Staff & roles
Admin opens from the avatar menu at the right of the top bar — it is deliberately not a tab, because most of the office never needs it. Roles are built from granular permissions — view_cases, manage_cases, assign_cases, view_campaign_history, view/manage_legislation, view/manage_office_comms, view_district_intel, view/manage_office_ops, manage_office, manage_office_users, view_office_audit — so interns see the queue and nothing else.
Users carry a name, email, role, and active flag; the superadmin manages accounts themselves. Name roles for the office, not the software — “Chief of Staff,” “Caseworker,” “Legislative Director,” “Comms” — and audit who holds view_campaign_history twice a year.
Signing in
Office staff sign in with a password or, when the office has it configured, Microsoft SSO — the same account they already use for work email. Passkeys are offered on the campaign side but deliberately not here; leaving them off the office side is a considered choice, not an oversight.
One person can belong to more than one office — a shared chief of staff, a district director covering two seats — and pick which office they are working in today. The account is one; the desk changes.
The constituent portal
One switch — gated on the office being public-enabled with casework on — plus the stats to run it: constituents, verified accounts, pending invites, active sessions, portal-filed cases.
Each account opens a drawer with its cases, its sessions (with IP and a revoke action), its notifications, and resend-invite or delete. Revoking a session logs that device out on its next request; the constituent's cases are untouched.
Public surfaces
Everything the district can see is off until the office turns it on, and each surface is its own switch — the Where-I-Stand page and the events feed, the constituent portal, the visitor kiosk. Nothing goes public as a side effect of something else; you decide, one at a time, what the outside world gets to see.
Feature flags sit above all of it, turning whole tabs on or off for the office — an office that does not run a legislative shop simply does not carry the tab. Turn on what the office actually does, and leave the rest dark.
NOTE — SUBSCRIBERS
The newsletter's subscriber list lives in Admin too — opt-ins and opt-outs both — so an unsubscribe is honored the moment it lands and the office never has to keep a side spreadsheet of who left.
The audit log
Every sensitive action, in order: when, actor, action, category, and success or failure, with detail. Search it, filter by category or status, and page back as far as the office's history goes.
Failures matter as much as successes — a red “export blocked — missing permission” row is the permission system working. Review the log monthly and before any staff departure; if it mattered, it's here.