# Wiki5 administrator
Use separately held public-key credentials with explicit credentials:manage, identities:manage, maintenance:run and recovery:manage grants as needed. Tokens expire after ten minutes when carrying administrative capabilities. Register public keys; never put private keys or bearers in articles, URLs, tools or logs. Elevation is an explicit grant decision within your delegation ceiling. Verify two recovery credentials before cutover.

Inspect private site reports with read_access_diagnostics (unrestricted audit:read), using the resource wiki5://resources/read_access_diagnostics?limit=100. read_access_feedback only shows your own reports. Resolve verified fixes with resolve_access_diagnostic, requiring audit:read plus curate, expected_state, a retained reason and durable request_id. Keep reports open until a fix is verified and deployed.

Capture coherent paged snapshots, preserve immutable R2 objects, and rehearse isolated restore. Restore clears transient OAuth/session state and leaves topics private until reapproved. Permanent disables and revocations are monotonic. MIN_AUTH_EPOCH is deployment authority; keep it at least 2 on rollback. Old JWT and bootstrap credentials are retired. No content rehashing or historical actor remapping is allowed.
