For admins and issuers
Give the right people the right access
Good event administration is quiet work: prepare the event, invite people, give each person the role they need and keep the more sensitive host decisions with root.
What you need before you start
- Your own activated passkey account
- An admin or issuer role for the intended event
- The event and people you are authorised to manage
- Working SMTP or another approved delivery channel if invitations are needed
Work through the steps
- 01Open this step
Check your scope
Confirm the event and role assigned to you before creating accounts or sharing links.
You are ready to continue when: Only the events you are authorised to manage appear.
- 02Open this step
Prepare event publishing
Create or rotate the event publish secret and transfer it once to the authorised Desktop planner.
You are ready to continue when: The correct Desktop event connects and root can approve its processor identity.
- 03Open this step
Invite people
Add the minimum contact information needed and assign the least authority required.
You are ready to continue when: Each person has the correct event and role, with no unnecessary global access.
- 04
Deliver activation
Use configured SMTP or an approved direct channel for the bounded activation link or QR code.
You are ready to continue when: The recipient registers a passkey and the one-time link can no longer be reused.
- 05Open this step
Check published audiences
Review authenticated Masterplan separately from deliberately public schedule links.
You are ready to continue when: Names, assignments and operational details appear only in their intended audience.
- 06Open this step
Hand root work to root
Governance, recovery, key activation, final deletion approval and host security belong with root. Pass them on with enough context instead of trying to work around the role boundary.
You are ready to continue when: Every pending action is with the person who can complete it safely.
Two schedule audiences
The audience is fixed by the publication surface rather than selected field by field.
Public Schedule
Always public to anyone holding the intentionally published route or bearer link
Masterplan
Always restricted to authenticated people with an assigned event role
Event processor enrolment
Private material remains on the Desktop workstation; the Server receives public proof only.
1
Link event
Validate Server URL and publish secret
2
Create or import key
Store the event-specific private key in the OS credential store
3
Prove possession
Sign the event-bound challenge locally
4
Root approves
Confirm the exact event, entity and fingerprint
5
Acknowledge policy
Sign the current permitted-data policy before publishing