Running the organisation
You decide who is in this organisation, what each person can reach, and how the work is structured. Most of what everybody else can do follows from choices you make here.
What you are responsible for
People, access, structure and oversight. You are not responsible for research design or for approving findings — those belong to the people holding those roles, and the platform keeps the boundary rather than relying on convention.
What you see, and why
The Command Centre is your organisation, counted from governed records. Every figure on it is a count of something real, and where a figure cannot be counted the panel says so rather than estimating.
Adding people
Nobody creates their own account. You invite them, and the invitation is what establishes who they are and what they may reach.
- Invite the person
They receive an invitation to the email address you use. The address is the identity — inviting the wrong address creates the wrong person.
- Grant a role
The role decides what surfaces they can open. A role is granted in the platform by someone who may grant it; if your organisation uses single sign-on, your identity provider’s group claim never selects a role.
- Assign them to work
A role says what kind of thing someone may do. An assignment says which project they do it on. An enumerator with no assignment sees an empty workspace, which is the most common “it is broken” report and is not a fault.
Narrowing what someone can see
A regional programme usually needs the Tanzania team to see Tanzania while a regional director sees everything. That is a geographic grant, and it behaves in one specific way worth understanding before you use it.
- A grant can only narrow. It never widens what a role already allows, and it can never reach past your organisation — so a badly written grant cannot become a privilege escalation.
- Somebody with no grant keeps exactly what their role gives them. Adding the feature changed nothing for anyone until a grant was written.
- Somebody with grants is confined to the union of them.
- Every grant carries a stated purpose and can carry an expiry. The purpose field is required because a grant nobody can justify at review is a grant that should not have been written.
Here is the same surface, opened by an unrestricted account and by one restricted to Tanzania. The unrestricted view carries four country deployments; the restricted view carries one, and says so.
Watching collection without doing the M&E job
You can see what field operations are running, what is assigned and where work is stuck. Acting on quality is the M&E Officer’s job; noticing that nobody is acting on it is yours.
Removing someone
When something goes wrong
| What you see | What to do |
|---|---|
| Someone says the workspace is empty | They almost certainly have a role but no assignment. Check what project they are on before assuming a fault. |
| Someone can see more than they should | Check their grants. A person with no grant holds whatever their role gives them across the whole organisation — narrowing requires writing a grant, not removing one. |
| A figure on the Command Centre says “not available” | That is a governed unavailability with a stated reason, not an outage. The reason is printed beside it. |
| An invitation was never received | Check the address you invited. The email address is the identity, and an invitation to a typo goes to the typo. |
Limits worth knowing before you plan around them
What this role cannot do, and what the platform does not offer
- You cannot approve findings or publish on someone else’s behalf. Publication approval is a separate authority, deliberately.
- You cannot see another organisation’s data under any arrangement, including a consortium. Consortium membership confers no data access; access exists only as an explicit, expiring, revocable grant.
- No tenant-administration permission can be granted to another organisation, under any arrangement.