Staff console (admin)
Caravan Command, the compact staff console — its 15 modules and which ones use real or demo data, the nine roles and what each can do, approvals and the two-person rule, the automatic anti-cheat with review only on appeal, the GM panel, the rule-based "needs attention" list, and how it works on a phone.
Caravan Command (apps/admin) is the team's console for running Zoen: the website, bugs and AI fixes, releases,
live switches, players and security. It is curated to Zoen's gameplay — no class balance (Zoen has no classes), no
auction house (stalls only), no quest or NPC editors (game content stays in git and the wiki). How it runs:
Web platform.
◆Modules
| Module | What it does | Data |
|---|---|---|
| Overview | Health, version and ruleset, key numbers, needs attention (each item names its rule), recent activity | real |
| Approvals | Requests that need a second person: GM grants, compensation, AI fix jobs | real |
| Bugs | Intake from the site, triage, duplicates, lifecycle, screenshots, Fix with AI | real |
| AI jobs | Waiting approvals, job steps, files, cost, pull request, worker status, kill switch | real |
| Releases | Versions from release.json: planned → building → testing → released, checklist gate, patch notes | real |
| Production | Art and audio queues, tasks and tests, tokens and cost, internal roadmap, open decisions (read from the repository) | real |
| Website | Posts with preview, FAQ, legal, status and incidents, site settings (main button, banner, maintenance) | real |
| Growth | Alpha sign-ups and newsletter (masked), alpha waves, the site funnel, social post drafts (one text per network, reviewed by a second person, copied out by hand — no network connected) | real |
| Live controls | Game maintenance, kill switches (game and site), announcements | real config |
| Config | Feature flags, ruleset multipliers within the limits in rulesets.json | real config |
| World & economy | Channels against the caps, world events, gold and Zoe flows, market limits; drop calculator | demo + real calculator |
| Players | Search, account, character inspector (11 slots, bag, receipts), the action ladder, GM panel | demo |
| Security | Security events, rule tiers and shadow mode, ban reviews, player reports, device watchlist | demo |
| Support | Contact inbox: ban reviews (7-day deadline), account recovery, player reports, general | real |
| System | Staff and roles, audit log with chain check, integrations, health | real |
"Demo" means generated sample players and events until the game servers exist (M6); every demo screen is labelled and the actions only change demo records. The screens switch to the real gateway later without changing.
◆Roles
Nine roles; permissions are checked by the console and again by the database. Only an owner changes roles.
| Role | In short |
|---|---|
| Owner | everything, including staff, exports, bans and rule tiers |
| Developer | bugs and AI jobs, releases (incl. release), flags and status, read-only players and security |
| QA | bug triage and the bug lifecycle, releases (read), production |
| Game master | player lookups, kick and mute, reset positions, announcements, request grants and compensation |
| Moderator | security events, appeals, suspensions and lifting bans, player reports, support (read) |
| Support | the support inbox and replies, player lookups |
| Marketing | website posts and publishing, announcements, sign-ups (masked), analytics |
| Analyst | analytics, growth, world and production (read-only) |
| Read only | read access to most modules, no personal data and no actions |
The role × module matrix is tested on every change (@rbac): each role's menu shows exactly the modules it may use,
and every module page agrees.
◆Approvals (two-person rule)
GM item grants, compensation and AI fix jobs become approval requests. Someone else decides — the owner may decide alone as the solo operator. Approving runs the action with the approver's session (a grant can run once, only from its approved request). Critical decisions need a fresh authenticator check. Requests expire after 7 days.
◆Anti-cheat and moderation
Bans are automatic (Security, anti-cheat and auto-ban, security.json):
- Certain rules ban at once; strong rules restrict (mute, trade lock or 24 h) and ban on a repeat within 30 days; watch rules only log. New rules start in shadow mode (they log what they would do).
- People only review bans the player appeals (site → Support → Ban review). The review queue shows the deadline, the evidence and the player's request; outcomes are upheld, reduced (to a 7-day suspension) or reversed (the player gets everything back from the receipts, plus a goodwill note).
- A rule whose bans are reversed too often in 30 days is flagged for demotion; the console can demote it or put it in shadow mode, but never raise it above the tier in the data (that needs red-team proof).
- Staff can also use the ladder by hand — warn, kick, mute, trade lock, suspensions — each with a reason; a permanent ban by hand is owner-only and needs typed confirmation.
◆GM panel
On a character, a game master builds a grant from the game's own item lists (orbs, shards, materials, consumables,
gear) plus gold; Zoe is only given back as compensation. GM-made items are always bound and flagged, so they can never
be traded, sold or mailed. The in-game GM commands for test servers (gm-room.json) are listed for reference.
◆Needs attention
Overview raises an item only when a named rule fires, for example: an approval is waiting, a ban review is past its 7-day deadline, a critical bug is open, an incident is unresolved, a site refresh could not be delivered for 10 minutes, an AI job is queued with no runner online, maintenance is on, features are switched off, or a release in testing still has open checklist items. Each item shows its rule.
◆On a phone
Bottom tabs (Overview, Approvals, Bugs, Security), the full menu in a drawer, cards instead of wide tables, dialogs as bottom sheets, 44 px touch targets and no hover-only controls. The console installs as an app and can send approval notifications (remote access).
Source: zoen/docs/design/ADMIN.md · 1,067 words · edit the Markdown, not this page.
