STC synthetic accounts — the address book

Source of truth: agent.fhir/estate/ (ADR-0042). Passwords live in 1Password (sweettreeconnect · Shared) at the titles shown — never here. Demo/test personas use the known fiction-only passwords.

Demo — the .xyz surfaces (database: demo)

The reactive half (sensor → push) is deliberately NOT here — it is the prod-resident Doll House (see prod-fixtures.yaml). Nothing in demo buzzes; that is by design.
accountenvwhat / where the secret lives
demo.planner@sweettreeconnect.comdemorole admin
Runbook role — plans, narratives, catalogue (admin), Connect charts.
1P: demo.planner@ — SweetTree Connect planner DEMO (app.sweettreeconnect.xyz)
demo.carer@sweettreeconnect.comdemorole carer
The 2026-09-09 probe finding lives here: claim listed both seats but the live team no longer seated the root (wipe orphaned it; family got a repair script, carer did not). The first converge closes it.
1P: demo.carer@ — SweetTree Carer DEMO (carer.sweettreeconnect.xyz)
demo.family@sweettreeconnect.comdemorole related-person
Runbook role — family view, two circles, in-app client switcher.
1P: demo.family@ — Circle of Support DEMO (circleofsupport.sweettreeconnect.xyz)
sthcs.li@, sthcs.ld@, sthcs.bi@, sthcs.dementia@demo—

Test — Claude + CI (database: test; .tech surfaces serve the journey suite)

accountenvwhat / where the secret lives
test.planner@sweettreeconnect.comtestrole planner
1P: test.planner@ — SweetTree Connect planner TEST (app.sweettreeconnect.tech)
test.carer@sweettreeconnect.comtestrole carer
1P: test.carer@ — SweetTree Carer TEST (carer.sweettreeconnect.tech)
test.family@sweettreeconnect.comtestrole related-person
1P: test.family@ — Circle of Support TEST (circleofsupport.sweettreeconnect.tech)

Training — the .training showhome (database: training; weekly reset)

Audience is EXTERNAL (sales prospects, client evaluators) — the reason this database may never derive from prod. Accounts live in Identity Platform tenant training-61qzz (ADR-0044): the .training surfaces sign into it automatically, and these credentials do not exist anywhere else. No IoT, no pushes in v1 (ADR-0043 §6). The weekly reset (Sun 03:30 UTC) restores the showhome; Auth accounts follow the standing rule — reported, disabled on expiry, never auto-deleted.
accountenvwhat / where the secret lives
training.planner@sweettreeconnect.comtrainingrole admin
In-tenant since 2026-09-14 (uid 9s5qBofK…; the disabled main-pool copy 2J11q4Uj… awaits Ed's by-name deletion). Sees all three showhome clients; admin unlocks the catalogue tab.
1P: training.planner@ — SweetTree Connect planner TRAINING (app.sweettreeconnect.training)
verify: cd agent.fhir && uv run python scripts/probe_env_personas.py --database training
training.carer@sweettreeconnect.comtrainingrole carer
In-tenant since 2026-09-14 (uid mVnQxyvh…; disabled main-pool copy la0FEm50… awaits deletion). On shift daily 08:00–20:00 UTC for The Show Home (rolling rota, renewed by the weekly reseed).
1P: training.carer@ — SweetTree Carer TRAINING (carer.sweettreeconnect.training)
verify: cd agent.fhir && uv run python scripts/probe_env_personas.py --database training
training.family@sweettreeconnect.comtrainingrole related-person
In-tenant since 2026-09-14 (uid I44rDmJ0…; disabled main-pool copy SdShBSke… awaits deletion). Next of kin of Sylvie Winterbourne AND (2026-09-29) Marguerite Fenwick (Spinal) — the Circle offers a client switcher; Marguerite brings the Doll House lanes. Live change made with `seed_personas.py --database training --family-teams-delta` (touches only this persona).
1P: training.family@ — Circle of Support TRAINING (circleofsupport.sweettreeconnect.training)
verify: cd agent.fhir && uv run python scripts/probe_env_personas.py --database training

Develop — the .dev surfaces (database: develop)

☠️ THE RULE ENDED 2026-09-17. It used to read: staff test on .dev with their OWN production accounts — Auth is project-wide, uids survive the pseudonymised clone, only the data differs (ADR-0038 §4.1 relaxation). That worked only because .dev shared the main pool. Binding the surface to tenant develop-wlqyv makes it a SEPARATE POOL: a production account is now refused on .dev outright, uid or no uid. Every person who tests here — Ed and Dylan included — needs an account minted inside the tenant via the planner's "+ Add user" door. "No dev-specific users" has gone from the design to the thing that locks you out. ADR-0038 §4.1 wants amending to say so. ☠️ develop also runs the STRICT ruleset — a thin or stale token is denied where prod's permissive rules would admit it; that asymmetry is unchanged, and is still why develop.caremanager@ exists.
accountenvwhat / where the secret lives
develop.carer@sweettreeconnect.comdeveloprole carer
The purpose-built DEV CARER (Ed 2026-10-06). An account inside tenant develop-wlqyv, so it signs in on .dev where production accounts are refused. Seated on the three HTEST fixture clients (Alice McTest, Bob Fixture, Charlie Sample). Carries 3 synthetic OWED chase cases, rebuilt every night with dates relative to the run (one overdue, one due today, one tomorrow), so the carer app's Owed list can be seen off production.
Survives the nightly wipe because Auth is not Firestore: the login and its claims are made once; refresh-develop-firestore.yml re-seats the graph (seed_personas.py --database develop --no-auth) and re-writes the owed cases (seed_dev_owed_cases.py --apply) after the HTEST fixtures. forgejo-runner@ has no Firebase Auth rights, by design.
1P: develop.carer@ — SweetTree Carer DEVELOP (carer.sweettreeconnect.dev)
verify: cd agent.fhir && uv run python scripts/seed_dev_owed_cases.py (dry run: lists the owed cases it would write)
develop.caremanager@sweettreeconnect.comdeveloprole planner
The purpose-built THIN dev planner: strict-rules rehearsals need an ordinary planner token (no admin bypass) against the strict ruleset — an admin's own account cannot exercise those branches. Used for the OMON-250 cutover rehearsals (all-green web-estate cell, 2026-07-24).
1P: develop.caremanager dev-planner
develop.relatedperson@sweettreeconnect.comdevelop retire-candidatesuperseded by the persona model. Disable-first when Ed marks.

PRODUCTION — fixtures living in the real database (database: (default) — never converged)

accountenvwhat / where the secret lives
dollhouse@sweettreeconnect.comPRODUCTION (default)The demo phone's carer. The Doll House is the one prod-resident demo estate — its story is the REACTIVE half (sensor → push), and the alert stack exists only in prod. Practitioner hop + rolling synthetic rota (~6 weeks ahead; re-run the script if the app shows no shift before a demo — runbook instruction).
appreviewer@sweettreeconnect.comPRODUCTION (default)App-store review persona (ADR-0038 §4.3: reviewers review the shipped binary → prod). dataScope=test carer on the HTEST demo teams. ☠️ Credential changes gate on app.circleofsupport/ci/ verify_appreview_creds.py BEFORE any store submission.
appreviewer_carer@sweettreeconnect.comPRODUCTION (default)Review persona for the carer app; same rules as appreviewer@.
Ami Tabletson (client fixture, no login)PRODUCTION (default)The reviewers'/tablet client. HTEST-stamped prod scaffold (5 docs + the once-missed root person); passes through to develop un-pseudonymised (synthetic exemption).
demo@sweettreeconnect.comPRODUCTION (default)Legacy "Demo hcs" carer (dataScope=test, six HTEST demo teams) — pre-ADR-0038 mechanism. RETIREMENT pending since the 3b cutover plan (disable → one demo cycle → delete by name, CEO consulted). Kept here so the retirement is a spec edit, not archaeology.
hcsdemo.carer@sweettreeconnect.comPRODUCTION (default)Legacy demo carer; same retirement path as demo@.
sthcs.li@, sthcs.ld@, sthcs.bi@, sthcs.dementia@PRODUCTION (default) unconfirmedSee demo.yaml's unconfirmed_accounts — four service-line carers on the pilot reference clients' teams, no env claim, absent from the runbook. Listed on the prod side too because without an env claim the gates admit them to prod/develop surfaces. Ed to confirm intent or retire.
pilot23.family@sweettreeconnect.ioPRODUCTION (default)Prod-truth family test user — CoS against a REAL pilot estate (sees a real client's live devices). HTEST-stamped person, deliberately no oneTouchId (invisible to onetouch-sync). Password known-1p.
1P: pilot23.family@sweettreeconnect.io
pilotN.carer@sweettreeconnect.ioPRODUCTION (default)The CURRENT per-pilot carer login pattern (install + e2e alert tests); known live: pilot0, 17, 23, 24. NOTE the domain: the .io accounts are this generation; the pilotN.carer@sweettreeconnect.COM accounts in the 2026-09-09 audit are the two OLDER generations (retirement queue below).
admin.monitor@sweettreeconnect.comPRODUCTION (default)OPERATIONAL — the IoT-monitor identity (role admin, 14 teams); the coordinator docs instruct using it. An ops identity, not a test login.
visualise@, meetingrooms@, outcomemonitoring@PRODUCTION (default)OPERATIONAL — per-app service logins for the gated dashboards.
test@sweettreeconnect.comPRODUCTION (default)OPERATIONAL — rides the real OneTouch sync with the canary identities; classifies as onetouch-real in the audit, correctly.
notaclient@, notacoordinator@, operations.carer@, develop.relatedperson@PRODUCTION (default) retire-candidatenotaclient@ = the frozen stc_carer app's login (sign-ins ended with the app; the NAME lives on as office SSID/MQTT user — unrelated to Auth). notacoordinator@ = superseded by admin.monitor (per app.coordinator CONTEXT). operations.carer@ = retired-fleet class (07-20 rules audit). develop.relatedperson@ = pre-persona dev RP login (see develop.yaml). Plus the audit's generation lists: pilot1–12,14 (.com, no-person) and, after per-pilot confirmation, pilot15–19 (.com, manual).