Admin
Settings that would otherwise be constants buried in the code, and the
state of what is actually running.
Anyone who can reach this server can see and change this page.
Sign-in is not built yet. Everything here is readable, and the settings that
could weaken a control — the provenance gate, the two-person rule, open-web
research — are deliberately read-only until it is. Secrets are never shown:
only whether they are set.
Users
Users exist in the database and the roles below are enforced by the lifecycle
rules, but nobody signs in — so nothing on this server currently knows who you
are. These records are what the approval history is attributed to.
What the roles mean
| viewer | Reads reports. Changes nothing. |
| analyst | Writes and edits, and submits for review. |
| approver | Reviews, approves and publishes — never their own edits. |
| admin | Everything, including this page and the approved site list. |