Administration interfaces
Three separate workspaces distinguish running a verification, setting enterprise policy and operating the global platform.
Interface boundaries
| Interface | Audience | Responsibilities |
|---|---|---|
| Organiser console | Event owner | Create, invite, monitor controls and export a report. |
| Enterprise administration | Customer administrators | Tenant users, devices, policies, integrations and audit. |
| Platform administration | Easytiou maintainers | Countries, providers, security baseline, resilience and global monitoring. |
Organising a meeting grants no fleet-management permission. Administering an enterprise never allows changes to global providers or the Easytiou security baseline.
Organiser console
The console is designed for screen sharing at the start of a meeting while remaining secondary to the signed state received on each participant’s phone.
- Create an event, define dates and select the required level.
- Invite participants and monitor identity and presence states.
- Start authorised controls and display their progress.
- Receive actionable alerts without disclosing reporters.
- Complete the event and create an audit report.
A projection can be forged. Each participant must be able to compare it with the official state delivered directly to their application.
Enterprise administration
Users and groups
Directory synchronisation, delegated roles and assigned policies.
Inventory and revocation
Compliance, suspension, loss, theft and immediate revocation.
Policies and certificates
Group requirements, enterprise public trust anchors and pre-publication simulation.
SIEM and audit
Approved destinations, delivery tracking, logs and exports.
An enterprise policy may strengthen the Easytiou baseline, never weaken it. Organisation context is derived from the session; a tenant identifier sent by the browser is not sufficient authorisation.
Proposed enterprise roles
| Role | Main scope |
|---|---|
TENANT_OWNER | Tenant governance and administrator appointment. |
TENANT_SECURITY_ADMIN | Policies, certificates, MDM and incidents. |
TENANT_DEVICE_ADMIN | Device inventory, suspension and revocation. |
TENANT_SIEM_ADMIN | SIEM destinations, formats, filters and tests. |
TENANT_EVENT_ADMIN | Event rules within published constraints. |
TENANT_AUDITOR | Read-only access to policies, revocations and logs. |
Sensitive actions require step-up authentication and may require dual approval. Final roles will be released with the stable API.
Suspension and revocation
- The administrator selects a device and structured reason.
- Step-up authentication confirms the sensitive action.
- The server invalidates sessions and prevents new protected operations.
- Active verifications are stopped or made inconclusive.
- The decision is propagated to integrations and recorded in the audit log.
Suspension is reversible after review. Key revocation is final; re-enrolment creates a new binding. Historical evidence preserves the status known when it was issued.
Platform administration
The maintainer workspace configures countries, identity and timestamp providers, assurance mappings, availability and failover policies. It is isolated from customer tenants and reserved for specialised internal roles.
- Secrets stay in a vault and are never displayed in clear text.
- Production changes are versioned, attributable and audited.
- Critical operations enforce separation of duties.
- Provider failover must never artificially increase the achieved level.
- Support access is limited, temporary and logged.
Try “device”, “role” or “revocation”.
