Access and participants
Roles and administration
What an administrator can do, what they deliberately cannot, and how to promote somebody.
Every account is one of two roles.
| Member | Administrator | |
|---|---|---|
| Create polls | yes | yes |
| Manage their own polls | yes | yes |
| See and manage every poll | no | yes |
| List every account | no | yes |
| Promote, demote, confirm, delete accounts | no | yes |
| See unpublished result totals | no | no |
| Vote in a private poll they were not invited to | no | no |
Member is the ordinary account and what everybody gets on registration. Nothing about it has changed: you own the polls you create and take part in the polls you are invited to.
Administrator additionally administers the platform. There is no ownership or invitation barrier: an administrator reaches every poll, in every phase, including other people's drafts and private polls.
What an administrator can do
See every poll. The poll list gains an extra scope, Everything on this platform, which lists every poll regardless of who owns it. Their own dashboard stays personal — it still shows only what needs them — because a dashboard listing every poll on the platform would be useless.
Manage any poll. Every management screen works on any poll: settings, options, invitations, lifecycle transitions, regenerating the participant link. A banner says plainly when you are looking at a poll as an administrator rather than as its owner.
Manage accounts. The administration area lists every account with what it owns and takes part in, filterable by role, confirmation status and name or email. From an account's page you can:
- change its role, promoting a member or demoting an administrator;
- confirm its email address on the holder's behalf, for when they cannot receive the email;
- delete it, but only if it owns no polls and has taken part in none.
Delete an archived poll permanently. This is the one power an administrator has over a poll that its own owner does not. An owner can archive any poll of theirs that has finished, and restore it — but destroying it, with the votes other people cast in it and its whole audit trail, is not a decision one person takes about other people's participation. See The poll lifecycle.
See platform counts. The overview shows accounts, polls by phase, and participation totals. Archived polls are included, with the archived figure shown separately — a total that fell whenever somebody tidied their dashboard would make this page understate the platform.
Two things an administrator deliberately cannot do
These look like oversights and are not. Both are worth stating clearly.
Seeing results before publication
An administrator cannot see option totals before a poll publishes its results.
This is not a role restriction being applied unevenly — it is the same rule that already applies to the poll's own owner. Result secrecy in Democratia means nobody sees totals early, and the whole design rests on that: the authorization rule refuses, the query that calculates totals refuses to run, and no page contains hidden result markup.
Admitting administrators early would change the promise from "nobody can see totals before publication" to "nobody except an administrator". That is a different product, so it is a decision for whoever runs the installation rather than a default.
Published results, on the other hand, are visible to an administrator on any poll, including private ones they were not invited to. That is the ownership barrier being lifted, which is what the role is for.
Voting in a private poll they were not invited to
An administrator manages polls; they do not thereby acquire the right to add a ballot to a decision they were not part of. Administering and participating are different things, and an administrator who could quietly add a ballot to any private poll would undermine every result on the platform.
If an administrator should vote in a private poll, invite them to it. Then they vote like anybody else, and their ballot is one ballot.
Deleting an account
Only an account that owns no polls and has taken part in none can be deleted. Anything else would orphan a poll or destroy a ballot, and the database refuses it outright.
This is the same retention rule described in Security and privacy: a submitted ballot is never silently destroyed. Removing an account that holds records needs an anonymisation policy — replace the name, keep the ballot — which this release does not implement. The account page explains why a particular account cannot be deleted.
An administrator also cannot delete or demote themselves. Both would let one person lock the platform out of its own administration by accident.
Promoting somebody
From the administration area, open the account and change its role. The change takes effect on their next request and is written to the application log with who made it, so the promotion is attributable after the fact.
There is no way to grant the role through a form, a URL or an API. The role is deliberately not mass
assignable, so adding role=admin to the registration or profile form achieves nothing — a test asserts
exactly that. An administrator can only be made by another administrator, or by whoever set the
installation up.
The first administrator
Every installation begins with one, so that there is somebody able to administer it:
dev@belodigital.com
On a brand-new installation its password is password. Change it on any installation reachable from
outside the machine it runs on — a known-password administrator is a known-password administrator.
Whoever set the installation up can also give it a real password from the start.
Setting an installation up again never resets a password that has since been changed, so the account you are signed in to today keeps working.