Skip to content

ToFF Form: Administration & Access Control ​

Powered by Formbricks
Managed by CultureOS

This document specifies the administrative governance, security controls, relationship-based authorization models, and statutory data retention policies enforced within ToFF Form.

System Operations & Engineering

This operational system is configured, deployed, and managed by CultureOS. CultureOS is an AI-native practice helping cultural institutions modernize digital infrastructure, archives, and research workflows responsibly.

Role-Based Access Control (RBAC) Matrix ​

Access privileges within ToFF Form are organized into four strictly segregated operational tiers:

Role TierAuthorized PersonnelSurvey AuthoringView & Export SubmissionsManage CollaboratorsSystem & Mail Configuration
OwnerNolan Feng / Executive Sponsor✅ Full✅ Full✅ Full✅ Full
AdminOperations Director / IT Lead✅ Full✅ Full✅ Full❌ Restricted
EditorCurators / Program Managers✅ Full✅ Full❌ No Access❌ No Access
ViewerJury Members / External Auditors❌ Read Only✅ View Responses❌ No Access❌ No Access

Relationship-Based Access Control (SpiceDB ReBAC) ​

To guarantee mathematical isolation between distinct institutional committees (e.g., Board of Trustees vs. Scholarship Selection Committees), ToFF Form leverages Authzed SpiceDB (v1.52) over gRPC port 50051.

Authorization Schema Topology ​

definition user {}

definition workspace {
    relation owner: user
    relation admin: user
    relation member: user

    permission manage = owner + admin
    permission read = manage + member
}

definition survey {
    relation workspace: workspace
    relation editor: user
    relation viewer: user

    permission edit = editor + workspace->manage
    permission view_responses = viewer + edit + workspace->read
}

This architecture ensures that even in multi-tenant collaborative setups, reviewers from one grant jury cannot observe or cross-reference applicant submissions assigned to a separate committee.

Statutory Privacy & Compliance Governance ​

1. California Consumer Privacy Act (CCPA / CPRA) ​

  • Verifiable Data Portability: Administrators can export all collected records linked to an individual’s identity within 48 hours of an official subject request.
  • Cryptographic Erasure: Submissions flagged for purge are physically deleted from the PostgreSQL persistence layer along with associated file uploads.

2. General Data Protection Regulation (GDPR) ​

  • Explicit Informed Consent: Mandatory consent blocks must be appended to all European or international surveys collecting identifiable telemetry.
  • Zero Third-Party Data Aggregators: No commercial tracking pixels (Meta, Google, ByteDance) exist within the frontend codebase.

3. FERPA Compliance for Educational Intakes ​

  • Scholarship evaluations, portfolio submissions, and reviewer scoring rubrics are protected by database row-level security and accessible only to verified jury members.

Personnel Onboarding & Offboarding SOP ​

Provisioning New Personnel ​

  1. Log into the administrative dashboard with Owner or Admin privileges.
  2. Navigate to Settings → Team Members → Invite Member.
  3. Enter the individual’s official @tomoffinland.org email and designate their RBAC tier.
  4. An automated onboarding invitation will be transmitted via Resend.

Immediate Deprovisioning Protocol ​

Upon the resignation or contractual termination of any staff member or jury juror:

  1. Navigate to Settings → Team Members.
  2. Locate the individual and select "Revoke Access & Delete User".
  3. The server immediately invalidates all active sessions and purges associated API keys.

Configured, deployed, and managed by CultureOS. CultureOS is an AI-native practice helping cultural institutions modernize digital infrastructure, archives, and research workflows responsibly.