Admin & Operations
Admin Panel
Administrative data and controls are available only after the backend validates an active session, strong owner assurance where required, role assignment, and specific admin capability.
Server authorization required
Owner access path
Use the production owner passkey flow to create a strong owner session before attempting protected operations. Ordinary authentication remains insufficient for privileged access.
Authenticate owner passkeyProtected operations
- Trusted-tester, role, audit, and privileged-session controls require server authorization.
- Live source-health operations are read from the protected API, not from page-local demo data.
- Usage and cost controls remain guarded by the existing capability boundary.
Boundary
UI -> shared API client -> Citizen Authority API