Manual / Ways in
If you administer this deployment
- For
- an administrator
- Status
- current
- Covers
- the Admin Console button, and the screens other people meet because of what you set
- Last checked against the app
ebc6de9(2026-08-20)
The shortest of the three routes, and the one where a wrong press is felt by somebody else. It is a reading order, not a summary: each page below is written once in the section it belongs to, and this page says only why it is on your path.
What your day looks like
Mostly nothing. Then somebody cannot sign in, or a newer timetable has arrived, or a new starter needs an account, or a controller reports that a screen is wrong and you have to work out whether it is the app, the data or the account.
What you own: one button — Admin Console, beside your name in the top bar — and everything behind it. Accounts and their roles; password resets; disabling, deleting and signing people out; the data versions this server is running; and Recent activity, the record of who did what. The panel is headed Users & access, and what is in it is walked through on What your role lets you do.
What you can leave alone: everything the app does with buses. The controller's route and the diversions planner's route cover the work itself, and you do not need either to keep the app running for the people doing it.
Read this before you press anything
Most of this app is safe to explore, because most of it only changes what you are looking at. The Admin Console is the exception: it changes what other people can do, while they are working, and several of its buttons cannot be taken back.
| Before you press | What does not come back |
|---|---|
| Reset password | Every session that account had, everywhere. It is a thing to do with somebody rather than to them, because they cannot undo it from their end — Signing in |
| Sign out, on an account | That person's session, wherever it was open. If they were part-way through drafting a diversion, that draft was on screen and is not saved for them — Planning a diversion |
| Disable or Delete | An account, and with it any way for that person to reach the two protected tabs. Disabling is the reversible one of the pair |
| A change of role | Nothing, but it lands on them while they are working and can move them off the tab they were on — What your role lets you do |
| Reload from disk, after promoting a version | Everyone else's page becomes one built from data the server has replaced. They get a banner and a Refresh now, and a refresh discards whatever they had unsaved — The banners, one by one |
| Any of the above | Nothing at all — every one of them is written to Recent activity, which is append-only. That is a feature on the day somebody asks what happened |
And one that is not yours to take back at all. A diversion record that has been approved can never be deleted, only retired, and Retired is the end of the line. If somebody asks you to make an issued diversion go away, the answer is on Approval, and what it freezes, and it is not a thing the Admin Console can do.
The path
Six pages. It is a short route because the app deliberately gives an administrator few levers.
| Read | Why it is here |
|---|---|
| Signing in | Everything a person meets at the door, including the two states that look like a broken account and are not: the wait after too many attempts, and an expired session |
| What your role lets you do | The five states of the top bar, and which control each role takes away. This is the page to read before changing anybody's role |
| A tab is greyed out | Faded, padlocked and absent are three different faults with three different fixes, and only one of them is an account. Most "I cannot get in" reports are answered here |
| The banners, one by one | Two of the four are yours: the timetable feed running out, and a newer version having been loaded. Nobody else can clear either |
| What is new in this release | The version chip is how you prove which build a deployment is actually running, which is the first question in any report that reaches you |
| Who to tell | Written for the person reporting, and worth reading from the other end: it is the list of what you will wish they had sent |
Two more, when the question is about defaults
| Read | When |
|---|---|
| Your operators and your depot | When a new starter asks why the app opens on a subset of the network. The starting scope is a deployment choice, and this page is where it is explained from the user's side |
| What Reset actually does | When you change a deployment default and want to know who it will reach. A setting somebody has never touched follows the deployment; one they have chosen does not |
What this manual does not cover
Loading a newer timetable or roster onto the server, installing the app, configuring the live feeds and the road data, and backing up the diversion register are all jobs done outside the app rather than in it. They are not in this manual, and not because they are secret: this tree is written for the screens, and those tasks have none.
The people who maintain this app keep a separate handbook for exactly that work. It is not part of this manual and cannot be reached from it. Where you will meet it instead is the Developer handbook link in the Map Explorer's map credits, which Basemaps and imagery points out — and which, on a normal deployment, your account is one of the few that can open.