SANDBOX
Administration

Users & roles

Role assignment and the capability each role carries.

Roles are enforced on the server, not in the UI

Every mutating route re-checks the role before it acts, and preparation is structurally separated from approval: an operator prepares, a reviewer authorises. An operator cannot approve their own case, and no agent can approve anything at all — agent runtimes are given read/analyse tool permissions only.
Directory

Users (3)

NameEmailRoleMFAActiveWorkspaces
Analyst (operator)operator@example.gov.pkoperatoronactivews-default
M. F. Ashrafadmin@example.gov.pkadminonactivews-default, ws-punjab, ws-ict
Reviewing officerreviewer@example.gov.pkrevieweronactivews-default, ws-punjab
Role capability

operator

  • ingest and investigate URLs
  • run agents
  • open and progress cases
  • assemble and seal evidence
  • prepare enforcement requests
Role capability

reviewer

  • everything an operator can do
  • approve or return cases at the approval gate
  • authorise enforcement requests
Role capability

admin

  • everything a reviewer can do
  • manage watchlist and integrations
  • configure retention