Internal — operators only

Operator console guide

Finance, operations, support, and super admins.

Sign in

Console gate: //gate/ittisal-lic-x7k9m2— not linked from the public site. Use work email + password; MFA when enforced.

Roles

RoleCapabilities
SUPER_ADMINAll: operators, SMTP, key rotation, incident response
OPERATIONSIssue, lifecycle, fulfill orders
SUPPORTCustomers, orders, re-issue, renew, block
FINANCECustomers, reports — no issuance
READ_ONLYDashboard + audit

First-login checklist

  1. Settings → change password from seed default.
  2. Settings → MFA wizard (QR scan or manual TOTP secret).
  3. Settings → register FIDO security key (super admins).
  4. Super admin: Settings → SMTP + team notification emails.

Daily workflows

  • Orders queue — verify email → fulfill or reject → delivery email sent.
  • Issue license — customer, tenant UUID, metrics, sign.
  • Lifecycle — re-issue (hardware/key), renew (extend), block (non-payment), revoke (abuse).
  • Key rotation — deploy new PEM → Admin → Re-issue all (FIDO or break-glass).

Full runbooks (repository)

Detailed procedures: docs/license/OPERATOR_GUIDE.md, OPERATIONS.md, RECOVERY.md, TROUBLESHOOTING.md

Ittisal License Server