Masterplan Optimiser

Admins and issuers

Set up an event and its access step by step

Admins manage authorised events and accounts. Issuers prepare bounded access for assigned events. Neither role receives host recovery, controller-key custody or final deletion authority.

Before you start

  • A fully commissioned Server with published governance
  • Your own active passkey account
  • An admin or issuer role assigned by root/global administration
  • The event and people you are authorised to manage
  • A secure channel for one-time links or working SMTP, if email delivery is expected
  • An identified Desktop planner if the event will be published from Desktop
  1. 1

    Activate your own account

    Use the organiser-provided activation route and register a passkey on a trusted device.

    Done when: You can sign in and the account shows the expected admin or issuer scope.

    Open guide
  2. 2

    Review your event scope

    Confirm the event name, dates, controller notice and role before creating accounts or sharing links.

    Done when: Only the events you are authorised to administer are visible.

    Open guide
  3. 3

    Prepare event publishing

    Create or rotate the event publish secret and transfer it once to the authorised Desktop planner.

    Done when: The correct Desktop event connects and its processor enrolment can be approved by root.

    Open guide
  4. 4

    Create accounts and roles

    Use the least privilege needed: participant/viewer, editor, issuer or administrator as authorised.

    Done when: Every person has the correct event assignment and no unnecessary global authority.

    Open guide
  5. 5

    Deliver activation

    Send the link through configured SMTP or provide the bounded link/QR through an approved channel.

    Done when: The recipient registers a passkey and the one-time activation becomes unusable.

    Open guide
  6. 6

    Review published schedules

    Check the authenticated Masterplan separately from deliberately public schedule links and revoke obsolete links.

    Done when: The public view contains only intentional public fields; authenticated access matches assignments.

    Open guide
  7. 7

    Operate and escalate

    Manage announcements and ordinary access. Escalate security, governance, recovery, processor approval and deletion closure to root.

    Done when: No pending action is being treated as complete without the required root or Desktop evidence.

    Open guide

Two schedule audiences

The audience is fixed by the publication surface rather than selected field by field.

Public Schedule

Always public to anyone holding the intentionally published route or bearer link

Masterplan

Always restricted to authenticated people with an assigned event role

Passkey and session flow

The authenticator retains the private passkey; the Server stores a public credential and bounded session digest.

  1. 1

    Challenge

    Server issues a short-lived WebAuthn challenge

  2. 2

    User presence

    Authenticator signs for the exact origin

  3. 3

    Verification

    Server verifies public credential, origin and counter

  4. 4

    Session

    Protected cookie carries a bounded session token

  5. 5

    Reauthenticate

    Privileged actions request a fresh passkey assertion

Event processor enrolment

Private material remains on the Desktop workstation; the Server receives public proof only.

  1. 1

    Link event

    Validate Server URL and publish secret

  2. 2

    Create or import key

    Store the event-specific private key in the OS credential store

  3. 3

    Prove possession

    Sign the event-bound challenge locally

  4. 4

    Root approves

    Confirm the exact event, entity and fingerprint

  5. 5

    Acknowledge policy

    Sign the current permitted-data policy before publishing

Use the canonical Server documentation for deployment-specific administration. Evidence verification and public key tools are in Evidence-Public.