User instructions
Review effective account access
Read the current policy before changing it
Open Users & access → select a user → Review effective access… as a current administrator. This is a read-only view: it does not enable an account, change permissions, acknowledge alerts or open private work. Disabled/deleted accounts are shown without effective access; retained configuration is not erased.
The review combines account status and role, project-wide workspace capabilities, active departments and effective department-head appointments, Fleet site roles, separate vessel log permissions and the effective rights for each linked logbook. View dependencies and the private-task backup safeguard are reflected in the result. An administrator's full access is clearly distinguished from a project user or a vessel-only account.
Read the scope correctly
Project-wide permissions are not narrowed by department membership or a vessel filter. Private task membership, named reviewers, ownership, record state and approval rules remain additional checks. A capability shown as granted does not assign the person to a task or authorise a physical operation.
Vessel-only accounts have no access to unscoped project workspaces. A logistics role does not automatically grant logbook rights. Review the site's separate log permissions and the linked logbook's effective capabilities; a withdrawn link or inactive site prevents vessel-only log access. Administrators retain project-wide log access. Archived status and site state remain relevant to particular actions.
Inactive-site logistics role capabilities describe retained role rights, not a permission to make a new movement on an inactive site. Existing workflow and active-site validation is still authoritative. A temporary sign-in lock is shown separately; the review does not infer that every existing session has been revoked.
Copy or save an internal summary
Copy internal summary and Save internal summary… read current permissions again. Export also rechecks after choosing a filename. Revoked administrator access clears the stale review and prevents a new summary. The UTF-8 .txt file contains account/access information, not passwords, password hashes, tokens, task contents or operational evidence. Protect it as internal information. It is a snapshot, not a permission grant, certified audit record or proof of continuing access.
Full database backups are different from operational reports
The review shows actual full-backup eligibility, not just the permission checkbox. Existing policy allows an appropriately permitted named project user to download a database only while the private-task safeguard permits it. When any private task exists, only an administrator can download the full database. Vessel-only accounts cannot export it. Current account state is checked again before delivery, together with private-task presence in the actual snapshot.
Use Backups & support → Save full database backup… in Admin or Workspace menu → Full database backup (sensitive)… in the browser. Both require deliberate acknowledgement of an unencrypted, unfiltered copy. The browser first checks current eligibility without downloading a database; opening the warning is not a download. The server requires an explicit acknowledgement on the download request and does not cache the response. An old client requesting /api/backup without that review receives a warning rather than a database; reload the app without clearing drafts.
Full backups contain saved records, accounts and password hashes, private work, permissions, original documents and stored evidence. They do not include active sessions, browser-only drafts, unsent photographs, unsaved editor changes, external files not stored in the database or HTTPS private keys. Password hashes are not plaintext passwords but still require protection. Permission changes cannot recall copies already downloaded. Check the browser download and the actual saved file: a download request is not proof of a successful disk save or a usable restore.
History-bearing .ajproject transfers, including selected workspaces and their dependencies, remain administrator-only, unencrypted and not recipient/vessel filtered. They are not a substitute for an operational report. This update does not add encryption, automatic redaction or new vessel-scoped workspaces. Review report contents and intended recipients before sharing.
Full-database downloads require a named, current account. Shared legacy sign-in codes cannot download them; sign in with an eligible named account instead.