# Web authentication and roles

Public registration is disabled. Web pages require a signed-in account. Password sign-in is throttled after five failed attempts per minute, sessions regenerate after sign-in, and sign-out invalidates the session. Super administrators and administrators can manage accounts at `/admin/users`; invitations create an account and email a time-limited password setup link. Administrators may invite observers, while only super administrators may grant system administrator or election officer roles. Account invitations and resent setup links are audited. Signed-out users can request a reset link at `/password/forgot`, and choose a password at least 12 characters long with upper and lower case letters and a number.

Configure Laravel's mail transport before sending invitations or reset links. In local development, `MAIL_MAILER=log` writes the link to `storage/logs/laravel.log`; production should use the organization's approved mail transport. If delivery fails, the account remains created and an administrator can resend the setup link after fixing mail configuration.

## Provision the first administrator

After configuring the database and applying migrations, create an administrator with a strong password:

```powershell
php artisan migrate
php artisan election:create-user "Election Administrator" admin@example.org --role=super_admin
```

The command prompts for a password twice and requires at least 12 characters. It does not put the password in shell history. To create another administrator, use `--role=admin`; for other account types, use `--role=observer` or `--role=election_officer`. The `election:promote-admin email@example.org` command grants full super administrator access to an existing account.

| Role | Access |
| --- | --- |
| `super_admin` | Full access to all election and campaign information, setup, and review controls |
| `admin` | Manage election master data, campaigns and agent assignments; view only campaign data explicitly assigned to the account |
| `election_officer` | View central dashboards, reports, and review records; no result or review mutations |
| `observer` | View only campaign data granted by campaign membership |

Only users with an active station assignment and the `agent` role in that campaign can submit, through either Livewire or the API. They can submit only for their own assignments and see their own station dashboard. Agents do not see campaign-wide tallies or review records. Other users have read only access to their assigned views; review controls are reserved for the super administrator. Campaign managers and analysts see only campaigns they belong to and the verified contest tally within that campaign's electoral scope. Accounts with no relevant assignment see an access-pending page.
