Admin console and RBAC
The admin console is part of the platform application. It consumes protected REST resources after server-side role authorization; hiding a control in the interface is never a permission boundary.
Role matrix
| Role | Scope |
|---|---|
| Owner | Full access, including billing and team management. |
| Admin | Members, VIP approvals, content, events, moderation, livestream, and operational metrics. |
| Editor | Content and events without billing or VIP-approval authority. |
| Moderator | Community spaces and reports only; other areas remain read-only or forbidden. |
Administrative route groups
/admin/applicationsand its approve/reject actions manage the manual membership-review step./admin/contentcontrols publishing, free/VIP access, and episode metadata./admin/events/:id/checkinhandles attendance and waitlist promotion./admin/messagesand/admin/reportssupport community moderation./admin/live/*,/admin/metrics, and/admin/integrationsoperate the livestream and show secret-free readiness.
Expected failure behavior.
A role without permission receives a safe 403 response. Sensitive changes should create an audit record on the server; clients should display the safe response and refresh authoritative state.