My Projects
No projects yet
Create your first project to get started
Project & phase timeline. Each bar wears its project’s colour and fades once it has ended; the chip beside the name is coloured by time left. The filled share is what has already elapsed, the knob is today, and a red outline flags a phase that ended but is still marked active. Click a row to unfold its phases.
No projects with phase data
QA Check
Quality score across all projects. Worst first. Click a project or PM to open it.
| Project | Client | PM | Status | Score | Issues | Completion | Last update |
|---|
No projects match
Post-completion checks across projects — one per completed contract — and the notes tagged AAR in any project. Click a row to open the project's Closing tab.
Notes by tag
Resource Allocation
Time Tracking
Select a person to review their calendar.
Pick a team member on the left to see their week calendar.
Payment Validation
Validate the payment requests submitted by consultants for your projects and budget codes. Approving here does not pay the invoice — HR finalises payment.
Servers and IT services
Flat registry of deployments per project (env, url, host, port, git). Source of truth is the maintainer's Excel — re-import to refresh.
| Project | Code | Env | Component | URL | Server | Port | Git | Comment | Actions |
|---|
No servers found.
Try clearing filters, importing the Excel file, or adding one manually.
Income
-
-
-
Income
Revenue by Client
| Project | Client | Phase | Spent | Contract | Consumed |
|---|
| Project | Client | Total Amount | Client Status | Contract Status | Bonus % | Contributors | Bonus Amount | |
|---|---|---|---|---|---|---|---|---|
| Total | ||||||||
Management Staff Bonus
| Role | Name | Condition (M-1) | Value (M-1) | Status | Bonus |
|---|---|---|---|---|---|
| Total Management Bonus | |||||
Recap per Person
| Name | Contract Type | Total Bonus | Action |
|---|
| Date | Bank Account | Third | Category | Wording | Amount | |
|---|---|---|---|---|---|---|
| Total | ||||||
| Category | Jan | Feb | Mar | Apr | May | Jun | Jul | Aug | Sep | Oct | Nov | Dec | Total |
|---|
Clients
No clients yet
Add your first client to get started
Team Members
Manage your global team directory. Members can then be assigned to projects with specific roles.
No team members yet
Projects
No projects for this client
Files
Dashboard
Contracts running
Every active contract, the soonest to end first.
On assignment
Each consultant's current Task Order, the soonest to end first.
Résumé des paiements
Par compte bancaire, toutes entités confondues
Salaires
Contrats français et espagnols
| Nom | Montant | Statut | Actions | ||
|---|---|---|---|---|---|
| Total | |||||
Payment requests
Consultants and freelancers
| Consultant | Amount | Status | Actions | ||
|---|---|---|---|---|---|
| Total | |||||
All reports
New Expense Report
File a report on a team member's behalf. It is saved as a draft under their name (they see it in their portal too) and enters the review queue when you submit it. Receipts are optional here: attach them if you have them.
Expense lines
Amounts include VAT| Date | Type | Description | VAT | Unit TTC | Qty | Total | Receipt |
|---|
Notifications
Level determination
Compose a person out of the parameters below and watch the target salary move, or enter a salary you already have and read back which levels produce it.
Pay Parameters
Salary grid parameters used to calculate target annual salary. Formula: (Base × Experience + Seniority + Responsibility) × Setup × Workload
Budget Codes
Settings
Database Backup & Restore
Download a backup of the database or restore from a previous backup file.
Backup
Download a snapshot of the current database. Use this to transfer data between environments or as a safety backup.
Restore
Upload a .db backup file to replace the current database. A safety backup is created automatically before restoring.
Drag & drop a .db file here, or click to browse
Hourly snapshots (local)
Every hour at :30 when the database changed — the newest 48 are kept, incident / pre-revert copies 14 days. The safety net between the S3 backups.
| Snapshot | Taken | Reason | Size |
|---|
No local snapshot yet — the first one is taken at the next half hour.
Database files set aside on the server
A startup check that took the database for corrupted moved it aside, or a restore kept the previous file as portal.db.bak. Adopt the one whose counts match the real data, then Restore it from the list above. Once the live database holds the real data, Delete the files left here: nothing removes them automatically.
| File | Modified | Size | Contents |
|---|
Scheduled Backups (S3)
Daily at 2:00 AM Paris time — retained for 60 days
| File | Date | Size |
|---|
No backups found in S3
Loading backups...
Object Storage Self-Check
For each logical bucket (business, hr, recruitment, backups, drive): writes a throwaway object, reads it back, fetches a presigned link from the server, lists and deletes it — proves bucket, credentials, region and endpoint
Access clean-up
Revokes the MCP keys and connector tokens of everyone who may not use the MCP (roster members, the consultant role, deactivated accounts), ends the portal sessions of roster-only people and cancels their unused roster invite links. Safe to run again.
Restore Database
You are about to replace the current database with:
This action will overwrite all current data. A backup of the current database will be saved automatically before restoring.
Show the platform to clients on a fully anonymized copy of the real data. Demo mode is scoped to your own session only — while it's on, you see a separate demo.db clone with fake names, emails and contact details, and every other user keeps working on live data. Your real database is never modified.
Demo mode is …
Loading status…
Demo data
Rebuild the demo database from a fresh copy of your real data: anonymize it, then seed synthetic demo activity (logins, HR alerts, payment histories, attendance). The rebuild happens on a temporary file — anyone browsing the demo keeps seeing the previous clone until the new one is swapped in. Run this whenever your real data has changed and you want the demo to catch up.
Good to know
- While demo mode is ON for you, your session shows fake data and your outgoing email notifications are suppressed. Other users are unaffected and keep seeing live data.
- Your real database is never touched — turn demo mode OFF to return to live data instantly. It only ever affects your own session.
- Document downloads (CVs, contracts, signatures) are intentionally blank in the demo.
- Names, emails, phones, IBANs, client contacts, proposal titles, server URLs and roster CVs are all anonymized; audit logs, HR alerts and payment histories are refilled with synthetic demo activity.
- Recruitment, the activity log, second-factor secrets and Cmd+Z history are not carried into the demo. Actions that reach outside the portal — inviting someone, service accounts, bonus emails, invoice requests — are refused while demo mode is on.
- If a demo session ever looks stuck, use Force demo OFF for all viewers below the toggle.
Who can sign in where: the consultant portal, the dashboard and the MCP connector, with each person's second factor. Click a person to switch an access on or off, send an invite or change their role. No HR record is shown on this page.
| Person | Role | Consultant portal | Dashboard | MCP | Second factor |
|---|
Nobody matches these filters
Who signed in, and who did what — on the dashboard, the consultant portal and over MCP.
| Date | User | IP Address | Location |
|---|
No login logs yet
| Date | Actor | Action | Entity | Outcome | IP |
|---|
No activity recorded yet
Every write on /api/* plus backup and export downloads. Bodies are sanitised (passwords, tokens, bank details and signatures are redacted) and dropped after 90 days; rows are kept 365 days. Sign-ins are in the Logins tab; MCP reads stay in Settings › MCP Keys & Bots › Recent requests.
Archived logs
Old log rows are moved out of the database into text files in the backups bucket, every night.
Configure accountant email addresses for notifications. Separate multiple addresses with ;
Receives the "contract completed" and "project closed" notices with the project manager. A role, not a name: change it here when the role changes hands.
Offered on each closing checklist and added to the client follow-up email. Leave empty to keep the survey item a manual tick.
Generate test access links to preview the different portals. Links expire after 7 days.
Loading...
Bot guard
Every write by a service account or over MCP goes through the guard: the pause switch below stops all of them at once (reads keep working); each credential is read-only until writes are granted and can be limited to areas and to a daily write budget; sliding-window rate limits answer 429, and the circuit breaker pauses the credential, takes a database snapshot and emails every super-admin. Anomalies (new data area, money/status data, refusal spikes) are emailed too; off-hours writes are only logged. Every bot write keeps a before/after copy of the row, so an actor's writes can be reverted without a full restore.
Loading...
Service accounts (bot logins)
Email/password logins for automation browsers that cannot complete Google sign-in (e.g. an LLM agent). Each bot gets a generated secret shown only once, a dashboard role that is never super-admin, no second factor, and a 30-day secret lifetime (the nightly sweep disables lapsed accounts). Bots cannot delete anything, invite people, change roles, or touch Settings — see the deny list in app.py. A new bot is read-only until a super-admin grants writes (Permissions), optionally limited to areas and a daily budget. Every account created or rotated is emailed to all super-admins.
Loading...
MCP API Keys
Per-user bearer tokens for the Model Context Protocol server. Keys are hashed at rest; the plaintext token is shown only once at creation. Every key is valid for 30 days (owners are emailed 5 days before, the nightly sweep revokes lapsed keys), each request carries a purpose, and every key issued or rotated is emailed to all super-admins. A key is read-only unless writes were asked for; deletes over MCP and area scopes are set per key (Permissions).
Loading...
Recent requests
Click Refresh to load.
MCP actions & roles
Every tool the MCP server offers and which portal roles can call it. The table is read from the code on each server start (services/mcp_access_map.py), so it follows what the server enforces: the consultant allowlist, the super-admin-only HR file, and the role checks inside each tool. On top of the role, a key's own permissions apply: a read-only key only gets Read tools, deletes need the key's delete permission, and area scopes narrow the list further.
Loading...
Every email and SMS the system can send: when it goes out, who receives it, and what it looks like. Pick an email to pause it, switch recipient groups off or add people who should get a copy. Required (sign-in and security) emails always reach their recipients.
Loading...
Loading...
SMS / One-time code test
Checking SMS provider...
Send a real one-time code to your phone and enter it below to check SMS delivery end-to-end (same pipeline as signature codes and portal login 2FA).
Architecture
Where data is stored and how the system is structured.
Server (Docker)
One Flask application served by Gunicorn in a Docker container: 2 workers × 8 threads, 120-second request limit, host port 8003.
What runs there:
- The database — one SQLite file,
data/portal.db(WAL mode), on theportal-dataDocker volume - The scheduler — held by one worker: backups and snapshots, calendar sync, reminders and digests, the nightly clean-ups
- Local snapshots of the database in
data/snapshots/(same volume)
Deployment: a push to main runs the Deploy GitHub Action, which rebuilds the image on the server and restarts the container. Schema changes are applied at start-up.
Database (SQLite)
All structured data lives in the one file: projects, clients, invoices, people and contracts, HR, recruitment, proposals, tender radar, CRM, marketing, calendar, skills, plus the logs and sign-in records.
- Nested data (phases, deliverables, line items…) is stored as JSON columns
- The Schema page lists every table live, with rows and size
- Demo Mode reads a separate, anonymised copy (
data/demo.db); the real file is never modified by it - Identity checks (who you are, your role, second factor, IT support) always read the real file
Object storage (files)
Files are kept in S3-compatible object storage on Scaleway (Paris, fr-par), in five buckets. Each file goes to a bucket by the first part of its path:
The five buckets:
- Business
ra-portal-business— client and project records:clients/contracts/invoices/projects/portfolio/company/portal/openings/radar/skills/marketing/ - Drive
ra-portal-drive— the Drive's Team drive and every My Drive:drive/. Never mixed with the business records. - HR
ra-portal-hr— personal data:consultants/roster-profiles/hr/team/expense-reports/, and the Drive's HR space underhr/drive/ - Recruitment
ra-portal-recruitment—applications/(CVs, videos). Every file is deleted one year after it was stored. - Backups
ra-portal-backups—backups/: the database copies and the log archives (backups/logs/)
When a file is deleted or replaced:
- Business, Drive and HR keep the previous version for 30 days (bucket versioning), then Scaleway removes it for good. Meanwhile it can be restored from the Scaleway console, by whoever holds the Scaleway account.
- Recruitment and Backups keep no previous version, on purpose: their expiry rules must really delete.
Business and Drive are in one Scaleway project, the other three in a restricted one with its own key. Bucket names and keys are in the server configuration (STORAGE_<BUCKET>_*); Admin › Database › Self-Check tests the five of them. The former AWS bucket is only read as a fallback for a file not found on Scaleway (never for Drive files), until it is decommissioned.
Sign-in
- Dashboard — Firebase Auth: Google sign-in for the company domains, or email + password for people outside them. Access is the person's role (super-admin, admin, HR, PM, BizDev) and can be switched off per person.
- Second factor — Google 2-Step for Google accounts; a passkey (or, by exception, a code) for password accounts, remembered per browser.
- Consultant portals — email + password set from an invitation link, or a magic link; a code by email or SMS, or a passkey, as second factor.
- Client portal — magic link sent to an authorised email, per project.
- Accountant portal — a signed read-only link valid 90 days.
- AI assistants (MCP) — OAuth through the dashboard sign-in, or a personal key valid 30 days; bots use service accounts.
Firebase accounts live at Google, not in the database backup. Sessions, keys, passkeys and trusted browsers are in the database.
External services
- AWS SES — every email the portal sends
- Sweego (Twilio as a second provider) — SMS codes
- Anthropic (Claude) — document extraction, Arturo, candidate and proposal assistance
- Mistral and AWS Textract — alternative extraction and OCR of scanned PDFs
- Google Calendar and Infomaniak (CalDAV) — calendar sync, both ways
- Google Drive / Sheets — bid folders and the finance sheets
- Mailchimp — newsletter audiences and sends
- ip-api.com — city and country of a sign-in
Only the calendar keeps a copy here: events are mirrored into the database so the portal can show and edit them. The other services hold nothing the portal would need to restore.
Domains & surfaces
One application answers on several domains and picks the surface from the host name.
dashboard.humanitarian.tech— the dashboard (all entities)portal.reliefapplications.org— Relief Applications consultant portalportal.oortcloud.tech— Oort consultant portalportal.ouirace.com— OuiRace consultant portal/portal/<project>— client portal;/careers— public job openings and applications/api/mcp— the MCP endpoint for AI assistants (/oauth/…for their sign-in)
All domains are proxied by nginx to the same container.
In short
The database right now
What takes the space
Size on disk per module, indexes included. Logs, journals and the calendar mirror grow with use; the business data itself stays small.
Every table
Click a table to see its columns. Names, types and counts only: no content is shown here.
How the main records relate
People: consultants is the one person table, for staff, consultants and roster members alike; the role column says what they may open. A person has one row there and one staff_contracts row per contract.
Inside a project row: phases, deliverables, contacts, the team and the client-portal emails are JSON columns of projects, not tables. Hours are rows of time_tracking_entries.
Files are not in the database: a column ending in _key holds the path of the file in object storage.
Automatic copies
Three jobs copy the database with SQLite's backup API, which is safe while people are working.
What is kept, and where:
- Every hour (at :30) — a local snapshot in
data/snapshots/, skipped when nothing changed. The newest 48 are kept. - Every 6 hours — a copy in the backups bucket under
backups/6h/, kept 7 days. - Every night at 02:00 (server time) — a copy under
backups/portal_backup_YYYYMMDD_HHMMSS.db, kept 60 days. - Snapshots taken before a restore, before a bot revert or during an incident are kept 14 days.
When a copy fails, every super-admin is emailed (at most once per 12 hours per job) with the error and the free disk space. Snapshot Now and Backup Now on Admin › Database run them by hand.
Manual download
Download Backup saves a copy of the database to your computer. Super-admins only: the file contains every HR record.
What a database copy contains:
- Included — all structured data: projects, clients, invoices, contracts, HR, recruitment, logs…
- Not included — the files in object storage (PDFs, CVs, signatures, pictures, everything in the Drive) and the Firebase accounts. Files have their own net: see Architecture › Object storage
Restore
Three sources, all on Admin › Database: a local snapshot, a backup from the bucket, or an uploaded .db file.
What a restore does:
- Checks the file first: SQLite integrity, the core tables, row counts next to the live ones (the upload has a Dry Run that stops there)
- Keeps the current contents as
portal.db.bak - Loads the copy into the live database in one transaction, so every server worker sees it at once
- Re-applies the schema changes newer than the copy, and deletes again what had been deleted since
Click Restore once: a second restore started meanwhile is refused.
When the server set the database aside
At start-up the server checks the database. A file it cannot read is moved aside (portal.db.corrupted…) and a new one is started, so the portal comes back empty rather than not at all.
- A red Database files set aside on the server box then lists each file with its row counts
- Adopt as snapshot on the one with the real counts, then Restore it from the snapshot list
- Once the live counts are right, Delete the set-aside files: nothing removes them automatically
Log archives
Logs are what makes the database grow. The recent rows stay in it, where Admin › Logs can filter and search them; the older ones are moved to text files in the backups bucket every night.
What moves, and when:
- AI-request log — rows older than 90 days; connection handshakes older than 7 days. Each person's latest request stays, for "last used".
- OAuth chatter of the activity log (discovery and request-entry traces), which is no longer recorded.
- Files:
backups/logs/<log>/<year>/….jsonl.gz, one JSON line per row, kept 365 days. - A row is deleted only after its file was stored and read back whole. No bucket, or a failed upload: nothing is deleted, and super-admins are emailed.
The activity log itself is not archived: bodies are dropped after 90 days and rows after 365, for good. Deleted rows free pages inside the database file, which SQLite reuses; the file does not shrink by itself.
Disk space
The local snapshots are full copies: 48 of them weigh 48 times the database. The Schema page shows the current database size, the snapshot folder and the free space of the data volume.
- A growing database grows the snapshot folder with it, on the same volume
- The backups bucket holds up to 60 nightly copies and 28 six-hourly ones
- Most of the growth is logs and mirrors, listed per table on the Schema page
Roles
raphael@reliefapplications.org). Inherits all rights.| Capability | Super Admin | Admin | HR | PM | BizDev | Consultant | Client |
|---|---|---|---|---|---|---|---|
| Admin Dashboard Access | |||||||
| Sign in to the dashboard (Google, or email + password with a second factor) | |||||||
| Dashboard section (Income, Financial, Tracking, Expenses, Planning) | |||||||
| Dashboard › Bonus | |||||||
| View as another role (preview only) | |||||||
| Impersonate a named person, open their portal as them (Test Portals) | |||||||
| AI assistant over MCP, unless switched off for the person | |||||||
| Calendar, Skills library, Doc pages, My TODOs, page comments | portal calendar | ||||||
| Projects | |||||||
| See project list & QA Check page | assigned | own | |||||
| Open a project (enter the card) | read only | team only | team only | assigned | own | ||
| Create new projects | |||||||
| Edit a project (details, time, deliverables, phases) | team only | team only | read | read | |||
| Delete projects | |||||||
| Time Tracking and Payment Validation (all projects view) | own projects | ||||||
| Resource Allocation | |||||||
| View Resource Allocation page (Project + People views) | |||||||
| Edit allocations inline on the global grid | |||||||
| Edit allocations on a project's Resource Allocation tab | own projects | ||||||
| Edit budget-code (overhead) allocations | |||||||
| Edit consultant weekly capacity (cap/wk) | |||||||
| Soft-flag a member as removed from a project | own projects | ||||||
| Clients | |||||||
| View clients | |||||||
| Create / edit / delete clients | linked | ||||||
| Biz Dev | |||||||
| Proposals, Tender Radar, CRM, Portfolio, Company info: view | |||||||
| Tender Radar and CRM: edit | |||||||
| Portfolio: edit cards and assets | |||||||
| Marketing | |||||||
| Marketing: calendar, content, library, brand kits, newsletter | |||||||
| Marketing: campaigns, templates, events, Mailchimp | |||||||
| Recruitment | |||||||
| Recruitment: openings, board, talent pool, email signatures | BizDev openings | ||||||
| Recruitment: Onboarding | |||||||
| Invoices & Contracts | |||||||
| Admin → Invoices: the invoice book (create, edit, delete, import, fetch) | own | ||||||
| Invoices and contracts of a project (project page) | own | ||||||
| Manage contracts | own | ||||||
| Manage bonuses | |||||||
| HR Module | |||||||
| HR → Team (staff records) | |||||||
| HR → Organisation Chart | |||||||
| HR → Dashboard, Contracts, Payments, Expense Reports, Leave, Salary grid | |||||||
| HR → Task Orders | own | ||||||
| HR → Roster | list | ||||||
| HR → Team photos | |||||||
| Counter-sign a Task Order or a Framework Agreement (the named CEO / COO signatories, not a role) | by name | ||||||
| Manage consultants (profiles, contracts, salary) | self | ||||||
| Approve leave requests | request | ||||||
| Approve payment requests | view | request | |||||
| Salary history, payroll exports | |||||||
| Settings | |||||||
| Manage team members & roles | |||||||
| Database: snapshots, restore, S3 backups, access clean-up | IT support | ||||||
| Database: download a copy | |||||||
| Logs: logins and activity (IT support without request bodies) | IT support | ||||||
| Access page: sign-in switches, invites, second-factor reset | IT support | ||||||
| Change a role (IT support: Consultant, PM and BizDev only) | IT support | ||||||
| Give or take IT support | |||||||
| Test Portals: the list, send an invitation | IT support | ||||||
| Test Portals: magic links, open a portal as, view as, accountant link | |||||||
| Demo Mode | IT support | ||||||
| Notifications: pause or reword an email, email design, SMS test | IT support | ||||||
| Accountants settings | IT support | ||||||
| MCP Keys & Bots, MCP Actions (IT support: no key or bot secret for an HR, Admin or Super Admin account) | IT support | ||||||
| Tech documentation (this page) | IT support | ||||||
| Consultant Portal | |||||||
| View own profile, contracts, payslips | |||||||
| Submit time, leave, payment requests | |||||||
| Client Portal | |||||||
| View own project (deliverables, invoices, contracts) | |||||||
| Sign documents | |||||||
Enforced server-side via the @require_role decorator and the per-project _can_access_project check in app.py. Super-admin inherits all rights; HR inherits admin rights for shared endpoints — except the Dashboard section (Income, Financial, Tracking, Bonus, Expenses, Planning), which is gated by @require_admin on every /api/dashboard/* route and is admin / super-admin only. The inheritance runs the other way on HR → Team: the staff-records page is HR / super-admin only and an admin sees HR → Organisation Chart — the same page's other view — instead. That one is a UI rule (canHrTeam), because the chart draws its boxes from the very same /api/hr/people list the records view reads; BizDev is strictly read-only on projects/clients with no inheritance. Project list & QA Check are visible to every dashboard role; opening a specific project ("team only") requires being super-admin, admin, the PM, or listed in the project's team assignments.
My TODOs
Loading…
Core documents
Uploaded policies with AI-generated summaries. Used by the MCP connector for compliance / due diligence questions.
Loading policies…
Edit card
Portfolio cards are presentation views of a project — editing here never changes the project itself. Saving never regenerates the visual.
A PDF keeps its hyperlinks in the exported deck. Saved when you click Save; replaces this language only.
Type the hero filename instead
Link card to a project
All caught up!
You've reviewed every profile in this pass.
Documentation
How Task Orders work in the portal.
Request a TO
Project Managers can request a new Task Order for a consultant directly from the portal. Here's how it works:
- Navigate to HR → Task Orders and click New Task Order
- Select the consultant from the team list. Only consultants with an active contract can be assigned a TO.
- Fill in the details:
- Project — the project this TO is linked to
- Budget code — for financial tracking
- Start & deadline dates
- Total hours or days allocated
- Rate — daily or hourly rate for the consultant
- Description — scope of the work
- Submit the request. The TO is created with status draft.
After the request
- Generate the TO document — click to generate the PDF.
- Send for signature — click to email the TO to the consultant. They receive a magic link to review and sign.
- Consultant signs — the consultant opens the link, reviews the TO, and signs electronically. Status moves to Ongoing.
TO lifecycle
How consultants submit invoices through the portal.
Submitting an invoice
Consultants submit invoices via the Consultant Portal. Each invoice is tied to a Task Order and a specific month.
- Open the portal — the consultant accesses their portal via the magic link sent by email.
- Select the Task Order — choose the active TO for which they want to submit an invoice.
- Fill in the payment request:
- Month — the period covered by the invoice
- Amount — the invoiced amount (based on days/hours worked × rate)
- Invoice PDF — upload the invoice document
- Timesheet — upload the signed timesheet for the period
- Submit — both the invoice and timesheet must be uploaded and the amount confirmed before submission is allowed.
What happens next
- Review — the PM and admin team are notified. They review the invoice and timesheet in the admin portal under HR → Payments.
- Approval — the payment request is validated and processed for payment.
- Payment — once paid, the status is updated and the consultant can see it in their portal.
Payment request lifecycle
Important notes
- Invoices must match the rate and conditions defined in the Task Order.
- A signed timesheet is mandatory for each payment request.
- Consultants can only submit invoices for Task Orders with status Ongoing.
- If a payment request needs correction, the admin can reject it and the consultant will be notified to resubmit.
Connect LLM
Welcome to your AI space 🎉
Two gifts have been waiting for you. Click to unwrap — each one unlocks a new way to bring our portal data into your favorite LLM.
An AI-ready portfolio
One file with every project we've ever shipped. Drop it in any LLM and find a relevant project example in seconds.
Plug your AI into the dashboard
Give your favorite LLM its own personal API key. It can then query projects, clients, invoices, and TOs in real time.
- OAuth (claude.ai web/desktop): you sign in with your portal Google account each time the token is refreshed. Only RA admins, PMs, HR, and BizDev are allowed; consultants are blocked.
- Static
mcp_…keys (CLIs, ChatGPT, Gemini): one key per device/LLM, auditable per person, valid 30 days then rotated; every key issued is reported to the super-admins.
Claude.ai (web & desktop)
OAuth — no token- Open claude.ai → Settings → Connectors → Add custom connector.
- Name:
RA Portal - URL:
https://dashboard.humanitarian.tech/api/mcp - Leave authentication empty — claude.ai will detect OAuth automatically.
- Click Connect. A popup will ask you to sign in with your portal Google account, then to confirm consent. Allow it — you're done.
- Enable the connector in a new chat. Try: "list my active projects".
mcp_… key and pass it as a header:
claude mcp add ra-portal --transport http https://dashboard.humanitarian.tech/api/mcp --header "Authorization=Bearer mcp_YOUR_TOKEN"
ChatGPT
native MCP Plus / Team / Enterprise- Open chatgpt.com → Settings → Connectors (or Apps → Custom MCP depending on your plan).
- Choose Add custom connector → MCP server.
- Name:
RA Portal - URL:
https://dashboard.humanitarian.tech/api/mcp - Authentication: Bearer / API key = your
mcp_…token. (If only "header" is offered, use header nameAuthorizationwith valueBearer mcp_YOUR_TOKEN.) - Enable the connector for the conversation, then ask a portal question.
Gemini
via CLI / proxyConsumer Gemini (gemini.google.com) doesn't expose remote MCP yet. Two practical options:
gemini mcp add ra-portal --transport http https://dashboard.humanitarian.tech/api/mcp --header "Authorization=Bearer mcp_YOUR_TOKEN"
mcp-remote for clients that only support local stdio MCP. Run:
npx mcp-remote https://dashboard.humanitarian.tech/api/mcp --header "Authorization: Bearer mcp_YOUR_TOKEN"
Then point your Gemini-based tool at the local stdio bridge.
Mistral / Le Chat
via proxyLe Chat doesn't currently expose remote MCP servers in the consumer UI. Options:
- mcp-remote bridge — same command as for Gemini above. Use it with any Mistral-API-compatible client that supports local MCP (Continue.dev, Cline, etc.).
- Mistral La Plateforme — if you're calling the Mistral API yourself, attach the portal as a tool by proxying through your own MCP-compatible runtime.
- Use Claude.ai or ChatGPT instead for portal questions if you don't need Mistral specifically — both have native MCP support.
Other MCP clients
Any MCP-compatible client (Cursor, Continue.dev, VS Code MCP extension, custom code) can connect with these details:
https://dashboard.humanitarian.tech/api/mcp2024-11-05Authorization: Bearer mcp_YOUR_TOKENAuthorization: Bearer mcpat_… — discovery at /.well-known/oauth-authorization-serverGET /api/mcp/healthTry these prompts
- "What can you tell me about my portal?" — the LLM will call
get_system_documentationandget_rights_matrix. - "List all active projects, group by client."
- "Which task orders are about to run out of hours?"
- "Summarize Alice's activity this year." (operational view only — no salary or leave data)
- "Top 5 clients by total invoiced revenue."
- "Search for anything mentioning ILO."
Keys expire after 30 days — rotate them.
Every mcp_… key is valid for 30 days; you get an email 5 days before it expires. The plaintext token is only shown once at creation. Whether a key is expiring, lost, or you suspect it's compromised, rotate it from the card above:
- Click Rotate next to the key. The old secret stops working immediately and a new one (valid 30 more days) is shown once — copy it.
- Update each connector (Claude.ai, ChatGPT, Gemini, …) with the new token.
- If you no longer need a key, click Revoke instead. Every key issued or rotated is reported to the super-admins.
The portal, explained.
Where things are, how to do them and what every status means, cut to what your role can open. The same handbook Arturo reads before he answers you.