Silicon ZombiesSILICON ZOMBIESDEVELOPER DOCSOpen preview

Platform guide

Admin console

The administrative surface uses the same API with explicit role checks, sensitive-action audit trails, and no client-only permission assumptions.

Admin console and RBAC

The admin console is part of the platform application. It consumes protected REST resources after server-side role authorization; hiding a control in the interface is never a permission boundary.

Role matrix

RoleScope
OwnerFull access, including billing and team management.
AdminMembers, VIP approvals, content, events, moderation, livestream, and operational metrics.
EditorContent and events without billing or VIP-approval authority.
ModeratorCommunity spaces and reports only; other areas remain read-only or forbidden.

Administrative route groups

  • /admin/applications and its approve/reject actions manage the manual membership-review step.
  • /admin/content controls publishing, free/VIP access, and episode metadata.
  • /admin/events/:id/checkin handles attendance and waitlist promotion.
  • /admin/messages and /admin/reports support community moderation.
  • /admin/live/*, /admin/metrics, and /admin/integrations operate the livestream and show secret-free readiness.
Expected failure behavior.

A role without permission receives a safe 403 response. Sensitive changes should create an audit record on the server; clients should display the safe response and refresh authoritative state.