Administration and audit
Site administrators are a separate role from organization owners and members. Ordinary accounts do not become administrators after a migration or language change. The admin page is protected by server authorization, not just a hidden menu.
Review and change records
Use /admin or /zh/admin with a deliberately bootstrapped administrator. Account search, task records, financial records, audit and optional notification/referral evidence are separated views. Exact audit filters can be combined; request and completion records show the lifecycle of a recorded action.
Sensitive actions require a reason, review confirmation and fresh authentication when requested. Refresh after uncertain responses before repeating a change. Credit adjustments retain payment holds; task retries retain original attempt limits and reservations. Payment checks do not initiate a charge/refund at the provider.
Raw identifiers, state codes, reasons, ledger notes and user-entered content stay as recorded. UI labels and explanations are translated; historical evidence is not rewritten.
Bootstrap and operation
Use the repository's admin:bootstrap only against a verified intended database/account. Do not grant all preview users administrator access. The operator commands expose bounded, audited recovery rather than direct unrecorded edits.
Normal preview schema remains through migration 0012. Later optional capabilities require a deliberately upgraded isolated acceptance database. This translation iteration does not migrate the main preview or change existing account roles.
For detailed original acceptance and operator examples, use the Chinese administration record. Real cloud operations remain deferred.