Overview
Administrators can manage the lifecycle and availability of server-scoped encrypted content. Administrative deletion controls operate on encrypted content objects and lifecycle state. Administrative controls do not grant access to:- Message plaintext.
- Attachment plaintext.
- Multimedia plaintext.
- User communications.
- Private key material.
- Protected key material.
- Cryptographic authority.
Administrative Capabilities
Administrators can:- Invite users.
- Remove users.
- Manage server membership.
- Review and approve join requests.
- Manage the lifecycle and availability of server-scoped encrypted content.
- Delete server-scoped encrypted content.
- Delete server-scoped encrypted messages.
- Delete server-scoped encrypted multimedia.
- Delete encrypted content generated by users within that server environment.
- Delete all encrypted content belonging to a specific user within that server environment.
- Delete all encrypted content within the dedicated server environment.
- Delete the entire server environment.
Administrative Boundaries
Administrative boundaries include:- Server administration is separate from Enigm App message plaintext.
- Server lifecycle control is separate from private key material.
- Server membership management is separate from Device Trust.
- Server ownership is separate from plaintext access to user content.
- Enigm Command authorization is separate from end-to-end encryption.
- Administrative deletion controls operate on encrypted content objects and lifecycle state.
Relationship With Enigm Command
Enigm Command provides the authenticated administrative surface for Enigm Server operations. Enigm Command authorization should remain:- Authenticated.
- Explicitly authorized.
- Scoped to the server environment.
- Auditable where appropriate.
- Separate from protected communication content.