# S·OS — Administrator Guide

**For:** `hello@caringforno1.com` (the owner/administrator)

You manage **who** joins, **what** they can do, **which licence** they hold, and **every service** on the platform.

## Your console

| What | Where |
|---|---|
| Users & access | `https://app.caringforno1.com/#/admin` (sidebar → Infrastructure & Admin → Admin — Users & Access) |
| Calendar & tasks | `https://app.caringforno1.com/#/calendar` |
| Guides | `https://app.caringforno1.com/#/docs` |
| Analytics | Umami dashboard (user `admin`) |

## Managing users

1. Open **Admin — Users & Access** → **👥 Users**.
2. **Enrol a user:** email + password + role + department → *Add user*. The new person signs in at `caringforno1.com` with that email/password.
3. **Change access level:** pick a new role from the dropdown next to the user — saved instantly. Roles are the access levels (see ROLES-AND-ACCESS.md).
4. **Reset a password:** *Reset password* → enter the new one (min 8 chars) → the user signs in with it.
5. **Remove a user:** *Remove* (you cannot remove yourself).

**Role = access.** `admin` = everything. `operator` = operations. `supervisor`/`case_worker`/`finance_staff` etc. = their department only. Never give `admin` to anyone but the owner.

## Services

- **Monitor / Control** (`#/monitor`, `#/control`) — live health and links for all 130+ services.
- Services enforce roles automatically at the API: admin passes every gate, operators manage most, department roles see their own.
- Embedded service UIs (grafana, bss-oss…) open through the same login — no second password.

## Licences & access notes

- "Licence" = the role + department combination you assign. Keep the matrix in ROLES-AND-ACCESS.md as the company-wide record.
- Department leads: enrol them with their department role (e.g. `supervisor` for a lead) and list their department name in the Department field.

## Calendar alerts

The calendar shows every task with due dates. Tasks due **today** or **overdue** pop up an alert on sign-in and when opening the calendar. Admin/operator can write; other roles are read-only on tasks.
