What is it?

Before you can adopt Plan✕ your IT or procurement team may want more information about the product so they can carry out due diligence.

<aside> <img src="/icons/info-alternate_gray.svg" alt="/icons/info-alternate_gray.svg" width="40px" /> The answer to most questions can be found on our Plan✕ Service Specification page

</aside>

How to do it

  1. Direct your IT team to the Plan✕ service specification pages, where they will be able to find answers to most questions. You can also share our most recent Penetration test (Security Audit) certification with them.
  2. If they have a questionnaire or DPIA screener that must be filled out, send it to @Alki Zaganiaris - OSL and @Silvia Pau - OSL via the ODP Slack or [email protected] and [email protected].

Accessing the Editor

Allowing Plan✕ domains

  1. If you have issues accessing the two Plan✕ Editor URLs shown below, you likely need to ask your IT team to add them to an ‘allowlist’ to prevent them being blocked by firewalls on your local council network:
    1. Production: editor.planx.uk
    2. Staging: editor.planx.dev

<aside> ⚠️ Troubleshooting: You navigate to one of the URLs above, but you face a message saying something along the lines of ‘Access Denied’ or ‘This site is blocked by your organisation’. This would then require your IT team to complete step 1 above.

</aside>

  1. Plan✕ uses the WebSocket protocol within the Editor to support collaboration and real-time updates. If you can access general menus but fail to load the flow graph, you likely need to ask your IT team to allow the following WebSocket Secure (wss) connections:
    1. wss://sharedb.editor.planx.uk
    2. wss://sharedb.editor.planx.dev
    3. wss://hasura.editor.planx.uk/v1/graphql
    4. wss://hasura.editor.planx.dev/v1/graphql

<aside> ⚠️ Troubleshooting: You have access to your workspace but when you load a flow/service, the graph structure appears stuck and does not load. This is expected if the wss connections are blocked, in which case your IT need to complete step 2 above.

</aside>

Signing in with Microsoft

If your LPA uses Microsoft, any staff in your Plan✕ team (see 5. Create your Plan✕ workspace) can sign in to the Editor via Continue with Microsoft.

Depending on your EntraID settings, the first person to sign in may see a "Need admin approval" message. Then the following applies:

  1. If your council has the admin consent workflow enabled, any staff member can request approval from that screen, and an admin will find the request under Enterprise applications → Admin consent requests.
  2. Alternatively, an admin should attempt to log in to Plan✕ via Continue with Microsoft. They will then need to sign in to their Microsoft account, tick Consent on behalf of your organisation and click Accept. If they are not a registered Plan✕ user, they will then see "User not found", but this doesn’t matter - the consent will already have been granted.
  3. If an admin would prefer to grant consent in advance without logging in to Plan✕, they can instead visit the following admin consent endpoint, substituting {tenant} for your tenant ID:
<https://login.microsoftonline.com/{tenant}/v2.0/adminconsent?client_id=4469ee56-9275-47f3-b29d-e0df0991099a&scope=openid%20email%20profile%20https%3A%2F%2Fgraph.microsoft.com%2FUser.Read&redirect_uri=https%3A%2F%2Feditor.planx.uk>

By ‘admin’, we mean an account with a role such as Global Administrator, Privileged Role Administrator, Cloud Application Administrator, or similar.