Operator access required. Sign in with an operator account.
Sign inOperations overview
What needs you now Loading
Checking action queues, production state, and recent operator activity.
Needs attention
Only queues with work waiting on an operator appear here.
Recent activity
The five latest audited operator actions. Sensitive payloads stay in the audit authority.
Members
Review account access and Pro grants. Open a member to manage their permissions.
Waiting for access
Checking waiting accounts…
Pro lifecycle
- Holders
- —
- Comped
- —
- Paid
- —
- Lapsed
- —
- Due soon
- —
- Permanent
- —
Loading Pro lifecycle…
| Member | Grant | Last seen · source | Ledger actions | · Activity | Open |
|---|
Loading authoritative account access…
Member
—
Each control changes one authority only. Warden Read and Warden Submit are separate, operator-granted lender permissions.
- Lifecycle
- —
- Approval
- —
- Role
- —
- Ledger
- —
- Signals
- —
- Pro
- —
- Warden
- —
- Account record
- —
Ledger adoption
Aggregate usage only. Borrower names, notes, money, and private records remain unread.
- Borrowers
- ——
- Loans
- ——
- Repayments
- ——
- Latest activity
- ——
Account lifecycle
Approval, suspension, revocation, and restoration remain separate from plan and product access.
Role and member grants
Moderator authority and community grants are independent. Operators and self-targets fail closed.
Product access
Ledger and Signals Free are included with approved account access. Pro and Warden grants are managed separately.
Direct payments
Warden access
Grant Read and Submit independently to trusted lenders and moderators. Submit is consequential: it lets the member create subjects through intake, edit fields and aliases on entries they filed, upload evidence images, corroborate, vouch, and change a subject's status. It does not grant staff management.
Destructive account actions
Soft delete disables the account record. Purge permanently removes the account and its private Ledger data after an impact preview.
Advanced account toolsDirect credential creation and local test-account cleanup. Use deliberately
Create an account with a password
Members can register directly. Use this only when an operator must set credentials and can deliver them securely out of band.
Clean up system-test accounts
Local runtime only. Preview explicitly marked system-test accounts, narrow by email or test key, then choose the exact rows to purge.
Nothing has been previewed.
Payments
Direct payments recorded by an operator. Voided entries stay in the list.
Moderation
The production gate. Signals members submit pass through here before they become searchable. Decisions hit the live moderation backend (/admin/signal/moderation) and every action re-fetches from the server. Escalate holds an item for a second reviewer without deciding it.
Loading queue…
Deciding closes the claim only. It does not change the Signal record; make any record correction separately.
Member-app ledger syncs (external staging). Approving promotes the default to contributions; rejecting keeps it out of every published output.
Signal intelligence
Unpaid signals collected from Reddit and Discord lending communities. Signals enter a moderation queue before becoming searchable by lenders via GET /signal/search.
Free-tier lookup cap
Daily limit on GET /signal/lookup per free-tier user (UTC day). Pro users with module_signal_pack bypass, and as of 2026-06-09 all approved (permitted) accounts bypass too. This cap only bites a future unapproved tier. 0 = unlimited (operator escape hatch). -1 = gate disabled (kill-switch).
Signal collector
Signals
Cross-community subjects
Borrowers reported across 2 or more subreddits: highest-priority moderation targets.
Loading…
| Username | Cmty | Subreddits | Unpaid | Total | Last seen |
|---|
| ID | Borrower | Status | Updated | Action |
|---|
Audit
Immutable trail of operator actions (accounts, entitlements, signals, disputes, and related changes).
Loading
| Time | Operator | Action |
|---|
Invitations
Choose the access path, create a one-time credential, then track its lifecycle without exposing the secret again.
Three distinct grants: codes and lender invites create lender access; operator invites create staff authority. Pro and Warden remain separate.
Registration codes
Create attributable registration codes, hand them off, and follow each code through redemption or revocation.
Access boundary: redemption creates an approved lender with Web Ledger access. Pro and Warden remain separate grants.
Mint and share
Use operator-direct for one lender or community for a named subreddit batch. Minting is recorded in the operator audit trail.
Track issued codes
Newest first. Recipient/source and internal notes remain editable after redemption; code identity and redemption history do not change.
Loading invite codes…
| Code | Recipient / source | Usage / status | Timeline | Actions |
|---|
Redemptions for
Who redeemed this code and when.
Loading…
| Redeemed by | When | IP |
|---|
Lender invitations
Create a named one-time link and track whether it remains pending, was accepted, expired, or was revoked.
Lender access: the invite carries Web Ledger. Approval follows the checkbox below; Pro and Warden are never implied.
Create lender invite
The secret link appears once. Send it out-of-band, then use lifecycle history, not the secret, to manage it.
Lifecycle history
Review outstanding links, acceptance, and closed entries. Revoke only an unused pending invitation.
Loading lender invites…
Operator invitations
Create staff access, share the one-time secret, and retain an auditable pending, used, revoked, or expired history.
High authority: acceptance creates an operator with the default platform-administration capabilities. Protected Warden intake remains separate.
Create operator invite
Use only for staff who should administer LoanLedger. The secret link cannot be retrieved after this result is dismissed.
Lifecycle history
Secrets never appear here. Review status and revoke an unused pending invitation when staff plans change.
Loading operator invites…
Notification manager
Manage the copy lenders receive, send manual notices, and review the delivery log.
Total sent
Unread (all lenders)
Notification templates
Click Edit to customise the title and body lenders receive.—
Event-triggered
| Name | Category | Sent | Active title |
|---|
Automated emitters
| Name | Schedule | Sent | Description |
|---|
Compose & send
Send to one lender or broadcast to an audience. In-app always delivers; email also sends for account/billing/system categories when the lender has email delivery on.
Advanced: send through a template key
Queued sends
Scheduled notifications waiting to fire (and recent ones). The drainer dispatches due sends within a minute.
| When | Recipient | Title | Status |
|---|
Lender inbox
Read-only view of a specific account's notification feed.
No messages in this view.
Emitter controls
Pause or resume system-triggered notification emitters by template key.
Loading notification emitters
| Template key | Source | Status | Sent (24 h) | Last run | Action |
|---|
Delivery log
—
| # | User | Title | Template | Status | Sent |
|---|
Rules & Config
Volatile operator knobs, changed live: no deploy, no restart. Each value is stored as data; the code ships a safe default, so an unset knob behaves exactly as before. Edits hit /admin/config and are written to the audit trail.
Brand
Brand & Logodefault
brand.logo_variantSwitch the LoanLedger mark the whole suite renders. Applied live and read per-environment. This LOCAL build and PROD keep separate settings. Leaving it on the shipped identity renders exactly what ships today.
/admin/config and the audit trail.Loading configuration…
Media
Site media
/admin/mediaUpload site images (logos, page art, help screenshots) as runtime data, no deploy. Each file gets a permanent content-addressed URL you can paste anywhere; replacing an image = uploading the new one and using its new URL. JPEG/PNG/GIF/WebP only (checked by content), 10 MB max. Deleting hides an asset (its URL stops serving); re-uploading the same file restores it.