Shadow and Shield / Accounts and Permissions

Accounts, organizations, and permissions.

Shadow and Shield uses users, organizations, roles, permissions, sessions, and defaults to control who configures tools, runs work, and reviews results.

At a Glance

Users, organizations, roles, permissions, and defaults.

This page covers authenticated users, sessions, organization scope, role-based permissions, tool licensing, and per-user defaults for supported platform activity.

01 / Accounts

User accounts.

Shadow and Shield uses per-user accounts across the touchscreen and network dashboard so supported actions can be attributed to authenticated users.

  • PIN-based authentication for touchscreen and dashboard workflows
  • PIN credentials stored as non-reversible hashes
  • Persistent authenticated sessions where supported
  • Account lockout protection for repeated authentication failures
  • Account state and removal behavior where implemented

02 / Sessions

Sessions.

Session records help the system connect authenticated user activity, interface state, and supported tool execution or administrative activity.

  • Session identity and lifecycle
  • User and organization scope
  • Cross-interface authentication behavior where supported
  • Session records stored in the local platform database

03 / Organizations

Organizations.

Organizations provide a structure for visibility, administration, and tool availability. Current deployments use single-level organization records unless a specialized hierarchy is validated.

  • Organization records and optional hierarchy
  • Organization-scoped visibility and filtering
  • Organization settings and default organization behavior
  • Per-organization tool licensing and availability controls where supported

04 / Roles

Roles and permissions.

Roles are named permission sets that determine which protected administrative, network, and workflow actions a user can perform within an organization scope.

  • Role records and role assignment
  • Organization-specific role resolution with global fallback where configured
  • Permission vocabulary based on explicit capability flags
  • Permission checks on protected actions
  • Interface controls can be shown, hidden, disabled, or gated by permissions where supported

05 / Licensing

Tool licensing.

Tool availability can be scoped by organization licensing records and enforced when users configure or run supported tools.

  • Organization-scoped licensing where supported
  • License records and tool availability
  • Enforcement at supported configuration or execution surfaces

06 / Interfaces

Cross-interface authentication.

Authentication behavior can propagate between touchscreen and network-dashboard contexts where supported, while sessions retain user and organization scope.

  • Touchscreen and dashboard authentication behavior where supported
  • Session lifecycle and scope
  • User and organization context retained with supported activity
  • Account and permission records available for review

07 / Defaults

User defaults.

Per-user settings can hold interface preferences, workflow configuration, and Quick Add defaults so technical users and operators can work from saved configurations.

  • Per-user interface preferences where implemented
  • Saved workflow configuration
  • Per-user Quick Add defaults for supported tools
  • Fallback to system tool defaults and database-stored configuration defaults

Keep permission claims tied to implemented roles, organization scope, licensing behavior, and release-supported enforcement.