Hello, I’m Nora, your AI guide from Technology Last Stop. This guide covers Development, QA and release promotion. Start in Development, freeze and validate in QA, then promote the same application code to Production. Your existing production owner account grants Dev/QA access. Current availability: Trusted same-account sign-in implemented; external provider acceptance separate. Before you start. Your existing approved TLS owner account and its registered Verify method; separately deployed Dev and QA Sites. A distinct database, object storage and vault key per environment. Dedicated provider test accounts are needed for external integration testing. Step 1. From the main Connect owner portal, use the visible Dev, QA or Company Workspaces buttons. They open separate tabs directly. Open Domains & access for provisioning details. Requested TLS addresses are dev.connect.techlaststop.com and qa.connect.techlaststop.com; until DNS and HTTPS activate, the Dev and QA buttons use the available private native addresses. Open Domains & access > Dev and QA DNS records to copy the exact GoDaddy Type, Name and Value for TLS. Each hostname needs its CNAME and both TXT records; the GoDaddy names already omit techlaststop.com. Step 2. Open Dev or QA directly and choose Continue with your existing account. If needed, complete Microsoft, Google or password sign-in and your existing LastStop Verify method at the trusted production identity service. You do not need to open production manually first or create a second account. The environment receives its own protected session. Step 3. Owners have automatic app-level access. Grant existing staff Development or QA access in Environments. Production validates the current account, role, environment permission and LastStop Verify state, then issues an encrypted, request-bound, one-use grant that expires after 60 seconds. The environment synchronizes the approved staff profile and creates a separate session for no more than eight hours. Sign in again to refresh role and profile changes; revoking the local environment session takes effect immediately. Sites owner-private audience remains an additional hosting restriction; a staff app grant does not change that audience. Step 4. Keep external actions isolated. Local tickets, chat, images and knowledge can be exercised using synthetic data; outgoing email is suppressed. Provider actions, device commands and production identity provisioning remain isolated. Live Stripe credentials are refused outside production. Step 5. Build the change in Development. Freeze the application source, lockfile and migration set; copy that same code to QA. QA covers roles, company isolation, payment failures, session lifecycle, upload boundaries and the intended device/browser journeys. Step 6. Record validation in the owner Environments page with the source commit, artifact checksum, environment and evidence. A QA pass requires a prior Development pass for the same identifiers; Production requires QA. This records evidence and does not itself invoke Sites deployment. Step 7. Publish the accepted code through the owner deployment workflow. Perform a short production health check for routes, sign-in, migrations and environment-specific providers. Full QA is repeated when code changes; a prior test cannot guarantee a different runtime configuration will succeed. Step 8. Professional includes limited clean Dev for five test users; Enterprise includes ten, after provisioning. Standard has no included Dev. QA is $79/month; the separate Dev + QA bundle is $99/month. The Configuration replicas & recovery guide describes encrypted settings transfer, verification, retry and rollback after TLS allocates an isolated target. Hosting allocation, full production cloning, capacity and customer federation remain unfinished. A request is not a deployed replica or an automatic charge. Step 9. Use dev.connect.techlaststop.com and qa.connect.techlaststop.com for TLS. Companies use dev.connect.companydomain.com and qa.connect.companydomain.com. Registered custom aliases return sign-in to the same hostname that started it; an unregistered hostname is rejected. Do not activate a preferred address until Sites reports active routing and HTTPS. Now verify the result. Each environment has its own database and bucket; no production secrets or customer data were copied. New migrations are additive and applied before the matching code is used. A production send or charge cannot be initiated from an isolated environment. Open in new tab is readable at mobile and desktop widths, keeps the complete label and does not open an embedded environment. The company environment request form fills connect.companydomain.com, dev.connect.companydomain.com or qa.connect.companydomain.com for the selected company and environment. Changing companies must not retain the previous company’s hostname. Previously requested, unverified company hosts using connect-dev.companydomain.com or connect-qa.companydomain.com are normalized to dev.connect.companydomain.com or qa.connect.companydomain.com. Verified custom hosts and custom alternatives are not renamed by this audited update. If you get stuck. If environment sign-in fails, use the displayed ENV reference: COOKIE or STATE means the browser handoff was missing or expired; REJECTED means the encrypted one-use grant, request binding or trusted key was rejected; RESPONSE or STORAGE means the received session could not be established. ENV-NETWORK applies only to a legacy handoff during staged deployment. Retry once from the environment link. Do not reset Verify or paste cookies into support messages. Pending custom domain: use the working private URL and add the exact CNAME/TXT values in the DNS instructions. Wix reports no managed DNS zone for techlaststop.com in the connected account. A private hosting audience blocks anonymous external webhooks. Keep it private until an approved provider test endpoint or intended audience has been configured. Use the current written guide for exact URLs, permission names, and provider documentation. Pause before entering credentials, and keep them in protected configuration. I’m Nora, your TLS guide.