PROTOTYPE Clickable mockup · simulates the finished app ◃ Product overview
Petanque Life Operator Console
Production OP

User directory

Search every user across every tenant, act on accounts with reason + fresh authentication, and run consent-gated impersonation. All actions run through the normal API — no backdoors — and everything is audited.

Cross-tenant search · email, name, license number, phone, user id · F21.06.01
NameEmailLicenseTenant · rolesStatus
Astrid Sjöberg astrid@nordvikpetanque.se SWE-10442 Nordvik Boule · player, club_admin active Open detail →
Astrid Sjöberg a.sjoberg@gmail.example SWE-10442 Sjöstad PK · player active Open detail →
Håkan Lindqvist hakan@granholmpk.se SWE-08211 Granholm PK · referee locked Open detail →
Marie Dubois marie@petitcochonnet.fr FRA-33108 Boule Provence · federation_admin soft-deleted (12 d left) Open detail →
Merge duplicate users · preview → confirm/cancel · audited · F21.06.08
Merge preview: 2 tenant memberships re-linked · 1 duplicate license consolidated (SWE-10442) · 3 sessions revoked on duplicate · audit trail records operation_id.
fresh-auth < 5 min
States
⏳ Searching all tenants…
📭 No user matches "astrid" — try license number or phone.
⚠ Search failed. Retry.
Profile · memberships · devices · OAuth · support history · F21.06.02
Astrid Sjöberg
astrid@nordvikpetanque.se · SWE-10442 · sv · created 2024-03-11
active
Memberships: Nordvik Boule (player, club_admin) · Sjöstad PK (player)
Linked OAuth: Google · BankID
Devices: iPhone 15 (last 8:15) · MacBook (last 30 Jun)
Open tickets: #4471 (license question)
Support history: 4 tickets · 2 impersonations · 1 refund
2FA: WebAuthn (2 passkeys)

Lock shows "contact support" at login (F21.06.04). Soft-delete anonymizes PII, is recoverable 30 d, then hard-deletes (F21.06.05). Every button prompts for a reason.

Account recovery · reason + fresh-auth per action · F21.06.03
fresh-auth < 5 min
Active sessions · revoke one or all-but-current · F21.06.07
DeviceIP · locationLast activity
iPhone 15 · app83.94.x.x · Stockholm4 min ago
MacBook · web83.94.x.x · Stockholm30 Jun
Effective-state inspector · 60 s cache · anomaly rules · F21.06.09
2 anomalies
• Login from new IP (30 d lookback) — today 08:15
• Failed-login spike: 3 in 24 h
Capabilities (Nordvik): member:read, competition:register, club:admin…
Feature flags: league_play on · courses off · groups on
Experiments: onboarding-checklist-v2 → variant B
Pending ops: license renewal payment (awaiting Swish)
Open support grants: SG-2214 (view, 41 min left)
Billing: license 350 SEK paid · no dunning

Read is audited as sys.user.effective-state.view.

Per-user timeline · 9 source collections, no new event store · F21.06.10
allsessionsauditgrantsimpersonationinvoicesincidentslegalfailed logins
2 Jul 10:41 impersonation Session started by maria.ek (grant SG-2214, view)
2 Jul 08:15 session Login iPhone · Stockholm · new IP flagged
1 Jul 19:02 invoice License invoice INV-8839 paid · 350 SEK
30 Jun 07:44 failed_login 3 failed attempts · then success
28 Jun 12:00 legal Accepted ToS v3.2
24 Jun 16:31 support Grant SG-2208 approved by user

Paginated (default 100, max 500) · rows drill into audit / incident / invoice / grant detail.

IMPERSONATING Astrid Sjöberg (astrid@nordvikpetanque.se) grant SG-2214 · view · ticket #4471 · auto-exit in 27:14

Non-dismissable, fixed top across the whole screen (F21.02.03). Max 30 min consent-gated / 15 min break-glass, countdown the last 5 min (F21.02.04). One session per operator, per target and per grant — a second attempt returns 409 (F21.02.10). Target is notified by e-mail after exit (F21.02.08). Read-full fidelity: the operator sees exactly what the target sees (F21.02.06).

Support-access grants · consent envelope, state machine pending → granted/denied → used/revoked/expired · F21.02a
GrantTarget userLevelTicketStatusNote
SG-2214 Astrid Sjöberg view #4471 granted expires in 41 min Impersonate →
SG-2213 Håkan Lindqvist interactive #4468 pending requested 10 min ago
SG-2211 Marie Dubois full #4460 denied user denied 1 h ago
SG-2208 Astrid Sjöberg view #4451 used exited 2 Jul 09:12
SG-2201 Pierre Marchand interactive #4449 revoked revoked by user (2 s propagation)
SG-2195 Ove Granlund view #4432 expired sweep job flipped it

Access levels: view (read-only, strict PII redaction) · interactive (writes inside guardrails) · full (no PII redaction) — credential/money/legal guardrails remain at every level (F21.02a.02). Rate limits: 3 pending per ticket, 10 requests/operator/hour, 3 denials per user per 24 h (F21.02a.05). User approves in email + in-app + push (F21.02a.09); expiry sweep runs every minute (F21.02a.08).

Request new grant / start impersonation · F21.02a.03 · F21.02.01
fresh-auth < 5 min sys_support / sys_engineer
Break-glass · consent skipped, sys_security only · F21.02a.06
Emergency access without consent. Requires a second admin (≠ requestor) + TOTP approval code, 15-min hard cap, forced user notification, dedicated banner badge.
Write guardrails · blocked at every level · F21.02.05
Change password / MFA / e-mail / recovery codes
Approve money movement or payouts
Accept legal documents on behalf of the target
Grant or change roles
Delete the account

API rejects with 403 impersonation_write_blocked; view-level rejects every non-GET with 403 grant_view_only; user revoke propagates within 2 s (401 grant_revoked).

Impersonation history · also visible to the user in the app · F21.02.09 · F21.11.05
maria.ek → Astrid Sjöberg2 Jul 09:02–09:12
view · grant SG-2208 · ticket #4451 · 14 reads · 0 writes
jonas.holm → Håkan Lindqvist28 Jun 14:11–14:26
interactive · grant SG-2144 · ticket #4390 · 31 reads · 3 writes
maria.ek (break-glass) → Marie Dubois12 Jun 10:44–10:51
sys_security · two-admin TOTP · 15 min cap · 9 reads · 0 writes
Test session — "login as self in role X" · sandbox tenant · F21.02.11
SANDBOX — not real data. This amber bar is shown in admin and app for the sandbox tenant (F21.03.04).
Create sandbox user · every attribute · F21.03.01
Preset scenarios · one-click spawn · F21.03.02
Current sandbox users
UserProfile2FACreated
test-player-01@sandboxplayer · sv · license active2FA offspawned 1 h ago
test-clubadmin-02@sandboxclub_admin · sv · pending approvals2FA onspawned 3 h ago
test-fedadmin-01@sandboxfederation_admin · en · open incidents2FA onspawned yesterday
Throttled to once per hour · audit-logged (F21.03.03)
Catch-all mail inbox · sandbox e-mail never reaches real recipients · F21.03.05
test-player-01@sandbox Welcome to Nordvik Boule (sandbox) 10:22
test-clubadmin-02@sandbox Your approval queue digest 09:10
test-player-01@sandbox License payment receipt yesterday
Open a mail to inspect rendered content, headers and links.