Roles and permissions
Showcase has five editor roles — administrator, author, presenter, front desk and viewer — plus the unauthenticated visitor flows Audience Integrations adds. There is no separate "moderator" role: moderating audience uploads is an administrator or author capability, like the rest of Audience Integrations. Showcase also uses an internal visitor-session role for visitor self-service; it cannot sign in to the Editor or reach any editor feature.
Capability matrix
| Capability | Administrator | Author | Presenter | Front desk | Viewer | Visitor with Access QR |
|---|---|---|---|---|---|---|
| Manage public URL and certificates | Yes | No | No | No | No | No |
| Create/edit connectors and mappings | Yes | Yes | No | No | No | No |
| Manage named connector credentials | Yes | Yes | No | No | No | No |
| Preview, dry-run, and run connectors | Yes | Yes | No | No | No | No |
| Manage Sites (hosted sites) | Yes | Yes | No | No | No | No |
| Create Personal Folders / Access QR, reset links | Yes | Yes | No | No | No | No |
| Configure drop zones and the unknown-ID policy | Yes | Yes | No | No | No | No |
| Add and test Codice Input scan stations | Yes | No | No | No | No | No |
| Approve or reject audience uploads | Yes | Yes | No | No | No | No |
| Operate a prepared presentation | Yes | Yes | Yes | No | No | No |
| Update text-widget content only | No | No | No | Yes | No | No |
| View one Personal Folder, edit allowed details, upload files for review | No | No | No | No | No | That folder only |
Front desk's access is a field-level allowlist for text-widget content, not a whole-route grant, so it sits outside the capabilities above rather than alongside Presenter. Viewer is read-only and has no access to Audience Integrations capabilities at all.
Server policy is authoritative. Hiding a menu item improves usability but is not the security boundary; direct requests from a lower role are rejected as well.
Credentials are not interchangeable
- An Editor account identifies an operator and inherits that person's role.
- A named connector credential identifies one outside system. It has an owner, last-use record, rotation path, and revoke action.
- An Access QR link grants access to one Personal Folder until an operator resets it. It is generated automatically and is not integration authentication.
Never give an editor token or connector credential to a visitor.
Turning Audience Integrations off
Audience Integrations is available by default, but it can be turned off
entirely. Set integrations_enabled: false in production_users.yaml, or
set the SHOWCASE_INTEGRATIONS_ENABLED environment variable to false, and
restart the Showcase server. This removes the Integrations, Sites and
Moderation sections from the editor and stops the server from registering
the Audience Integrations API routes at all: connectors and push ingest,
the Codice event API and drop zones, Codice aliases, scanner device and test
routes, Hosted Sites, public assets, Personal Folder access and Access QR
links, and audience uploads and moderation. Codice DB stays, and codes
still work with physical Codice markers. It is not a routine setting to
toggle casually, since it also removes the underlying routes visitors and
connectors rely on. See File locations
for where production_users.yaml lives on each platform.