Organisation · Security
Identity & security
Control which social sign-ins are offered per surface. Email one-time code is always on — it is the platform's base method and cannot be turned off.
| Provider | Player app | Admin console | Public web |
|---|---|---|---|
| 🔗 Apple | |||
| 🔗 Microsoft | |||
| 🔗 GitHub |
Require two-factor for selected roles. Members without a requirement can always enable it voluntarily.
ROLES WITH A TWO-FACTOR REQUIREMENT
3 administrators do not meet the requirement yet (within the grace period). They are reminded at every sign-in.
Machine clients for integrations (bookkeeping, import, kiosk). Each client gets only the scopes it needs — never a human session.
🔑 Client secret — shown only once
plm2m_9f2kq•••••••••••••••••••3acU Copy it now and store it securely. If it is lost it must be rotated.
- Bookkeeping sync (Fortnox)finance.export.read · IP: 193.14.88.0/24 · Active · used today
- Results import (legacy)competition:results:write · IP: 10.80.0.0/16 · Active · used 28 Jun
- Old kiosk bridgekiosk:orders:read · IP: — · Blocked 12 May
Calls from outside the IP allowlist are denied. All usage is visible in the access log.
Some fields require their own field-level permission. If the role lacks the permission, the field is masked — the rest of the record is delivered as usual (never a flat no on the whole record).
| Field | Permission | Roles with access |
|---|---|---|
| Date of birth | privacy.personal_data.read | Federation administrator, Membership manager |
| ICE / basic medical info | privacy.medical.read | Only the person themselves (+ emergency at events) |
| Protected personal data | privacy.safeguarding.read | Federation administrator |
| Account number / payout | finance.account.read | Club treasurer, Federation finance |
WHAT IT LOOKS LIKE WITHOUT PERMISSION
Emergency reads of ICE/medical data at an ongoing event require check-in + a mandatory reason and are reviewed afterwards.