Building·Launch Dec 31·110d 23h

Features & Community

Community roles & permissions

Access is based on trust, responsibility, demonstrated accuracy, and least privilege. Every elevated action is audited, most are reversible, and none bypass rights, security, evidence, or publication gates.

On this page

Public Visitor

#1

Anyone on the internet, no account needed.

Intended for
The general public, researchers, families, students, and journalists.
How to qualify
No account required — the public archive is free with no paywall.
Can view
Published, source-backed records: people, teams, events, photographs, programs, sources, timelines, and memorials.
Can create
Nothing (read-only).
Can edit
Nothing.
Can review
Nothing.
Can approve
Nothing.
Can publish
Nothing.
Merge / restore
Nothing.

Cannot

  • Submit or edit records
  • See draft, quarantined, or tombstoned material
  • Access review or administrative tools
Not audited

Registered Member

#2

A signed-in community member.

Intended for
People who want to save work and participate as contribution workflows open.
How to qualify
Register an account (public registration itself is currently gated in preview).
Can view
Everything a visitor sees, plus their own account, drafts, and contribution history.
Can create
Personal drafts and permitted member workflows (submission opens when contributions are enabled).
Can edit
Their own drafts.
Can review
Nothing.
Can approve
Nothing.
Can publish
Nothing (no automatic publication authority).
Merge / restore
Nothing.

Cannot

  • Publish anything directly
  • Review or approve others' submissions
  • Access curator or admin tools
Audited

Contributor

#3

A member who submits historical material to the archive.

Intended for
People with photographs, documents, corrections, stories, or identifications to share.
How to qualify
Any member may contribute once the contribution workflow is enabled.
Can view
Their submissions and review status, plus everything a member sees.
Can create
Archive uploads, metadata, source declarations, person/team/event tags, provisional Person proposals, life-date and memorial information, stories, corrections, and identity proposals.
Can edit
Their own submissions, including responding to reviewer send-backs.
Can review
Nothing.
Can approve
Nothing.
Can publish
Nothing — all submissions remain subject to review.
Merge / restore
Nothing.

Cannot

  • Publish their own contributions
  • Approve or reject others' work
  • Bypass rights, security, evidence, or duplicate review
Audited· Secondary review applies

Trusted Contributor

#4

A contributor whose accuracy has been demonstrated through peer review.

Intended for
Reliable contributors with a strong, well-sourced track record (RBAC token: verified_contributor).
How to qualify
Earned through demonstrated accuracy and peer review — never granted automatically by submission count.
Can view
Everything a contributor sees, with a recognized trust status.
Can create
The same rich contributions as a contributor, with greater trust in triage.
Can edit
Their own submissions.
Can review
Limited peer input where assigned; scoped, not global.
Can approve
Nothing by default. Any reduced-review handling is under evaluation and still passes every publication, rights, security, evidence, and duplicate gate.
Can publish
Nothing directly.
Merge / restore
Nothing.

Cannot

  • Auto-publish or bypass any governance gate
  • Override rights, security, or protected canonical facts
  • Escape audit logging or duplicate controls
Audited· Secondary review applies

Subject Reviewer

#5

A scoped reviewer for a specific team, decade, league, or family.

Intended for
Experts trusted to review submissions within a defined subject scope (RBAC token: subject_reviewer).
How to qualify
Invited based on subject expertise and demonstrated reliability.
Can view
Submissions and evidence within their assigned scope.
Can create
Review notes and revision requests within scope.
Can edit
Governed records within their assigned authority.
Can review
Submissions, sources, identity evidence, and duplicates within scope.
Can approve
Specific content types within their scope, per policy.
Can publish
Only within assigned authority and gates.
Merge / restore
Nothing by default.

Cannot

  • Act outside their assigned scope
  • Receive unrestricted administrative access
  • Bypass rights/security/publication gates
Audited· Secondary review applies

Curator

#6

A cross-collection reviewer and content steward.

Intended for
Trained curators responsible for verifying and publishing historical records.
How to qualify
Appointed for demonstrated curatorial care and policy compliance.
Can view
Review queues, submissions, evidence, media presentation, and audit history.
Can create
Corrections and curated records within authority.
Can edit
Governed records; media presentation (primary image, featured order, focal/crop, captions).
Can review
Submissions, sources, identity evidence, Person proposals, and duplicates.
Can approve
Content within curatorial authority after gates pass.
Can publish
Publication-ready, gate-cleared records.
Merge / restore
Person merges within authority (rights overrides remain narrower).

Cannot

  • Manage users or platform configuration
  • Override rights takedowns without the rights role
  • Physically delete records (tombstone only)
Audited· Secondary review applies

Content Manager (Archive Admin)

#7

Senior content governance across the archive.

Intended for
Senior staff overseeing review, publication, and complex historical decisions (RBAC token: archive_admin, distinct from system_admin).
How to qualify
Appointed to senior content-governance responsibility.
Can view
Broad review queues, audit history, and processing/publication state.
Can create
Governed records and corrections at higher authority.
Can edit
Higher-risk historical changes within content governance.
Can review
Curator actions and complex evidence conflicts.
Can approve
Higher-risk historical changes and publication decisions.
Can publish
Across content areas within governance.
Merge / restore
Manage and roll back governed merges.

Cannot

  • Manage system-level configuration reserved for system administrators
  • Access infrastructure, secrets, or security-operations internals
Audited· Secondary review applies

Administrator

#8

Platform administration and governance oversight.

Intended for
System administrators (RBAC token: system_admin; 'admin' is the legacy alias).
How to qualify
Appointed to platform administration.
Can view
Administrative dashboards, audit review, and system reports.
Can create
Platform configuration and governance controls.
Can edit
User and role assignments, feature flags, and content governance.
Can review
Oversight of review, processing, and security state.
Can approve
Publication and configuration controls.
Can publish
Governed platform-wide.
Merge / restore
Governed merges, restores, and rollbacks.

Cannot

  • Physically delete historical records (tombstone only)
  • Bypass audit logging
Audited· Secondary review applies· Can manage users

Platform Governance (Owner)

#9

Ultimate platform stewardship and governance.

Intended for
The platform owner. This tier is derived (admin-class role + owner allowlist), never a stored role.
How to qualify
Reserved for platform ownership.
Can view
Full governance oversight.
Can create
Governance-level decisions.
Can edit
Governance-level configuration.
Can review
Final governance review.
Can approve
Final governance approval.
Can publish
Governance-level.
Merge / restore
Governance-level merges, restores, and rollbacks.

Cannot

  • Physically delete records — the archive is tombstone-only by design
Audited· Can manage users

Growing into more responsibility

  1. 1

    Register as a member.

  2. 2

    Make accurate, well-sourced contributions.

  3. 3

    Build a reliable, peer-reviewed contribution history.

  4. 4

    Complete role-specific guidance where required.

  5. 5

    Receive an invitation or approval for elevated, scoped access.

  6. 6

    Operate within your assigned content area — always subject to audit and role review.

Elevated access is granted on demonstrated reliability, historical care, policy compliance, and community need — never automatically by contribution count.

Permission matrix

Derived from the platform's enforced role model. Owner tier omitted for clarity.

Capabilities by community role
CapabilityPublic VisitorRegistered MemberContributorTrusted ContributorSubject ReviewerCuratorAdministrator
Browse & search the public archiveViewViewViewViewViewViewView
Save drafts & contribution historyNot AvailableEdit Own DraftEdit Own DraftEdit Own DraftEdit Own DraftEdit Own DraftManage
Submit archive material & metadataNot AvailableSubmitSubmitSubmitSubmitSubmitSubmit
Propose identities & new PeopleNot AvailableNot AvailableSubmitSubmitSubmitSubmitSubmit
Review submissions, sources & evidenceNot AvailableNot AvailableNot AvailableNot AvailableReviewReviewReview
Approve or reject contentNot AvailableNot AvailableNot AvailableNot AvailableApproveApproveApprove
Publish recordsNot AvailableNot AvailableNot AvailableNot AvailablePublishPublishPublish
Merge / restore / roll back recordsNot AvailableNot AvailableNot AvailableNot AvailableNot AvailableManageManage
Manage users, roles & feature flagsNot AvailableNot AvailableNot AvailableNot AvailableNot AvailableNot AvailableManage

Governance & accountability

How access is protected

  • Least-privilege access — you get only what your role needs.
  • Server-side authorization enforces every permission, not just the interface.
  • Content-level review boundaries keep authority scoped and appropriate.
  • Audit logging and version history record who changed what, and when.
  • Approval is separated from submission — no one publishes their own work unchecked.
  • Publication-readiness, rights, and security gates must pass before anything goes public.
  • Changes are reversible; records are tombstoned, never physically deleted.
  • Protected canonical fields require evidence-backed review to change.

Role registry last generated 2026-07-02 JST · mirrors enforced authorization.