Staff sign in
This is separate from the player sign-in. A staff account cannot be used on /app/*, and a player account cannot be used here.
Staff area — every visit is logged
Sign-ins, IP address, every time sensitive content is opened, and every sign-off are written to a log that cannot be deleted. The log exists as audit evidence for our funder, not to monitor staff.
Step 1 · Staff account
Step 2 · Two-factor code
Required on every /manage/* account. There is no "skip this step" option and no SMS fallback.
No self-service sign-up
Staff accounts are created only by the system admin, with a role and a reason recorded at the time. This page has no "Create account" button, no "Request access" link, and shows no list of roles or people.
Trouble signing in
If your authenticator app is on a lost or replaced phone, the system admin has to reset the second factor for you. Nobody can do it from this screen, and support will never ask you for a code over the phone or by email.
Contact the system admin through the internal staff channel.
A wrong email, a wrong password and a wrong two-factor code all return the same line: "Those sign-in details are not correct." The system will not tell you whether an email exists or which step failed. Anything more specific would let an outsider work out who works on the project.
What you will see after signing in
- Overview — everything waiting on your sign-off.
- Review queue — sensitive content submitted for clinical review.
- Risk warning facts — wording and cited sources.
Every other /manage/* route returns 403, including if you type the address by hand.
This is not the player sign-in
Players and people in a cooldown week use /login. The two flows are kept apart so a staff account can never accidentally open behavioural data on the player side.