← System Documentation Election setup

Election officers and appointments

Appoint the three core members, add optional roles, protect letters and understand access expiry.

Election Officer and Appointment Guide

1. Appointment basis

Every election role is assigned to an authorised user for a specific election cycle. A person does not need to be in the voter directory or register. A voter does not become an officer automatically.

2. Core and optional roles

The mandatory software core is three distinct people: Commissioner/Chairperson, Secretary, and ICT and Data Protection Commissioner. Deputy, Gender and Inclusion, Appeals, Returning, Registration, Polling, Observer, Auditor and general Committee roles are optional.

3. Appointment record

Each appointment should contain:

  • active authorised user;
  • role;
  • official reference;
  • start and end dates;
  • protected PDF appointment letter;
  • active state;
  • appointing user;
  • revocation details where applicable.

The application records the letter filename, upload time and SHA-256 digest.

4. Access states

  • Future: no operational access yet.
  • Current: normal authorised access.
  • Read-only grace: limited inspection for seven days after end where the page permits it.
  • Expired: no access.
  • Revoked: immediately inactive.

Read-only grace never permits configuration, candidate deletion, nomination decisions, poll control or result approval.

5. Separation rules

Use three different people for the core roles. Do not combine Commission and Appeals duties for the same person in the same cycle. The accused officer cannot review their own complaint. The Commissioner cannot appoint themselves through the Commission workflow.

6. Officer conduct

Officers must use named accounts, keep credentials private, avoid viewing ballot choices, preserve evidence, document incidents, follow POST-only controls and stop work when access expires. Support during verification must not become proxy voting.

7. Revocation

Governance uses the revocation action with a specific reason. Revocation preserves the appointment record and audit history. Do not delete an appointment to hide prior authority.

8. Troubleshooting

Permission denied usually means wrong election, inactive user, missing role, future/expired dates, revocation or a page outside the role’s permission list. Correct the appointment rather than granting superuser status.

Continue the procedure