Manage staff accounts and permission roles.
| User | Role | Last Login | Status | Actions | |
|---|---|---|---|---|---|
TJ Tyrell Johnson | t.johnson@s2s.org | Admin | Today, 8:30 AM | Active | |
DW Dr. Williams | d.williams@s2s.org | Facilitator | Today, 9:45 AM | Active | |
MC M. Chen | m.chen@s2s.org | Facilitator | May 17 | Active | |
SA Sarah Adams | s.adams@s2s.org | Staff | May 12 | Inactive |
Departments
Departments group staff for assignment routing and department-scoped permissions.
| Department | Lead | Members | Scope | Actions |
|---|---|---|---|---|
| Intake | Sarah Adams | 5 | New-client onboarding, eligibility, enrollment | |
| Client Success | Dr. Williams | 8 | Ongoing case management, sessions, retention | |
| Marketing | M. Chen | 3 | Outreach, webinars, communications campaigns | |
| Billing | Tyrell Johnson | 2 | Invoicing, payments, accounting reconciliation |
Roles & Permissions
Representative catalogFine-grained view / create / edit / delete permissions per widget & table, gated by role — the same feature-flag/gating model used for provider tiers. Toggle a cell to grant or revoke; changes are audit-logged.
| Resource (widget / table) | View | Create | Edit | Delete | Department gate |
|---|---|---|---|---|---|
Clients clients table / Add-client action |
Intake onlyAdd-client (create) limited to Intake dept (A5) | ||||
Schedule schedule table / session widget |
All departments | ||||
Evaluations evaluations table / eval widget |
Client Success | ||||
Accounting / Invoices accounting table / invoice widget |
Billing | ||||
Victim Info client-detail victim panel (sensitive) |
Restricted — access audit-logged | ||||
Letters / Reports letters table / reports widget |
All departments | ||||
Admin & Users user table / roles & permissions |
Admin role only |
⚑ PENDING — Canonical permission catalog
The matrix above is a representative sample. S2S still owes the canonical list of resources (exact widgets/tables) × actions (view/create/edit/delete), and the default grant per role/department. Confirm: full resource enumeration, which actions exist per resource, and the baseline grants for Staff / Facilitator / Accounting / Compliance / Admin.
Role / Permission Audit
Point-in-time report of who holds which role & department, plus the change history of permission grants/revokes over the matrix above.
| Role | Users assigned | Department gate | Last permission change |
|---|---|---|---|
| Admin | ⚡ Pending S2S | All departments | May 21, 4:30p · T. Johnson |
| Facilitator | ⚡ Pending S2S | Client Success | May 19, 10:12a · T. Johnson |
| Accounting | ⚡ Pending S2S | Billing | — |
| Compliance | ⚡ Pending S2S | All departments | — |
| Staff | ⚡ Pending S2S | Intake | — |
Permission change history
⚡ PENDING — Audit data feed
Per-role headcounts and the full permission change history are placeholders. S2S owes the canonical role/department roster (and therefore real assignment counts) and the audit-event feed that backs the change history. Structure ships; counts and events do not.
Agency Hierarchy Configuration
Parent agencies own child sub-agencies; children inherit parent config unless overridden.
Platform Metrics
Admin-level counts across the whole platform. Values resolve once the master metrics list is finalized.
Users
Active
⚡ Pending S2S
Onboarded
⚡ Pending S2S
Deactivated
⚡ Pending S2S
Platform totals
Total providers
⚡ Pending S2S
Total agencies
⚡ Pending S2S
Total states
⚡ Pending S2S
⚡ PENDING — Master metrics list
No values are fabricated. The panel ships the structure for the admin counts S2S asked for (Users: active / onboarded / deactivated; totals: providers / agencies / states), but the metric definitions and counting rules are blocked on Michael's master metrics list (the same list that gates the marketing/CCM metric set). System/server monitoring is intentionally excluded by design.
Organization
Notifications
Staff One-Time Password (OTP)
Generate a temporary single-use code for staff login / account recovery.
Twilio 10DLC Campaign
RegisteredOut of Scope (by design)
- Server monitoring is intentionally excluded — owned by DevOps tooling (GAP #32).
- Embedded low-level admin tools (DB console, raw queue board) are intentionally excluded from this portal (GAP #39).
Zoom
Webinar meetings
Stripe
Payment processing
Twilio
SMS notifications
HubSpot
CRM sync
HubSpot Custom Objects & Data Origin
Audit tracks which records originate in HubSpot vs locally. 6 custom objects under evaluation for canonical ownership.
| Object | System of Record | Status |
|---|---|---|
| Contact | HubSpot | Synced |
| Enrollment (custom) | Local | Evaluating |
| Referral (custom) | Local | Evaluating |
Failed Login Attempts
Who / when / where, broken down by user type. Repeated failures from one source are flagged.
| When | Who (attempted identity) | User type | Where (IP / location) | Reason |
|---|---|---|---|---|
| May 22, 7:58a | m.chen@s2s.org | Staff | ⚡ IP / location pending S2S | Bad password |
| May 21, 11:46p | AC-7823 (client) | Client | ⚡ IP / location pending S2S | Account locked (5 attempts) |
| May 21, 3:12p | officer@alameda.gov | Agency officer (CCM) | ⚡ IP / location pending S2S | Expired OTP |
| May 20, 6:03a | unknown@— | Unknown | ⚡ IP / location pending S2S | No matching account · repeated |
⚡ Pending S2S — these rows are structure-only. The real failed-attempt feed (per-source IP + geolocation, the lockout threshold, and the canonical user-type list) is owed before any live data renders.
Records flow through 5 lifecycle stages. Retention is 7 years per cohort after completion.
Operational
Active records
Research
De-identified analysis
Retention
Cold storage
Expiration
Scheduled purge
Long-term
Legal hold archive
Cohort Retention
| Cohort | Stage | Records | Purge Date (7yr) |
|---|---|---|---|
| 2026 Active | Operational | 1,847 | — |
| 2024 Cohort | Research | 3,210 | Dec 2031 |
| 2018 Cohort | Expiration | 2,904 | Jun 2026 |
Queue Workers
15/16 up
Pending Jobs
128
Failed (24h)
7
Avg Latency
240ms
BullMQ Queue Workers (16)
| Worker | Pending | Failed | Status |
|---|---|---|---|
| notifications | 42 | 2 | Running |
| hubspot-sync | 42 | 3 | Running |
| zoom-attendance | 31 | 0 | Running |
| billing-color-engine | 13 | 2 | Stalled |