Complete Electoral Workflow
1. Governance authorisation
Before creating records, identify the governing constitution, election regulations, appointing authority, data controller, dispute process, result-approval requirement and retention rule. CivitasVote enforces software controls but does not create legal authority.
2. Platform and association establishment
The technical superuser creates ordinary users and appoints a Platform Administrator. The Platform Administrator creates the association and assigns an Owner/Administrator. The association record defines branding, privacy contact and retention policy.
3. Election-cycle creation
Association governance creates the election, selects the type and nomination mode, defines nomination dates where applicable, sets voting times, approval threshold and verification methods. The cycle begins in Draft.
4. Appointment of election officers
Appoint three distinct core members with PDF letters:
- Commissioner/Chairperson;
- Secretary;
- ICT and Data Protection Commissioner.
Add optional roles according to governance needs. Appointments are cycle-specific, date-bound and independent of voter eligibility.
5. Voter register preparation
Build the register from the association directory, a previous cycle, an import or an empty register. Verify identity, status and active state. Resolve exclusions and objections. Certify the register with an official reference. Certification stores a digest; later changes require recertification.
6. Position and question configuration
Create each office or question. Define kind, seats, maximum selections, order, required status and abstention. Review the complete ballot before candidate publication.
7. Nomination and candidate process
Upload mode
The Commission adds or imports candidates, then supplies photographs and reviews statuses.
Self mode
Eligible voters submit during the nomination window. The Commission places each record under review, approves, rejects or records withdrawal. Approval creates a linked candidate. Unlinked direct candidates are invalid and must be removed.
Mixed mode
Both sources are accepted. The Commission must reconcile duplicates between uploads and public submissions.
None mode
The system skips formal nominations; officers add predetermined candidates or questions.
8. Objections and complaints before voting
Receive public election objections and officer complaints. Assign the competent reviewer, preserve evidence, enforce recusal and document remedies. Candidate or register changes may require candidate-list republication or register recertification.
9. Final candidate-list publication
After nomination closure, complete every Submitted and Under-review decision. Confirm all approved nominations have linked approved photographed candidates, all direct candidates are permitted by mode and each required position has valid candidates. Rejected and withdrawn nominations remain excluded. Publish the final list.
10. Readiness
Resolve every readiness error. The system checks current appointments, letters, register certification and digest, eligible voters, positions, candidates, photographs, candidate-list publication, configuration consistency and other service rules. Record a witnessed mock election.
11. Voter verification
The voter opens the election page and uses an enabled route: one-time code, personal PIN, institutional email, passkey or controlled assistance. Successful verification issues a short-lived voting ticket. Credentials and tickets must not be recorded in notes or disclosed to officers.
12. Ballot submission
The voter completes the single ballot page. The dynamic form enforces required choices, maximum selections and abstention. Submission is irrevocable. The service stores an anonymous envelope and selections without a voter foreign key, marks participation on the eligibility side and returns a receipt.
13. Monitoring and incidents
Officers monitor availability, verification problems, notification delivery and incidents, not selections. Record incidents with factual timestamps. Avoid server or database changes during open voting.
14. Closing and tallying
The Commissioner closes manually or the scheduler closes where auto-close is enabled. Tallying verifies the frozen register and computes candidate/question totals. The snapshot stores ballot count, rejected count, tally data, digest and signature.
15. Reconciliation and recount
Compare ballots with participation markers and investigate discrepancies. A recount requires a reason and creates a new snapshot version; it does not overwrite the original.
16. Independent approval
Authorised current officers record independent approve/reject decisions. The system requires at least the configured count. A person cannot approve twice through the same membership. A blocking rejection must be resolved according to governance and service rules.
17. Publication and reports
Published results appear on the public results page and previous-results archive. Officers may export CSV and certified PDF. The generated declaration includes metadata, results, electronic approvals, incidents/recount statement, official signature blocks, two representative acknowledgement rows per approved candidate, result digest and signature value.
A separately signed declaration may be uploaded to protected storage and served through the controlled public resolver.
18. Post-election disputes
Continue to receive permitted objections and officer complaints. A result challenge may lead to a reasoned recount, correction under authority, cancellation or invalidation. Preserve every prior snapshot and declaration.
19. Final records and access closure
Verify the audit ledger, export governance records, preserve the certified register, nominations, candidate evidence, tally snapshots, approvals, declarations, incidents and disputes. Revoke or allow expiry of officer access. Apply retention only after all holds end.