Appearance
ToFF Form: Administration & Access Control
Powered by Formbricks
Managed by CultureOS
This document specifies the administrative governance, security controls, relationship-based authorization models, and statutory data retention policies enforced within ToFF Form.
System Operations & Engineering
This operational system is configured, deployed, and managed by CultureOS. CultureOS is an AI-native practice helping cultural institutions modernize digital infrastructure, archives, and research workflows responsibly.
Role-Based Access Control (RBAC) Matrix
Access privileges within ToFF Form are organized into four strictly segregated operational tiers:
| Role Tier | Authorized Personnel | Survey Authoring | View & Export Submissions | Manage Collaborators | System & Mail Configuration |
|---|---|---|---|---|---|
| Owner | Nolan Feng / Executive Sponsor | ✅ Full | ✅ Full | ✅ Full | ✅ Full |
| Admin | Operations Director / IT Lead | ✅ Full | ✅ Full | ✅ Full | ❌ Restricted |
| Editor | Curators / Program Managers | ✅ Full | ✅ Full | ❌ No Access | ❌ No Access |
| Viewer | Jury Members / External Auditors | ❌ Read Only | ✅ View Responses | ❌ No Access | ❌ No Access |
Relationship-Based Access Control (SpiceDB ReBAC)
To guarantee mathematical isolation between distinct institutional committees (e.g., Board of Trustees vs. Scholarship Selection Committees), ToFF Form leverages Authzed SpiceDB (v1.52) over gRPC port 50051.
Authorization Schema Topology
definition user {}
definition workspace {
relation owner: user
relation admin: user
relation member: user
permission manage = owner + admin
permission read = manage + member
}
definition survey {
relation workspace: workspace
relation editor: user
relation viewer: user
permission edit = editor + workspace->manage
permission view_responses = viewer + edit + workspace->read
}This architecture ensures that even in multi-tenant collaborative setups, reviewers from one grant jury cannot observe or cross-reference applicant submissions assigned to a separate committee.
Statutory Privacy & Compliance Governance
1. California Consumer Privacy Act (CCPA / CPRA)
- Verifiable Data Portability: Administrators can export all collected records linked to an individual’s identity within 48 hours of an official subject request.
- Cryptographic Erasure: Submissions flagged for purge are physically deleted from the PostgreSQL persistence layer along with associated file uploads.
2. General Data Protection Regulation (GDPR)
- Explicit Informed Consent: Mandatory consent blocks must be appended to all European or international surveys collecting identifiable telemetry.
- Zero Third-Party Data Aggregators: No commercial tracking pixels (Meta, Google, ByteDance) exist within the frontend codebase.
3. FERPA Compliance for Educational Intakes
- Scholarship evaluations, portfolio submissions, and reviewer scoring rubrics are protected by database row-level security and accessible only to verified jury members.
Personnel Onboarding & Offboarding SOP
Provisioning New Personnel
- Log into the administrative dashboard with Owner or Admin privileges.
- Navigate to Settings → Team Members → Invite Member.
- Enter the individual’s official
@tomoffinland.orgemail and designate their RBAC tier. - An automated onboarding invitation will be transmitted via Resend.
Immediate Deprovisioning Protocol
Upon the resignation or contractual termination of any staff member or jury juror:
- Navigate to Settings → Team Members.
- Locate the individual and select "Revoke Access & Delete User".
- The server immediately invalidates all active sessions and purges associated API keys.