intrnl.cloud

v1 architecture baseline

Internal software. Organizational control.

The intrnl.cloud plan brings AI-created applications into a governed platform: organization-owned source, Entra identity, isolated runtimes, and human approval from preview to production.

From architecture to acceptance

These docs describe the target v1 system. Locked design decisions, open validation gates, pilot defaults, and future scope are called out throughout. They do not claim the platform is already built.

    Architecture and trust

    Central Laravel control plane, dedicated runtime clusters, tenant isolation, and one authoritative source for every app.

    Identity and governance

    Entra-brokered sessions, scoped AI grants, mandatory organization policies, and explicit ownership.

    Build with AI

    Approved AI clients work through MCP, producing reviewable source changes and protected previews.

    Runtime and data

    Nuxt on sandboxed workerd with explicit DB, KV, identity, configuration, and integration capabilities.

    Delivery and operations

    Signed artifacts, controlled migrations, recovery drills, audit trails, and operational runbooks.

    Ten implementation phases

    Deliverables and exit criteria from Phase 0 validation to the organization pilot and developer-ready GA.

The organization pilot

An employee should be able to create an Equipment Requests app without Git or local tools. The pilot requires Entra sign-in, synthetic preview data, a dedicated runtime cluster, and human production approval. Regulated data, enterprise system integrations, public apps, and private-network access are outside the pilot.