ZEVR

Admin

Start at Today. Every screen checks your permissions on the server, so a link here only means the screen exists, not that you can act on it.

Operator tools

These act. They do not navigate.

Each one is authorized on the server and written to the audit trail. Several are destructive, and several require a second approver who is not you.

Session

Local probes — development only

Blocked outside local/test environments.

Person profile (read_any)

Account tier (privileged + dual approval)

Account status (lock / disable / re-enable)

Org OS offboarding (SOT §30 — disable + revoke)

Disables the account and revokes sessions with OFFBOARDING. Discord role removal stays Privileged Sync /offboard (EOS).

Membership status (staff + dual approval)

Revoke session (revoke_any)

Audit trail (audit.record.read)

Ops verify-controls (R-01)

Re-attack audit immutability after interactive migrator DDL. Requires privileged + step-up + ops.controls.verify grant.

CMS refuse drills (handoff §8 / SOT §29)

Expected: HTTP 403 with distinct reason_codes. These edges exist so CMS cannot pretend to own later-batch domains.

authorize(): person-profile · accounts/tier · accounts/status · membership/status · sessions/revoke · audit · ops/verify-controls · cms-forbidden refuse drills · local: elevate-staff / step-up