Separate operational surfaces
Center server, kiosk, client station, authority terminal, tabulator, monitoring, and verifier have distinct permissions.
A lifecycle-controlled election moves from configuration and sealing through supervised voting, close, decryption, tabulation, and verification.
Center server, kiosk, client station, authority terminal, tabulator, monitoring, and verifier have distinct permissions.
Draft, readiness, open, paused, closed, decrypting, and finalized states govern which actions are available.
Critical transitions, device activity, approvals, ballot operations, and result assembly produce reviewable evidence.