# Sites access and audit

## Roles and scope

- **Sites Super Admin** is global. It can manage every Sites Website, all global modules, access assignments and audit history.
- **Website Manager** is assigned explicitly per Website. It can view and manage assigned Website identity, typography, operators, structured Google Ads, frontend status and Domain Health.
- **Sites Viewer** is assigned explicitly per Website. It can view Website configuration, health, readiness and reports only.

No Sites role changes TakafulHub Agent, Core Admin or VastPro permissions.

## Sensitive-action policy

Only a Sites Super Admin may create Websites, change a primary domain, set lifecycle to Live/Archived, edit executable Header Code, or mutate Operator Themes, Global Legal Templates, Campaign Popups and Social Proof.

Managers cannot access global modules. They may set a Main Operator only while the Website is not Live. The existing operator and lifecycle integrity rules still apply.

## Bootstrap

The Phase 15 migration copies the existing trusted Sites access source: every existing `users.is_admin = true` user receives `sites_role = super_admin` once. It does not grant access to every user and does not automatically grant future Core admins Sites access. Website Managers/Viewers must be explicitly assigned through **Access & Permissions**.

## Audit trail

`sites_audit_logs` is append-only from the product UI. `SitesAuditService` records meaningful mutations: Website lifecycle/domain/frontend/identity/typography/marketing changes, operator changes, Domain Health checks, global themes/legal/popup/Social Proof changes, and access grants/updates/revocations.

Audit data includes actor snapshot, stable action, category, Website context, summary and compact safe metadata. Raw Header Code, scripts, tokens and uploaded file content are never recorded. Header Code entries only report configuration state such as `not_configured → configured`.

## Operational views

Super Admins use **Access & Permissions** for Website assignment and **Audit Log** for paginated, Asia/Kuala_Lumpur-formatted event history. Audit filters include Website, actor, category and date range. Reads are not logged.
