Neon Law
  • Services
  • Book Consultation opens in a new tab
  • Sign in

← Operating Neon Law Navigator

Environment Matrix

Chapter 4 of 7 · Section 27 of 45

Sections

1. Intro

  • 1. Deploy your own
  • 2. Agenda

2. Prepare Google Cloud

  • 3. Bring your own project
  • 4. Dry-run first
  • 5. Private assets and domain restricted sharing
  • 6. The Navigator deployment matrix
  • 7. The `/app` mount and HTTP route ownership
  • 8. `neon` — the whole brand seam
  • 9. Live rollout checkpoint
  • 10. Set one site to one version

3. Provision the Infrastructure

  • 11. The APIs that light up
  • 12. Network and storage buckets
  • 13. How a Project portal reaches a client
  • 14. A document's bytes and authorization are separate
  • 15. A private image registry
  • 16. The cluster comes up
  • 17. What setup owns — and what follows it

4. Environment Matrix

  • 18. Three operating modes, two deployment profiles
  • 19. The deployment that says its matters are sample
  • 20. Configuration precedence: the first source wins
  • 21. Local dev controls: inputs read by `navigator dev`
  • 22. Local runtime: what `.devx/env` generates
  • 23. The store: SurrealDB
  • 24. Where SurrealDB authorization lives
  • 25. Deployed runtime: core web and worker wiring
  • 26. Deployed runtime: identity and access
  • 27. Deployed runtime: email, signatures, and billing
  • 28. Deployed runtime: repositories, content, AI, and scheduled work
  • 29. Provision and ship: variables read by the operator CLI
  • 30. Ancillary operations and opt-in test controls
  • 31. When sample data appears

5. Configure the Trust Boundaries

  • 32. Secrets: the invariants that gate the boot
  • 33. Sign-in: bring an OIDC provider; passwords live there, not here
  • 34. Role rings: who can do what
  • 35. Provider signup and parity across the deployments
  • 36. The external surface — every third party, in one place
  • 37. The two service deployments
  • 38. Security architecture

6. Ship the Instance

  • 39. Ship and verify
  • 40. Post the verified handoff in `#navigator`
  • 41. Point your domain at the instance (optional)
  • 42. Drive it from the CLI
  • 43. Make it yours — white-label under your own brand
  • 44. This is how we set up our production deployment

7. Wrap Up

  • 45. Canonical references

Deployed runtime: email, signatures, and billing

CapabilityEnvironment variablesDev / production rule
Email backendNAVIGATOR_EMAIL_BACKENDMust be sendgrid outside the harness
Outbound SendGridSENDGRID_API_KEY, SENDGRID_FROM_EMAILRequired outside the harness
SendGrid base URLSENDGRID_BASE_URLOfficial hosts only outside the harness
Inbound URL gateSENDGRID_INBOUND_SECRETRequired outside the harness
Inbound signatureSENDGRID_INBOUND_PUBLIC_KEYRequired when summary review is enabled
Attachment scannerNAVIGATOR_CLAMD_ADDRRequired in every deployed profile; private clamd only
Event webhookSENDGRID_EVENTS_SECRET, SENDGRID_EVENTS_PUBLIC_KEYRequired outside the harness
Threaded mailNAVIGATOR_PARSE_HOST, NAVIGATOR_LAWYER_NOTIFY_EMAILBoth values enable it
Summary opt-inNAVIGATOR_SUMMARY_ENABLEDEnables durable review
Summary identityNAVIGATOR_DEPLOYMENT_ID, NAVIGATOR_SUMMARY_CHANNEL_IDDurable review coordinates
Summary envelopeNAVIGATOR_SUMMARY_ENVELOPE_RECIPIENTSUnset/off by default; blank values fail
SMS intakeNAVIGATOR_SMS_NUMBER, TWILIO_AUTH_TOKENOff by default; a number needs the token
Summary Gemini modelNAVIGATOR_SUMMARY_GEMINI_MODELOptional Vertex model override
Summary Gemini locationNAVIGATOR_SUMMARY_GEMINI_LOCATIONOptional Vertex location override
Summary input limitNAVIGATOR_SUMMARY_MAX_INPUT_CHARSOptional input limit
Summary output limitNAVIGATOR_SUMMARY_MAX_OUTPUT_TOKENSOptional output limit
DKIM fenceNAVIGATOR_DKIM_REQUIRE_DOMAINOptional domain pin
Lawyer-sender DKIM checknone (always on)Must pass for sender's own domain on every lawyer command/relay
Internal ops noticesSLACK_WEBHOOK_URLOptional; otherwise captured in memory
Per-Project client-view noticesSLACK_BOT_TOKENRequired outside the harness; creates private Project channels
Dash0 endpointDASH0_ENDPOINTOptional staging-only integration declaration
Dash0 datasetDASH0_DATASETRequired with DASH0_ENDPOINT
Dash0 tokenDASH0_TOKENEncrypted Secret Manager input; required with DASH0_ENDPOINT
DocuSign endpointDOCUSIGN_BASE_URLDeclares DocuSign; demo in dev, live in production
DocuSign accountDOCUSIGN_ACCOUNT_IDEnvironment-specific account
DocuSign JWT IDsDOCUSIGN_INTEGRATION_KEY, DOCUSIGN_USER_IDPreferred auth path
DocuSign JWT proofDOCUSIGN_PRIVATE_KEY, DOCUSIGN_OAUTH_BASEPreferred auth path
DocuSign static authDOCUSIGN_ACCESS_TOKENShort-lived fallback
DocuSign signerDOCUSIGN_SIGNER_EMAIL, DOCUSIGN_SIGNER_NAMERequired signer identity
DocuSign webhookDOCUSIGN_HMAC_KEY, DOCUSIGN_WEBHOOK_SECRETRequired once DOCUSIGN_BASE_URL is set
Xero tenantXERO_TENANT_ID, XERO_BASE_URLAll Xero values select real billing
Xero OAuth clientXERO_CLIENT_ID, XERO_CLIENT_SECRETOtherwise stub billing
Xero OAuth tokenXERO_TOKEN_URL, XERO_SCOPE, XERO_ACCESS_TOKENOtherwise stub billing

Presenter notes

NAVIGATOR_CREDENTIAL_ENVIRONMENT must exactly match dev or production outside the harness. A normal dev deployment therefore sends real email from a non-production SendGrid account and creates non-binding envelopes in DocuSign demo. Dash0 is staging-only and optional: omit DASH0_ENDPOINT to omit the dataset and token as well. Once the endpoint is declared, all three Dash0 values are required; the deployment, Secret Manager, and ship checks refuse a missing value instead of allowing the renderer to drop Dash0 silently. Xero is different today: its variables are not part of the deployment invariant, so an incomplete production Xero set still boots and selects StubBillingProvider. Treat that as an explicit capability choice, not evidence that an invoice reached the ledger.

View all slidesOpen display
← PreviousNext →
Neon Law
  • X opens in a new tab
  • LinkedIn opens in a new tab
  • YouTube opens in a new tab
  • API opens in a new tab
  • Blog opens in a new tab
  • Contact
  • Glossary opens in a new tab
  • Navigator opens in a new tab
  • Notations opens in a new tab
  • Presentations opens in a new tab
  • Privacy opens in a new tab
  • Team opens in a new tab
  • Terms opens in a new tab
  • Testimonials
  • UX opens in a new tab
  • contact@neonlaw.com
  • +1 510 800 2080
  • Nevada
    5150 Mae Anne AveSte 405-9002Reno, NV 89523
  • New York
    12 E 49th St18th FloorNew York, NY 10017
  • Justice Technology AssociationMission-Aligned Partner opens in a new tab

Attorney advertisement. Nothing here is legal advice without a signed retainer for an active project. Past results do not guarantee future outcomes.

© 2026 Shook Law PLLC

NEON LAW® is a registered trademark of Shook Law PLLC, U.S. Reg. No. 6,325,650 opens in a new tab

Powered by Neon Law Navigator 26.10.4

Everyone deserves to be seen. Made with ❤️ in 🗽.