What Bridge does
Per-client file sharing for Tax Compliance + BPS Accounting + BPS Payroll to receive monthly fiscal input from clients. Now Hub-native — 13 internal entities (9 CLA + 4 Family Office) and 223 active client companies served through one canonical surface keyed on CUI. (Note: automated ANAF SPV submission from Bridge is currently offline post-cutover — declarations are filed manually via the desktop ANAF tool; see the SPV tab.)
Recent change · 24-May-2026
Cutover live · 2-Iun. Bridge is now live at /bridge/. Legacy system retired. Report issues via /feedback/. Hyper-care: 7 days. Admin
· Hub-native MVP · edge-to-edge layout · permanent right rail · doc preview · category stripes · is_internal split · 17 stale companies archived · 10 P1 audit fixes (FK validation · standardised Beta responses · env-driven contacts · GIN trigram). T-062 permissions · T-063 cert UI · T-064 alert subs LIVE. T-065 OCR · T-066 Sign · T-067 e-GOV Beta (gated on SME interviews + env flags).
Owners
Sites.ReadWrite.All granted 25-Mai · Bridge ↔ SP live-sync unblocked)This week · post-cutover hyper-care
- Cutover live 2-Iun · DNS flipped · Hub-native single-surface operation
- Fix-stream live 3-4 Iun · 8+ UI commits from Laura · Cristina · Mihaela · Irina escalation feedback (download branches · per-folder upload chip · per-row Delete + Move Hub-native · dead-VM removals)
- SP
Sites.ReadWrite.Allgrant LIVE (Maria Boițan @ RezolvIT · 25-Mai) ·/api/sp-grant-verify?site=clientsreturns GRANT_FULL_READWRITE_CONFIRMED · blob Copy + bidirectional Bridge ↔ SharePoint sync unblocked - T-066 Sign-document · UI live · server-side signing still gated on RezolvIT eIDAS provisioning (same env vars as ANAF submit · Resend b7ca0298) · until then sign-declarații via Outlook to Ionut · unblocks Laura points #4 / #6 / #11 (multi-cert sign · cert-row sign buttons · ANAF declaration submit)
- Send bug reports + file_id to
bi-automation@cla.com.ro· same-day response
Post-cutover · 30-day plan
Hub-native single surface live. Path to steady-state:
- 2-Iun (done): cutover · DNS flip · legacy bridge.cla.com.ro deprecated (CF 525)
- 3-4 Iun (in-flight): hyper-care · ship feedback-driven UI fixes daily
- By 18-Iun: 3 Beta endpoints flip OK once envs land (OCR · Sign · E-GOV)
- 30-Iun: T-067 direct-ANAF path (RezolvIT replacement infra)
- 31-Iul: T-075 VM .68 decommission · api.cla.com.ro retirement
System status
Integration probes
Data quality & access
Internal-13 pilot probe Admin only
Legacy bridge.cla.com.ro probes
https://bridge.cla.com.ro.
Recent failures (last 24h)
Common failure patterns · diagnostic shortcuts
| Symptom | Likely cause | Where to look | Fix · who owns |
|---|---|---|---|
| Fisa / Vector pull fails with "0 Unknown Error" | cert missing on practice (no certificatepractice row OR no certificatepracticetype fallback) | Admin → Certificates · search by company · check assignments. Also: scripts/audit-firmwide-certificatepractice-2026-05-23.mjs output (CSV in repo). | Cristina + Raluca · add row to bridge_legacy.certificatepractice per scripts/_fix_pmg_certificatepractice_2026_05_23.mjs pattern. Or apply via T-069 CSV when Cristina returns it. |
| Hub-side mutation succeeds but no audit row in hub_audit_log | schema-mismatch bug (the 2026-05-23 SHA 9bf9d8a regression) | Activity Log tab · filter by user-email · check rows lining up with the action. Also: node scripts/audit-postcutover-write-consistency.mjs --since "DATE". | Hub agent · all bridge-v2-* writes should route through safeHubAudit() (commit ae8a5c5). If new endpoint shipped without the helper · grep for inline INSERT INTO hub_audit_log and migrate. |
| Recipient never gets Bridge share email | Resend dispatch cron not firing · OR recipient address bounced | Active Shares panel · find the token · check email_results array. Activity Log filter action=share_extern_create. HUB_NOTIFY_LIVE env on Vercel. | BI · check cron history at /api/bridge-v2-cron-send-notifications · confirm HUB_NOTIFY_LIVE=true · re-send manually via brShareExternOne if needed. |
| File preview shows "Binary preview not available" | Legacy backend blob proxy unreachable OR file_id unknown | Open /api/bridge-v2-file-content?file_id=NNN in browser tab. 404 = file gone from legacy · 502 = legacy unreachable · 503 = BRIDGE_LEGACY_ADMIN_USER/PASS env missing on Vercel. | RezolvIT if legacy unreachable. BI if env vars missing. Hub agent if file_id query returns 404 unexpectedly (data drift). |
| User reports "I don't see client X" | Bridge ACL not granting access · OR client archived · OR is_internal=true | Run node scripts/verify-bridge-acl-matches-legacy.mjs --include-admins. Check picker · toggle Internal tab + show-archived. | BI · ACL gap: assign user to company via bridge_legacy.usercompany. Internal: confirm with Ionut if the client should be in Internal bucket. Archived: restore via direct UPDATE if intentional. |
| Permissions toggle doesn't stick | isBIWriter gate rejected the call · OR Bridge legacy not picked up the change | Browser console → Network tab → POST /api/bridge-v2-permissions response. 403 = caller not in BI_WRITERS_HARDCODED. Activity Log filter action='Update Permissions'. | Hub agent · add caller to BI_WRITERS_HARDCODED in shared/bridge-acl.js if intentional. Confirm Bridge legacy reads the same bridge_legacy.permissions table (it does · single source of truth). |
Deep links · monitoring + audit + escalation
- /api/bridge-v2-ecosystem-health · JSON of all integrations
- /api/bridge-health · legacy probes
- /api/health · Vercel liveness
- Activity Log · 452K rows · filterable
- Admin modal · Permissions · Certs · Alerts
- GitHub Actions · Notion publish + CI
- Pre-cutover runbook (historical) ·
docs/runbooks/bridge-cutover-30jun.md(now archived · actual cutover executed 2-Jun with shifted timeline) - Strategy ·
docs/notion/bridge-phase4-cutover-runbook.md - T-069 cert audit ·
data/cert-audit-2026-05-23/firmwide-cert-audit.csv - CUI coverage audit ·
data/cui-audit-2026-05-24.csv
- RezolvIT: maria.boitan@rezolvit.ro · catalin@rezolvit.ro · suport@rezolvit.ro (always 3)
- BI: bi-automation@cla.com.ro (DL) · bogdan.buzatu / maria.clipa / alina.artemenko @cla.com.ro
- Partners: partners@cla.com.ro (DL · includes Ionut)
- Tax SME: laura.munteanu@cla.com.ro (compliance) · raluca.neamtu@cla.com.ro (practice TL)
- Cert ops: office@cla.com.ro (Cristina Arhire)
Documents
| Index | Name | Created | Modified | By | Action | |
|---|---|---|---|---|---|---|
↑ Pick a company to start company → practice → folder · files appear here once you reach a folder | ||||||
▾ 👤 My Bridge work
Files I touched
My activity events
👥 Client + Staff Onboarding / Offboarding
Each button opens a form modal · runs preflight checks against client and staff data · returns step-by-step workflow with owner + deadline per step. Built after Ana Tifigiu audit · scaled the lessons firm-wide. Generates a checklist only — no automatic write-back yet. Approved onboard/offboard actions are run by the BI team (see below).
🔁 SharePoint sync · Import scan / Export to SP
Import scan = recursive folder inventory read-only · 4-level deep default. Export = write XLSX practice export back to SP at chosen path. Validation gate = check a filename against 8 hard-reject patterns BEFORE upload.
🗂️ Duplicate file scanner
Top duplicate clusters (canonical names with most (N) variants)
⚠ Pathological filenames
By practice
By uploader (top 15)
By company (top 15)
🔐 ANAF SPV cert waterfall
📊 Firm-wide ANAF filings · churn radar
Daily volume (last 30d)
Top 15 filers (last 90d)
⚠ Stale clients · churn radar (≥5 historic filings · 0 in last 60d)
🏛️ Practice dashboard
🔍 Search files across all — Bridge files
Bridge
Bridge is live. Client, staff, certificate and folder data are synced from the legacy system. Writes are controlled through approved action buttons (Upload · Edit · Delete) which mirror to SharePoint and the underlying record store. Technical details
— sourced from bridge_legacy schema (41 tables · 935 MB · 1:1 ingest from legacy 2026-05-21 16:30 RO) · cutover live 2-Iun-2026 · Hub canonical · legacy VM .68 decom 31-Iul-2026.
Clients · 223 active
| Name | CUI | Contact | ANAF Cert | Cert Status | Cert Expiry |
|---|---|---|---|---|---|
| loading… | |||||
Staff · 463 active
| Name | Active | Internal | Admin | |
|---|---|---|---|---|
| loading… | ||||
ANAF SPV Certificates
| Holder | Serial | Status | Expiry | Active Clients Using | Last ANAF refresh |
|---|---|---|---|---|---|
| loading… | |||||
👥 Users
Bridge clients
| Name | CUI | Practices | Users | E-sign token | SP folder | Status | Cert expiry |
|---|
Add / update client
SPV Messages · per company
SPV · ANAF gateway
e-gov · Latitude integration
SPV inbox · ANAF Lista Mesaje
Filing actions
⚠ Change request protocol
View access is firm-wide — anyone with a CLA Hub login can read Users, Clients, Practices, Health, Manual, Q&A, Audit log.
Edit access is restricted to BI Team only. Operationally only Maria Clipa and Alina Artemenko hold the keys to mutate anything in Bridge — provisioning users, archiving clients, renaming practices, editing the manual, answering Q&A.
Any change must be requested in writing via the Hub Feedback Hub (/feedback/) or by emailing maria.clipa@cla.com.ro + alina.artemenko@cla.com.ro with bogdan.buzatu@cla.com.ro (BI TL) on CC. No verbal or chat-only requests — every mutation must leave a written trail.
Permission model
| Capability | Hub level | Notes |
|---|---|---|
| Open Bridge (read + use) | staff+ | Anyone with a CLA Hub login |
| View Users, Clients, Practices, Health, Manual, Q&A, Audit | staff+ | Read-only · firm-wide |
| Edit Users / Clients / Practices / Manual / Q&A | BI Team · written request | Operational owners: Maria Clipa + Alina Artemenko. All mutations gated server-side. Submit request via /feedback/ or email both + CC Bogdan Buzatu (BI TL). |
| Architectural escalation / new feature | BI TL | Bogdan Buzatu approves scope before Maria/Alina execute |
| Cloudflare DNS / cache purge | RezolvIT | Catalin / Maria · escalate via Suport RezolvIT |
| SSH VM .68 / nginx / Docker | decommissioning | VM .68 retiring 31-Iul (T-075) · Bridge already runs on Hub (Vercel + Neon) since 2-Iun cutover |
| Backend Bridge code | BI & Automation | Owned by BI team (Bogdan Buzatu TL · Maria Clipa · Alina Artemenko) — Hub-side codebase, all writes go through architectural discipline gate |
Hub access by role
Bridge is reachable to anyone with a CLA Hub login (staff and above). Edits are restricted to the BI Team (Maria + Alina, with Bogdan as TL). To grant or revoke specific Hub access, go to /admin/access-matrix/.
Technical Manual
Bridge v2 · Architecture
🚦 Bridge Cutover Runbook
Q&A · FAQ
Add / update Q&A entry
🏛️ Practices
🧹 Stale clients
Bridge probe history
bridge_legacy.activitylog). This tab shows monitor probe history only.
| When | Verdict | Frontend | API | CORS | E2E | Issues | Actor |
|---|---|---|---|---|---|---|---|
| Loading… | |||||||
✍ Sign document
192.168.1.69) was severed at the 2026-06-05 cutover and is being restored (RezolvIT + Bogdan). The legacy bridge.cla.com.ro/sign page is also dead (CF 525). Interim: file ANAF declarations manually with the desktop ANAF tool (sign with the physical token, bring the recipisă back into Bridge); to sign an arbitrary file, email it to ionut.zeche@cla.com.ro. Re-enables automatically once the signing-server link + certs are restored.
Two-step signing flow that mirrors the legacy bridge.cla.com.ro/sign page. Pick a token certificate, upload a file, the server signs it with the cert and returns the signed file. Writes locked to BI team + Ionut (per Rule #4 · feedback_bridge_writes_bi_only).
🔐 Certificate inventory
POST /api/v1/integrations/sign/{cert_id} → certSIGN Java agent at 192.168.1.69:8001 — the same live proxy bridge-v2-file-send-egov already uses. Open item (T-066): wire this endpoint to that proxy via getLegacyServiceToken() (mirror file-send-egov) · then this tab signs in-place and the Beta banner comes down. The direct-eIDAS path stays as the post-31-Iul fallback (Phase 2).
📋 Reports
Read-only exports for audit + management reporting. Mirrors the legacy bridge.cla.com.ro/reports dropdown.