--- type: User Story title: Operate settings and audit views description: Authorized administrators control server messaging and investigate recent platform events. tags: [admin, settings, audit, operations] timestamp: 2026-08-02T14:12:43Z story_id: US-012 status: verified --- # User Story As an administrator, I want operational settings and audit visibility, so that I can manage player guidance and investigate activity. # Acceptance Criteria - [x] The admin console shows the deployment-managed Discord guild ID and linked invite URL. - [x] An authorized administrator can update the denied-player registration message. - [x] Settings actions validate message length server-side. - [x] Administrators can browse the latest 100 events. - [x] Event views show type, subject, IP, classification, and approximate location when available. - [x] Admin console access itself creates an audit event with the SSO identity. - [x] Settings, users, and events are linked from the shared admin navigation. - [x] Administrators can independently configure registration-required, group-access-disabled, schedule-denied, and VPN/proxy/Tor-denied game-message templates. - [x] Registration, group, and network templates accept only `{player}` and `{group}`; schedule templates also accept `{next_start}` and `{next_end}`. - [x] Every template is validated server-side and has a safe default. - [x] Admission-message changes are audited with the administrator identity without logging credentials. # Implementation - [`apps/web/src/app/admin/(console)/page.tsx`](../apps/web/src/app/admin/%28console%29/page.tsx) - [`apps/web/src/app/admin/(console)/actions.ts`](../apps/web/src/app/admin/%28console%29/actions.ts) - [`apps/web/src/lib/admission-settings.ts`](../apps/web/src/lib/admission-settings.ts) - [`packages/database/drizzle/0004_zippy_silver_centurion.sql`](../packages/database/drizzle/0004_zippy_silver_centurion.sql) - [`packages/database/drizzle/0005_young_vertigo.sql`](../packages/database/drizzle/0005_young_vertigo.sql) - [`apps/web/src/app/admin/(console)/events/page.tsx`](../apps/web/src/app/admin/%28console%29/events/page.tsx) # Validation Admin routes are dynamic, role-protected, linted, and included in every production build. # Related Stories - [Administrator SSO](us-011-admin-sso.md) - [Preserve an audit trail](us-010-audit-events.md)