports for audit + management reporting. Mirrors the legacy bridge.cla.com.ro/reports dropdown.

✓ Build status (2026-05-25): All 5 report types wired live against bridge_legacy · Users · Activities · Practices · Clients · Activity Log. Each tile downloads a CSV scoped to admin firm-wide rollup. Default windows: Activities 30d · Activity Log 90d. JSON via ?format=json for ad-hoc programmatic use.