BridgedCRMsimulated operator frame · signed in as Ada Lovelace (op-demo)bus events: …
What you're looking at: the iframe is the bridge's real /screens/tg-inbox, framed by this simulated
CRM page — allowed only because this origin is in the bridge's live managed frame-ancestors allowlist (§10).
This page minted the ticket server-side via a signed POST /session and handed it to the screen over
postMessage (§11.3). Every action in the iframe is authorized by that ticket alone.
Ada is scoped to LD-1001…LD-1006, so Priya's chat shows as unlinked awaiting triage.
Replies go out through the (fake) Telegram Bot API; inbound messages are published to the CRM event bus as
message.received.