Skip to content

Roles and permissions

Showcase has five editor roles — administrator, author, presenter, front desk and viewer — plus the unauthenticated visitor flows Audience Integrations adds. There is no separate "moderator" role: moderating audience uploads is an administrator or author capability, like the rest of Audience Integrations. Showcase also uses an internal visitor-session role for visitor self-service; it cannot sign in to the Editor or reach any editor feature.

Capability matrix

Capability Administrator Author Presenter Front desk Viewer Visitor with Access QR
Manage public URL and certificates Yes No No No No No
Create/edit connectors and mappings Yes Yes No No No No
Manage named connector credentials Yes Yes No No No No
Preview, dry-run, and run connectors Yes Yes No No No No
Manage Sites (hosted sites) Yes Yes No No No No
Create Personal Folders / Access QR, reset links Yes Yes No No No No
Configure drop zones and the unknown-ID policy Yes Yes No No No No
Add and test Codice Input scan stations Yes No No No No No
Approve or reject audience uploads Yes Yes No No No No
Operate a prepared presentation Yes Yes Yes No No No
Update text-widget content only No No No Yes No No
View one Personal Folder, edit allowed details, upload files for review No No No No No That folder only

Front desk's access is a field-level allowlist for text-widget content, not a whole-route grant, so it sits outside the capabilities above rather than alongside Presenter. Viewer is read-only and has no access to Audience Integrations capabilities at all.

Server policy is authoritative. Hiding a menu item improves usability but is not the security boundary; direct requests from a lower role are rejected as well.

Credentials are not interchangeable

  • An Editor account identifies an operator and inherits that person's role.
  • A named connector credential identifies one outside system. It has an owner, last-use record, rotation path, and revoke action.
  • An Access QR link grants access to one Personal Folder until an operator resets it. It is generated automatically and is not integration authentication.

Never give an editor token or connector credential to a visitor.

Turning Audience Integrations off

Audience Integrations is available by default, but it can be turned off entirely. Set integrations_enabled: false in production_users.yaml, or set the SHOWCASE_INTEGRATIONS_ENABLED environment variable to false, and restart the Showcase server. This removes the Integrations, Sites and Moderation sections from the editor and stops the server from registering the Audience Integrations API routes at all: connectors and push ingest, the Codice event API and drop zones, Codice aliases, scanner device and test routes, Hosted Sites, public assets, Personal Folder access and Access QR links, and audience uploads and moderation. Codice DB stays, and codes still work with physical Codice markers. It is not a routine setting to toggle casually, since it also removes the underlying routes visitors and connectors rely on. See File locations for where production_users.yaml lives on each platform.