City of Nagatama
Synthetic demonstration data
Sign in

Security Center

Authorization is evaluated server-side for every privileged action. Controls below are labeled honestly for procurement review: nothing is shown as active unless it genuinely is.

Roles & permissions matrix
Least-privilege grants. This map is the server's source of truth.
PermissionAdministratorRecruiterInvestigatorSupervisorAuditor
applicant.read
applicant.write
applicant.assign
stage.advance
investigation.read
investigation.write
investigation.review
document.read
document.upload
questionnaire.manage
workflow.manage
task.manage
communication.send
report.read
audit.read
security.manage
settings.manage

Administrator

System configuration, roles, workflow, retention and integrations. Full read access.

Recruiter

Owns lead and applicant intake through interview; schedules events and communicates with candidates.

Investigator

Works assigned background segments and evidence. No workflow configuration or role management.

Supervisor

Reviews investigative work, approves command review and offer stages, reads the audit trail.

Auditor

Read-only oversight across records, reports and the audit trail. Cannot modify any record.

Staff accounts & sessions
Synthetic account inventory with last sign-in.
AccountRoleScopeMFALast sign-in
R. Okonkwo
r.okonkwo@nagatama.gov
AdministratorAll departmentsenrolled (demo)Sep 26, 2026, 7:12 AM
T. Lindqvist
t.lindqvist@nagatama.gov
RecruiterPOLICEenrolled (demo)Sep 26, 2026, 6:41 AM
J. Castellanos
j.castellanos@nagatama.gov
RecruiterFIREnot enrolledSep 25, 2026, 9:05 PM
Det. P. Ngata
p.ngata@nagatama.gov
InvestigatorPOLICEenrolled (demo)Sep 26, 2026, 5:58 AM
Det. S. Reyes
s.reyes@nagatama.gov
InvestigatorPOLICEenrolled (demo)Sep 25, 2026, 6:22 PM
Inv. A. Brennan
a.brennan@nagatama.gov
InvestigatorFIREnot enrolledSep 24, 2026, 4:10 PM
Lt. K. Duarte
k.duarte@nagatama.gov
SupervisorPOLICEenrolled (demo)Sep 26, 2026, 4:33 AM
BC L. Fontaine
l.fontaine@nagatama.gov
SupervisorFIREenrolled (demo)Sep 25, 2026, 2:47 PM
C. Mbeki
c.mbeki@nagatama.gov
AuditorAll departmentsenrolled (demo)Sep 23, 2026, 11:02 AM

Active demonstration session: Signed out (Auditor) · session id

Security & integration control status
Demonstration honesty: planned and integration-required controls are not claimed as active.
  • Calendar & Mailbox Syncnot connected

    Microsoft Graph / Outlook / Exchange adapter

    Requires: Tenant ID, application (client) ID and client secret with delegated Calendars.ReadWrite consent.

    Appointments in this demo are stored locally only. No mailbox or calendar traffic occurs.

  • SMS Notificationsnot connected

    SMS provider adapter (Twilio-compatible)

    Requires: Account SID, auth token and a provisioned sending number.

    Outbound SMS in this demo is queued in the UI only and never transmitted.

  • Transactional Emailnot connected

    SMTP / email relay

    Requires: Relay host, credentials and verified sending domain (SPF/DKIM/DMARC).

    Portal notices are displayed in-app for the demonstration.

  • Upload Malware Scanningnot connected

    AV / sandbox scanning service

    Requires: Scanning service endpoint and API credentials.

    Documents display 'Not scanned — integration required'. No scanning is performed in this demo.

  • Single Sign-On (SAML / OIDC)planned / not active

    Agency identity provider

    Requires: IdP metadata, signing certificate and attribute mapping for role claims.

    Demo uses a local role selector; production intent is IdP-issued roles.

  • Multi-Factor Authenticationplanned / not active

    IdP-enforced MFA / authenticator app

    Requires: IdP policy enforcement or authenticator enrollment service.

    MFA enrollment flags shown in Security Center are synthetic.

  • Encryption Key Managementplanned / not active

    Cloud KMS / HSM

    Requires: Key ring, customer-managed key and rotation policy.

    Demo shows integrity hashes only; envelope encryption is not configured.

  • WAF & Rate Limitingplanned / not active

    Edge WAF

    Requires: Edge deployment with managed rule set and rate-limit policy.

    Not active in this demonstration environment.

  • SIEM Log Forwardingplanned / not active

    Agency SIEM

    Requires: Log ingestion endpoint and forwarding credentials.

    Audit events are stored in-app for the demonstration only.

  • Data Loss Preventionplanned / not active

    DLP service

    Requires: Policy set and inspection endpoint.

    No content inspection is performed in this demo.

  • Backups & Disaster Recoveryplanned / not active

    Managed backup / cross-region replication

    Requires: Backup schedule, retention target and tested restore runbook (RPO/RTO agreed).

    Demonstration data resets on reload.

  • Records Retention Exportplanned / not active

    Agency records management system

    Requires: Export format agreement and destination credentials.

    Retention classes are displayed but not enforced in the demo.

Recent security-relevant events
Authentication, permission and export events.