Tracker Scheduler Access (Phase 1, 2026-08-10)

Overdue-permit tracker reworked for branch-scheduler access (entirely-api bbce572, entirely-portal 6911462).

  • GET /tracker/data now requires portal login or API key. Branch-scoped roles (scheduler/assistant/ap/goa/goa_readonly) receive ONLY their branch’s zone via _ZONE_BY_ACCOUNT in routes/tracker.py; triage, UP owners/admins, corporate GOA, and API-key callers keep all six zones. POST /tracker/sync gated the same way.
  • New GET /tracker/export.csv — same scoping, Export CSV button on the page.
  • Portal: /tracker RoleRoute gained scheduler; JES-branch schedulers get an “Overdue Permits” sidebar link (GW branches have no zone → no link). Zone tabs derive from the response, so scoped logins see one tab.
  • unlikely.ltd mirror now reads a nightly snapshot (/opt/scripts/tracker_snapshot.py, 20:45 ET claude cron → /var/www/taskforce/snapshot.json) instead of the live endpoint, which was world-readable since April.

Phase 2 (NOT done): remap unlikely.icu domain roles to schedulers + make /tracker its landing, deactivate Stephaney + remove her upload grant — held until she departs (8/31) or moves to unlikely.engineer. Audience = branch schedulers is a working assumption; Angie (corporate GOA) may redirect it. The post-Stephaney data feed is undecided; her workbook autosync cron is pinned broken (root-owned log dir) by explicit decision.

Update (same night): the tracker is named The Backlog (Dustin, via the orientation-card session; card rev 5 prints “The Backlog / unlikely.icu”). Portal page title + all sidebar labels renamed (entirely-portal 6529a1f). The unlikely.ltd mirror keeps its unbranded title on purpose.