Read-only console gallery
Every page of the portal, without live data.
Open each workspace, then each page. This shows layout and role boundaries only. It grants no access and changes no record.
Enterprise organizationRead only
Organization console
Each society keeps its own boundary.
List and open communities in this organization. Provisioning a new one is an identity-sensitive action.
This page
Community list
Names on the live page are this organization’s communities.
| Action | Enterprise | Community admin | Must not |
|---|---|---|---|
| View | Summary cards | Full ops | See another org |
| Open | Jump with scope | Work as themselves | Carry a wrong cookie |
| Provision | Create with evidence | Receive the community | Clone residents |
| Retire | Controlled offboard | Export window | Hard-delete history |
On the live page
Work this role can do
1Open a community console2Compare types without mixing data3Provision only if entitled4Leave a community you should not see
Access boundaries
Least privilege by default
- No merged resident lists
- No silent provision
- MFA for identity actions
Production access
Preview is not permission.
Real consoles appear only after an authorized role, valid scope and required two-step verification are confirmed.