Multi-Level Admin Capabilities

The problem

Many SeaSketch projects run for years. Over that time, the list of project administrators tends to grow. Today, every administrator has the same powers: they can change anything in the project, including map layers, sketching tools, reports, forums, surveys, and user management.

In practice, people are invited as admins for very different reasons:

  • A small number of people are true project leads. They need full control and are responsible for how the project is set up.
  • Government partners or other stakeholders are sometimes invited mainly as a symbolic recognition of their role. They should appear as administrators, but are not expected to reconfigure the project.
  • Contractors and specialists often have a narrow job — for example, uploading data and designing map styles — and should not be able to change sketching tools, publish reports, or download survey results that may contain personal information.

A single admin role works well for many projects. For others, it creates a risk of unwanted changes or inappropriate access to sensitive data.

What this feature would do

Projects could opt into a more flexible admin model. Instead of a single “administrator” switch, a project would have:

Project Owners — a small set of people with full control. They can do everything an admin can do today, and they are the only ones who can decide who else gets which responsibilities.

Capabilities — specific powers that can be granted, such as editing map layers, publishing those layers, managing users, designing surveys, or exporting survey responses. Each capability unlocks a clear part of the admin dashboard.

Roles — ready-made bundles of capabilities that match common staff types (for example Data Manager or Community Manager). Owners can assign a role as a starting point, then add or remove individual capabilities when someone needs a custom mix.

This feature would be opt-in

A capabilities model gives more control, but it also adds real complexity to day-to-day project administration. Large cloud platforms (for example AWS IAM) use a similar approach, and keeping permissions straight can become a full-time job. Project Owners would need to decide who gets which roles and capabilities, debug cases where someone doesn't have the right capabilities to do their work, and periodically review whether those assignments still make sense. That overhead is why multi-level admin access would be optional.

Suggested roles

These roles are starting points for common situations on SeaSketch projects. Project Owners hold every capability plus the exclusive powers listed later — they are not shown as a “role” below.

Roles are flexible. If a VIP should also help with survey invites, an Owner can add surveys.facilitate without creating a new role. The person’s access is simply that role plus the extra capability.

VIP

For government partners and other stakeholders who should follow project activity and preview upcoming map layers, without the ability to make drastic edits.

activity.viewlayers.view_draft

Data Editor

For contractors or staff who upload data, maintain metadata, and design map styles. They work in the draft layer list; someone else decides when changes go live.

layers.view_draftlayers.edit

Data Manager

For a trusted data lead: everything a Data Editor can do, plus publishing layers and managing the geographies used for clipping and analysis.

layers.view_draftlayers.editlayers.publishgeography.manage

Planning Lead

For the people who set up sketching tools, attribute forms, and the analytical reports planners see when they draw.

layers.view_draftlayers.editgeography.managesketches.editsketches.managereports.editreports.publish

Community Manager

For the people who run participation and the project's public face: invites, groups, forums, and branding (name, logo, about page, languages, map extent).

activity.viewsettings.customizationusers.managelayers.view_draftlayers.editforums.manageforums.moderate

Survey Facilitator

For field staff coordinating survey data collection. They can monitor progress and limited response collection details, but not see individual responses for all users.

surveys.facilitate

Survey Administrator

For the people who own the survey program: designing surveys, managing invites, and working with response data — including exports that may contain personal information.

surveys.facilitatesurveys.editsurveys.access_responsessurveys.manage

What each role can do

CapabilityVIPData EditorData ManagerPlanning LeadCommunity ManagerSurvey FacilitatorSurvey Administrator
activity.view
settings.customization
users.manage
layers.view_draft
layers.edit
layers.publish
geography.manage
sketches.edit
sketches.manage
reports.edit
reports.publish
forums.manage
forums.moderate
surveys.facilitate
surveys.edit
surveys.access_responses
surveys.manage

What only Project Owners can do

Some actions stay with Project Owners even when a project uses multi-level admin access. These are powers that change who is in charge, who can join, or that can permanently remove data.

Reserved for OwnersWhy
Assigning roles and capabilitiesOnly Project Owners decide who gets which roles or capabilities, and who else becomes an Owner.
Project access settingsWhether the project is public, invite-only, or admins-only; whether it appears in public listings; and whether major tools (forums, sketches, overlays) are hidden.
API and Mapbox keysKeys that grant ongoing programmatic or mapping access outside day-to-day admin work.
Data retentionSettings that can permanently delete archived uploads.
Groups that carry admin capabilitiesMembership of any group that already has capabilities assigned — so a Community Manager cannot escalate their own access by joining such a group.
Deleting the projectRemoving the project entirely.

Detailed list of admin functionality and matching capability assignment

Use this section when you want to check a specific part of the admin dashboard and see which capability (or Owner-only rule) covers it. Expand any area below.

Project settings
Admin functionalityCapability
Name, description, logo, and logo linksettings.customization
About pagesettings.customization
Supported languagessettings.customization
Map extent (the default map view)settings.customization
Default map options (scale bar, legend)settings.customization
Who can join / whether the project is listed publiclysettings.access (Owners only)
Hiding forums, sketches, or overlays from the main appsettings.access (Owners only)
Mapbox and project API keyssettings.keys (Owners only)
Activity
Admin functionalityCapability
Activity dashboard (visitors, popular layers, forum activity)activity.view
Users & groups
Admin functionalityCapability
View participants and profilesusers.manage
Create, send, edit, and track invitesusers.manage
Approve or deny access requestsusers.manage
Create, rename, and delete groups; assign membershipusers.manage
Make someone a Project OwnerOwners only
Ban someone from posting in forumsforums.moderate
Data layers
Admin functionalityCapability
View the draft (unpublished) layer listlayers.view_draft
Upload data and manage processing jobslayers.edit
Add remote sources (ArcGIS, GeoJSON, and similar)layers.edit
Organize folders and layer order in the draft listlayers.edit
Edit metadata and map styleslayers.edit
Control who can see each layerlayers.edit
Manage basemapslayers.edit
Offline map packages (when enabled)layers.edit
Publish draft layers so participants can see themlayers.publish
Change how long archived uploads are retainedsettings.retention (Owners only)
Geography & reports
Admin functionalityCapability
Create, edit, and maintain geographies and clippinggeography.manage
Create reports and edit draft contentreports.edit
Publish reports for planners to usereports.publish
Sketch classes (sketching tools)
Admin functionalityCapability
Create or delete a sketching toolsketches.manage
Edit settings, attribute forms, and stylessketches.edit
Configure geography clipping and analysissketches.edit
Assign the primary report to a sketching toolreports.publish
Forums
Admin functionalityCapability
Create and organize forums; set who can read or postforums.manage
Community guidelinesforums.manage
Hide posts, lock topics, ban postersforums.moderate
Surveys
Admin functionalityCapability
Monitor survey progress and invite status (no answers)surveys.facilitate
Design surveys and manage survey invitessurveys.edit
View, correct, and export responsessurveys.access_responses
Create or delete surveys; archive responsessurveys.manage

Help refine this proposal

Add your comments or directly add new roles or capabilities to the spreadsheet below.

Feedback spreadsheet