Enrollment management is protectedStudent enrollment records remain behind existing RLS. A dedicated admin-scoped read/write path must be certified before this module exposes enrollment data or controls.
Certificates
Pending certification
Certificate administration is not yet exposedNo certificate records or issuance controls are surfaced until the underlying certificate architecture and authorization path are independently verified.
Audit Logs
Pending certification
Audit log viewer is not yet exposedAudit records require a dedicated admin-scoped read path and retention/authorization verification before browser access is enabled.
Identity security boundary: this release stores only verification status, method, provider/reference metadata and timestamps. It does not collect or persist raw NIN, NINAuth tokens, passport photographs, identity documents, or biometric material. Production VERIFIED status requires an authorized NIMC/NINAuth/verification-partner method; sandbox cannot activate a provider.
Existing authorization boundary: this page authenticates the existing Supabase session and then calls the authenticated-only public.is_current_user_admin() authorization function. The browser never receives direct access to private.admin_users.