Voting Operations Guide
1. Opening
Only the current Commissioner uses the controlled Open action. The service verifies readiness, certified register and fingerprints, freezes the eligible-register snapshot and records the action.
2. Voter journey
The voter opens the public election page, verifies eligibility through an enabled method, receives a short-lived voting ticket, completes one ballot page, reviews choices and submits once. The receipt should be saved privately.
3. Support
Polling/verification officers may explain navigation and help with accessibility, but must not:
- ask how the voter intends to vote;
- observe or record selections;
- retain PINs, codes or tickets;
- operate as a proxy;
- reuse a device session without clearing it safely.
4. Monitoring
Monitor application availability, verification failures, notification delivery, rate limits, database health, disk space and incidents. Do not inspect ballot selections for operational curiosity.
5. Incidents
Record reference, title, description, severity, reporter, time and resolution. Preserve logs and screenshots where lawful. Escalate suspected compromise immediately and avoid undocumented server changes.
6. Closing
The Commissioner closes manually or the scheduler closes where auto-close is enabled. Confirm the status before tallying. A voter who has not submitted before closure cannot complete the ballot afterwards.
7. Election-day prohibitions
Do not deploy code, migrate schema, edit voter/candidate records, rotate keys, delete files or change server time during open voting. Every exceptional action requires governance authority and evidence.