ASSIGNIT | ACCESS STUDIO EXTENSION 0.3.0

Sign into Access Studio, connect an Infor session, choose or create a
persona, and record what that persona should see and do as you walk Infor.

INSTALL FOR A DEVELOPMENT PILOT
1. Unzip the extension into a permanent local folder.
2. Open chrome://extensions or brave://extensions.
3. Enable Developer mode and choose Load unpacked; select this folder.
4. Open Access Studio from its toolbar action (side panel).
5. Use the Access Studio account your workspace administrator provides.

The default account-server address is https://access.assignit.io. Public
deployment and recovery checks are recorded separately from live Infor coverage.
To run locally,
follow ../server/README.md and expand Server address on the login form to use
http://127.0.0.1:8767. The backend must explicitly permit extension ID jdgjimaajgnaplclecnknielmgnepbde.
The packaged public key keeps this ID stable across unpacked installs.

YOUR WORKFLOW
- Sign into Access Studio. The account provides assigned workspaces and roles.
- Choose your workspace. Connect an already open Infor tab in this browser
  profile. The Access Studio pilot accepts any Infor CloudSuite environment;
  each persona and its choices remain tied to that exact tenant/environment.
  Operators can also configure a workspace with a restricted environment list.
- If Infor is not signed in, open your environment and sign in normally.
  Access Studio does not collect your Infor/Microsoft password or cookies.
- Choose a saved persona or create a job/responsibility with optional task notes.
  Suggestions come from screen labels; you confirm which persona to design for.
- Navigate in Infor as usual. The panel groups visible fields, actions, lists,
  forms and navigation. It updates when supported controls/frames change.
- Compact groups list Menus, Pages, Lists, Forms, Fields and Actions. Infor
  toolbar/navigation controls are available in a separate collapsed group.
- Show / Hide records visibility. Add criteria when that choice depends on a
  field or context: all/any conditions, is/is not/contains/is empty/is not empty.
  Criteria are user-entered requirements; the collector never reads field values.
  The earlier Permission dropdown is removed; existing permission records remain.
- Add an optional reason. Locate outlines the observed control briefly.
  Pick on page selects a control without activating it. A hover outline and banner confirm Pick is active. Escape cancels it.
  Exit Pick to navigate.
- Review choices across visited screens and download requirements JSON.

WHAT IS SAVED
Reviewed controls, persona choices and notes save to the Access Studio workspace
DB. Assigned administrators/designers can edit; consultants can review. The web
reviewer uses the same login and shows saved personas, requirements and save
history. A failed save retains a local draft scoped to account/server/workspace.
A conflicting revision never silently overwrites another editor. Export/back up
your draft before loading a newer saved version. Sign-out removes the account
session; unsaved drafts remain available only to the same account/workspace.

PRIVACY AND SCOPE
The collector reads UI labels/control metadata, not field values, table records,
passwords or session cookies. Tabs in other browser profiles are not available.
Unselected Infor tabs are scanned once for connection discovery only after login
and workspace selection; continuing observation requires an explicit connection.
Infor OS portal tenant paths are matched to their embedded application tenant.
Only that environment and trusted inherited frames in the connected tab are accepted.
Already-open tabs receive the current collector without reloading Infor. Older prototype
captures remain in their original local keys and are not automatically uploaded.

These are desired-access requirements. DOM labels/IDs do not establish native
security mappings. This version does not hide controls, block native actions,
generate deployable LPL or apply Infor changes. Native permissions must be mapped,
configured and positively/negatively tested by the technical security owner.

VERIFICATION LIMITS
Model, scanner/content, worker and actual HTTP backend tests are provided.
Read deployment and browser receipts for the exact verified build and scope.
Browser flow QA uses actual UI/source with a synthetic extension-API adapter and
local fixture. Native extension installation, login-document and worker startup
are verified separately. Read-only live discovery on the signed-in HCM HR Admin
Resources page identified fields, actions, menus, pages, a list and a form. The
native connected-panel and Pick checks are recorded in the deep-pass receipts. The supported
CDP development install is removed on browser restart; use the normal Load
unpacked steps above for a persistent development install.
Cross-origin Infor frames, virtualized controls and hidden/collapsed items need
live validation. Only currently rendered visible supported controls are listed;
repeat same-label controls without stable IDs may be combined conservatively.
Discovery currently supports *.inforcloudsuite.com; custom/on-premises hostnames
require a separate connector and are not detected by this pilot.

OUTSIDE-STORE DISTRIBUTION
Unpacked Developer mode is appropriate for this trusted development pilot.
For a managed organization, Chrome supports administrator-controlled self-hosted
installation through enterprise policies. General Windows/macOS self-hosted
installation requires those policies; Linux has additional self-hosting options.
https://developer.chrome.com/docs/extensions/how-to/distribute

DEVELOPMENT
From the parent source workspace:
  node --test tests/extension-*.test.cjs
  python3 -m unittest discover -s tests -p test_extension_server.py
  node tests/browser-extension.cjs
The last command requires existing CDP9223 and refuses to launch another browser.
