Product · Officer portal

Run the process. Never cast the ballot.

The portal is for administrators, clerks, and officers: systems, membership, procedure packs, decisions, evidence, tallies, and audit. It has no Mode B cast API surface for ballots.

Membership & officers

Bootstrap first officer, appoint others, dual-control proposals when the pack requires it, bind tokens with share card / QR, TOTP for high-assurance packs.

Decisions & deliberation

Draft or live create, min-argue windows, emergency open when policy allows, arguments, community notes, options, lifecycle open / close / extend / void.

Integrity operations

Log browser with presets, roll commitment view, tallier share handling for open ceremony, audit pack download, public hub links.

Branding & packs

Apply procedure packs, edit governance settings, theme tokens for civic teal / horizon / parchment (and custom brands).

What the portal must never do

  • Accept or submit a ballot without a device signature
  • Let an admin assign privileged roles to themselves
  • Silently rewrite the append-only log

Stack: React, Vite, TypeScript. Talks to the Go API (VITE_API_BASE).