Security Center
Authorization is evaluated server-side for every privileged action. Controls below are labeled honestly for procurement review: nothing is shown as active unless it genuinely is.
| Permission | Administrator | Recruiter | Investigator | Supervisor | Auditor |
|---|---|---|---|---|---|
| applicant.read | |||||
| applicant.write | |||||
| applicant.assign | |||||
| stage.advance | |||||
| investigation.read | |||||
| investigation.write | |||||
| investigation.review | |||||
| document.read | |||||
| document.upload | |||||
| questionnaire.manage | |||||
| workflow.manage | |||||
| task.manage | |||||
| communication.send | |||||
| report.read | |||||
| audit.read | |||||
| security.manage | |||||
| settings.manage |
Administrator
System configuration, roles, workflow, retention and integrations. Full read access.
Recruiter
Owns lead and applicant intake through interview; schedules events and communicates with candidates.
Investigator
Works assigned background segments and evidence. No workflow configuration or role management.
Supervisor
Reviews investigative work, approves command review and offer stages, reads the audit trail.
Auditor
Read-only oversight across records, reports and the audit trail. Cannot modify any record.
| Account | Role | Scope | MFA | Last sign-in |
|---|---|---|---|---|
| R. Okonkwo r.okonkwo@nagatama.gov | Administrator | All departments | enrolled (demo) | Sep 26, 2026, 7:12 AM |
| T. Lindqvist t.lindqvist@nagatama.gov | Recruiter | POLICE | enrolled (demo) | Sep 26, 2026, 6:41 AM |
| J. Castellanos j.castellanos@nagatama.gov | Recruiter | FIRE | not enrolled | Sep 25, 2026, 9:05 PM |
| Det. P. Ngata p.ngata@nagatama.gov | Investigator | POLICE | enrolled (demo) | Sep 26, 2026, 5:58 AM |
| Det. S. Reyes s.reyes@nagatama.gov | Investigator | POLICE | enrolled (demo) | Sep 25, 2026, 6:22 PM |
| Inv. A. Brennan a.brennan@nagatama.gov | Investigator | FIRE | not enrolled | Sep 24, 2026, 4:10 PM |
| Lt. K. Duarte k.duarte@nagatama.gov | Supervisor | POLICE | enrolled (demo) | Sep 26, 2026, 4:33 AM |
| BC L. Fontaine l.fontaine@nagatama.gov | Supervisor | FIRE | enrolled (demo) | Sep 25, 2026, 2:47 PM |
| C. Mbeki c.mbeki@nagatama.gov | Auditor | All departments | enrolled (demo) | Sep 23, 2026, 11:02 AM |
Active demonstration session: Signed out (Auditor) · session id
- Calendar & Mailbox Syncnot connected
Microsoft Graph / Outlook / Exchange adapter
Requires: Tenant ID, application (client) ID and client secret with delegated Calendars.ReadWrite consent.
Appointments in this demo are stored locally only. No mailbox or calendar traffic occurs.
- SMS Notificationsnot connected
SMS provider adapter (Twilio-compatible)
Requires: Account SID, auth token and a provisioned sending number.
Outbound SMS in this demo is queued in the UI only and never transmitted.
- Transactional Emailnot connected
SMTP / email relay
Requires: Relay host, credentials and verified sending domain (SPF/DKIM/DMARC).
Portal notices are displayed in-app for the demonstration.
- Upload Malware Scanningnot connected
AV / sandbox scanning service
Requires: Scanning service endpoint and API credentials.
Documents display 'Not scanned — integration required'. No scanning is performed in this demo.
- Single Sign-On (SAML / OIDC)planned / not active
Agency identity provider
Requires: IdP metadata, signing certificate and attribute mapping for role claims.
Demo uses a local role selector; production intent is IdP-issued roles.
- Multi-Factor Authenticationplanned / not active
IdP-enforced MFA / authenticator app
Requires: IdP policy enforcement or authenticator enrollment service.
MFA enrollment flags shown in Security Center are synthetic.
- Encryption Key Managementplanned / not active
Cloud KMS / HSM
Requires: Key ring, customer-managed key and rotation policy.
Demo shows integrity hashes only; envelope encryption is not configured.
- WAF & Rate Limitingplanned / not active
Edge WAF
Requires: Edge deployment with managed rule set and rate-limit policy.
Not active in this demonstration environment.
- SIEM Log Forwardingplanned / not active
Agency SIEM
Requires: Log ingestion endpoint and forwarding credentials.
Audit events are stored in-app for the demonstration only.
- Data Loss Preventionplanned / not active
DLP service
Requires: Policy set and inspection endpoint.
No content inspection is performed in this demo.
- Backups & Disaster Recoveryplanned / not active
Managed backup / cross-region replication
Requires: Backup schedule, retention target and tested restore runbook (RPO/RTO agreed).
Demonstration data resets on reload.
- Records Retention Exportplanned / not active
Agency records management system
Requires: Export format agreement and destination credentials.
Retention classes are displayed but not enforced in the demo.