Features & Community
Community roles & permissions
Access is based on trust, responsibility, demonstrated accuracy, and least privilege. Every elevated action is audited, most are reversible, and none bypass rights, security, evidence, or publication gates.
On this page
Public Visitor
#1Anyone on the internet, no account needed.
- Intended for
- The general public, researchers, families, students, and journalists.
- How to qualify
- No account required — the public archive is free with no paywall.
- Can view
- Published, source-backed records: people, teams, events, photographs, programs, sources, timelines, and memorials.
- Can create
- Nothing (read-only).
- Can edit
- Nothing.
- Can review
- Nothing.
- Can approve
- Nothing.
- Can publish
- Nothing.
- Merge / restore
- Nothing.
Cannot
- Submit or edit records
- See draft, quarantined, or tombstoned material
- Access review or administrative tools
Registered Member
#2A signed-in community member.
- Intended for
- People who want to save work and participate as contribution workflows open.
- How to qualify
- Register an account (public registration itself is currently gated in preview).
- Can view
- Everything a visitor sees, plus their own account, drafts, and contribution history.
- Can create
- Personal drafts and permitted member workflows (submission opens when contributions are enabled).
- Can edit
- Their own drafts.
- Can review
- Nothing.
- Can approve
- Nothing.
- Can publish
- Nothing (no automatic publication authority).
- Merge / restore
- Nothing.
Cannot
- Publish anything directly
- Review or approve others' submissions
- Access curator or admin tools
Contributor
#3A member who submits historical material to the archive.
- Intended for
- People with photographs, documents, corrections, stories, or identifications to share.
- How to qualify
- Any member may contribute once the contribution workflow is enabled.
- Can view
- Their submissions and review status, plus everything a member sees.
- Can create
- Archive uploads, metadata, source declarations, person/team/event tags, provisional Person proposals, life-date and memorial information, stories, corrections, and identity proposals.
- Can edit
- Their own submissions, including responding to reviewer send-backs.
- Can review
- Nothing.
- Can approve
- Nothing.
- Can publish
- Nothing — all submissions remain subject to review.
- Merge / restore
- Nothing.
Cannot
- Publish their own contributions
- Approve or reject others' work
- Bypass rights, security, evidence, or duplicate review
Trusted Contributor
#4A contributor whose accuracy has been demonstrated through peer review.
- Intended for
- Reliable contributors with a strong, well-sourced track record (RBAC token: verified_contributor).
- How to qualify
- Earned through demonstrated accuracy and peer review — never granted automatically by submission count.
- Can view
- Everything a contributor sees, with a recognized trust status.
- Can create
- The same rich contributions as a contributor, with greater trust in triage.
- Can edit
- Their own submissions.
- Can review
- Limited peer input where assigned; scoped, not global.
- Can approve
- Nothing by default. Any reduced-review handling is under evaluation and still passes every publication, rights, security, evidence, and duplicate gate.
- Can publish
- Nothing directly.
- Merge / restore
- Nothing.
Cannot
- Auto-publish or bypass any governance gate
- Override rights, security, or protected canonical facts
- Escape audit logging or duplicate controls
Subject Reviewer
#5A scoped reviewer for a specific team, decade, league, or family.
- Intended for
- Experts trusted to review submissions within a defined subject scope (RBAC token: subject_reviewer).
- How to qualify
- Invited based on subject expertise and demonstrated reliability.
- Can view
- Submissions and evidence within their assigned scope.
- Can create
- Review notes and revision requests within scope.
- Can edit
- Governed records within their assigned authority.
- Can review
- Submissions, sources, identity evidence, and duplicates within scope.
- Can approve
- Specific content types within their scope, per policy.
- Can publish
- Only within assigned authority and gates.
- Merge / restore
- Nothing by default.
Cannot
- Act outside their assigned scope
- Receive unrestricted administrative access
- Bypass rights/security/publication gates
Curator
#6A cross-collection reviewer and content steward.
- Intended for
- Trained curators responsible for verifying and publishing historical records.
- How to qualify
- Appointed for demonstrated curatorial care and policy compliance.
- Can view
- Review queues, submissions, evidence, media presentation, and audit history.
- Can create
- Corrections and curated records within authority.
- Can edit
- Governed records; media presentation (primary image, featured order, focal/crop, captions).
- Can review
- Submissions, sources, identity evidence, Person proposals, and duplicates.
- Can approve
- Content within curatorial authority after gates pass.
- Can publish
- Publication-ready, gate-cleared records.
- Merge / restore
- Person merges within authority (rights overrides remain narrower).
Cannot
- Manage users or platform configuration
- Override rights takedowns without the rights role
- Physically delete records (tombstone only)
Content Manager (Archive Admin)
#7Senior content governance across the archive.
- Intended for
- Senior staff overseeing review, publication, and complex historical decisions (RBAC token: archive_admin, distinct from system_admin).
- How to qualify
- Appointed to senior content-governance responsibility.
- Can view
- Broad review queues, audit history, and processing/publication state.
- Can create
- Governed records and corrections at higher authority.
- Can edit
- Higher-risk historical changes within content governance.
- Can review
- Curator actions and complex evidence conflicts.
- Can approve
- Higher-risk historical changes and publication decisions.
- Can publish
- Across content areas within governance.
- Merge / restore
- Manage and roll back governed merges.
Cannot
- Manage system-level configuration reserved for system administrators
- Access infrastructure, secrets, or security-operations internals
Administrator
#8Platform administration and governance oversight.
- Intended for
- System administrators (RBAC token: system_admin; 'admin' is the legacy alias).
- How to qualify
- Appointed to platform administration.
- Can view
- Administrative dashboards, audit review, and system reports.
- Can create
- Platform configuration and governance controls.
- Can edit
- User and role assignments, feature flags, and content governance.
- Can review
- Oversight of review, processing, and security state.
- Can approve
- Publication and configuration controls.
- Can publish
- Governed platform-wide.
- Merge / restore
- Governed merges, restores, and rollbacks.
Cannot
- Physically delete historical records (tombstone only)
- Bypass audit logging
Platform Governance (Owner)
#9Ultimate platform stewardship and governance.
- Intended for
- The platform owner. This tier is derived (admin-class role + owner allowlist), never a stored role.
- How to qualify
- Reserved for platform ownership.
- Can view
- Full governance oversight.
- Can create
- Governance-level decisions.
- Can edit
- Governance-level configuration.
- Can review
- Final governance review.
- Can approve
- Final governance approval.
- Can publish
- Governance-level.
- Merge / restore
- Governance-level merges, restores, and rollbacks.
Cannot
- Physically delete records — the archive is tombstone-only by design
Growing into more responsibility
- 1
Register as a member.
- 2
Make accurate, well-sourced contributions.
- 3
Build a reliable, peer-reviewed contribution history.
- 4
Complete role-specific guidance where required.
- 5
Receive an invitation or approval for elevated, scoped access.
- 6
Operate within your assigned content area — always subject to audit and role review.
Elevated access is granted on demonstrated reliability, historical care, policy compliance, and community need — never automatically by contribution count.
Permission matrix
Derived from the platform's enforced role model. Owner tier omitted for clarity.
| Capability | Public Visitor | Registered Member | Contributor | Trusted Contributor | Subject Reviewer | Curator | Administrator |
|---|---|---|---|---|---|---|---|
| Browse & search the public archive | View | View | View | View | View | View | View |
| Save drafts & contribution history | Not Available | Edit Own Draft | Edit Own Draft | Edit Own Draft | Edit Own Draft | Edit Own Draft | Manage |
| Submit archive material & metadata | Not Available | Submit | Submit | Submit | Submit | Submit | Submit |
| Propose identities & new People | Not Available | Not Available | Submit | Submit | Submit | Submit | Submit |
| Review submissions, sources & evidence | Not Available | Not Available | Not Available | Not Available | Review | Review | Review |
| Approve or reject content | Not Available | Not Available | Not Available | Not Available | Approve | Approve | Approve |
| Publish records | Not Available | Not Available | Not Available | Not Available | Publish | Publish | Publish |
| Merge / restore / roll back records | Not Available | Not Available | Not Available | Not Available | Not Available | Manage | Manage |
| Manage users, roles & feature flags | Not Available | Not Available | Not Available | Not Available | Not Available | Not Available | Manage |
Governance & accountability
How access is protected
- Least-privilege access — you get only what your role needs.
- Server-side authorization enforces every permission, not just the interface.
- Content-level review boundaries keep authority scoped and appropriate.
- Audit logging and version history record who changed what, and when.
- Approval is separated from submission — no one publishes their own work unchecked.
- Publication-readiness, rights, and security gates must pass before anything goes public.
- Changes are reversible; records are tombstoned, never physically deleted.
- Protected canonical fields require evidence-backed review to change.
Role registry last generated 2026-07-02 JST · mirrors enforced authorization.
