Oracle owns identity: login, profile, profile updates

Decided 5 Oct 2026 (Ravneet): login, the student profile, and getting students to keep it up to date all belong to Oracle, the home host. Oracle already owns coins and the shared student memory, so it owns the record those depend on.

What Oracle owns

Area Route / data Notes
Login (OTP now, Google later) /login, /api/auth/*, ck_identity.* One login for all Cetking sites
Student profile /profile, /api/profile/*, ck_student_profiles Read + edit by the student
Profile completion profileCompletion() Oracle nudges until it is 100%
Coins (already Oracle) ck_coin_ledger Shown in the profile header

Profile layout rule

Every block is a separate card with its own Edit / Save / Cancel. Editing one card never touches another.

  1. Personal: name, email (Google, status only), city. Mobile and Permanent ID are locked.
  2. My MBA Plan: exam year, exams, primary exam, target colleges.
  3. Cetking: membership, member since, centre, course, batch, coins. Read-only, managed by Cetking.
  4. Education: college, degree, graduation year, work experience.

New cards (e.g. scores, category, photo) are added as new cards, not by growing an existing one.

How Oracle gets students to update it (next phases)

  • On login: if the profile is under 100%, Oracle shows one small card: "Add your exam year (10 sec)" with a single field. It asks for one thing at a time, never a long form.
  • In conversation: when a student says something that belongs in the profile ("I'm giving CAT 2027"), Oracle offers "Save to your profile?" and saves only on a tap. It never saves silently.
  • Morning nudges: at most one profile nudge a week, and only for a field another bot needs (e.g. Purva needs target colleges).
  • Other bots read the profile through Oracle's shared memory and never write to it. If a bot needs a missing field, it hands the student to Oracle.

Rules (unchanged)

  • Only the server writes, and only allowlisted fields per card. Protected fields (ID, phone, lifecycle, course, batch, centre, coins) are always rejected.
  • Students cannot change or delete their Permanent ID; only Ravneet can delete it.
  • Opacity: no user counts anywhere; bots see only this student.
  • Greys only for UI.

Source: GitHub cetking-one/docs/ORACLE-IDENTITY-SCOPE.md. Edit the file there; this page updates on the next release.