Administration
Users & roles
Role assignment and the capability each role carries.
Roles are enforced on the server, not in the UI
Every mutating route re-checks the role before it acts, and preparation is structurally separated from approval: an operator prepares, a reviewer authorises. An operator cannot approve their own case, and no agent can approve anything at all — agent runtimes are given read/analyse tool permissions only.
Directory
Users (3)
| Name | Role | MFA | Active | Workspaces | |
|---|---|---|---|---|---|
| Analyst (operator) | operator@example.gov.pk | operator | on | active | ws-default |
| M. F. Ashraf | admin@example.gov.pk | admin | on | active | ws-default, ws-punjab, ws-ict |
| Reviewing officer | reviewer@example.gov.pk | reviewer | on | active | ws-default, ws-punjab |
Role capability
operator
- ingest and investigate URLs
- run agents
- open and progress cases
- assemble and seal evidence
- prepare enforcement requests
Role capability
reviewer
- everything an operator can do
- approve or return cases at the approval gate
- authorise enforcement requests
Role capability
admin
- everything a reviewer can do
- manage watchlist and integrations
- configure retention