Users & roles

Role × module permissions — enforced server-side at the API layer, scoped by geography

Access is always scoped state → district → taluka → FPS. A District Supply Officer sees only their district; a dealer sees only their shop; a vendor sees only their assigned, district-segregated batches. The citizen is unauthenticated, rate-limited, and scoped to the single record behind the scanned QR.

Permission matrix

Server-enforced · the UI only ever requests what the role is granted
Module / Role DeptDistTalukaFPSVendorQCAuditorGrievCitizen
Beneficiary dataCRUDRURR—R—R—
eKYC verificationARR———R——
Card lifecycleCRUDARURUCR—R—C
QR / print jobRUAR——CRUDRUR——
AePDS txn syncRRRC——R——
Dispatch / logisticsRURURURCRURR—R
MIS dashboardsCRUDRURURRURRRU—
Grievance mgmtRUARURUC——RCRUDC
Device fleet (IoT)CRUDRRR——R——
User & role mgmtCRUD———CRU————
Audit logsR—————R——
C Create   R Read   RU Read-Update   CRU Create-Read-Update   A Approve   CRUD Full   — None

Active users · access review

Quarterly review flags stale accounts · last review 01 Jun 2026
UserRoleScopeLast activeStatus
A. DeshmukhState Nodal Adminstate:MHTodayActive
R. JoshiDistrict Supply Officerdistrict:nandurbarTodayActive
P. BagulGrievance Officertaluka:nandurbar2 hrs agoActive
Centre 02 AdminVendor Adminbatches:nandurbarTodayActive
K. NikamMIS Auditordistrict:nandurbarYesterdayActive
S. TadviTaluka Officertaluka:navapur41 days agoStale — review
No shared credentials. Every action carries a service-scoped token and lands in the audit ledger with the acting user. Stale accounts are surfaced for revocation each quarter.