BridgedCRM simulated operator frame · signed in as Ada Lovelace (op-demo) bus events: …
What you're looking at: the iframe is the bridge's real /screens/tg-inbox, framed by this simulated CRM page — allowed only because this origin is in the bridge's live managed frame-ancestors allowlist (§10).
This page minted the ticket server-side via a signed POST /session and handed it to the screen over postMessage (§11.3). Every action in the iframe is authorized by that ticket alone. Ada is scoped to LD-1001…LD-1006, so Priya's chat shows as unlinked awaiting triage. Replies go out through the (fake) Telegram Bot API; inbound messages are published to the CRM event bus as message.received.