Role matrix
Every role is a vetted adult. Permissions are least-privilege by default: nobody, including a partner administrator, can read a child-level record or a sealed story, because those surfaces do not exist in this product.
—
| Capability |
|---|
Approvals inbox
Requests queue to the role that owns them. Approving here changes state in this session; anything touching BRAVE content or public statements is blocked at the gate and cannot be approved by anyone in the prototype.
Materials versioning
Container records only. Each row is a delivery wrapper — a slot that will hold a partner-supplied approved item. Publishing a new version supersedes the old one and the old one stays visible, so a leader who printed last month's copy can see what changed.
| Wrapper | Triple Lens | Version | Published | State | Supersedes | Content | Delivery |
|---|
Attendance
Three states only: present, absent, excused. No commentary field, no behaviour rating, no ranking. First name and age band are the only participant fields, and guardian consent state gates whether a row can be marked at all.
| Participant | Age band | Guardian consent | Mark | Recorded |
|---|
Participants are shown as a first name and an age band. That is the whole child record in this product: no surname, no address, no photo, no contact detail, no notes. Rows without guardian consent cannot be marked and are excluded from every count.
Incidents & escalation
Severity decides the route and the clock. A leader records what happened and who was told — never an interpretation, and never the identity of a young person in free text.
Severity routing table
| Severity | Route | Acknowledge within | Session |
|---|
Incident log
| Ref | Triple Lens | Club | Category | Severity | Routed to | State |
|---|
Audit trail
Append-only. Every approval, version publication, attendance change, incident route and policy refusal writes a line. Lines cannot be edited or deleted from the console — the filter below only changes what you are looking at.
An export request is itself an audited event, recording the requester, scope and reason. In this prototype the export produces nothing: the data-responsibilities item on the partnership gate is unsigned, so no data may leave the system.