User Manual

Guides for board members, moderators, and administrators.

Download / Print Manual

Platform Security

How Agenda Beacon protects material that is not marked public — share this with your board, counsel, or procurement team.

Org AdminBoard MemberModerator / Secretary

Access Enforced In The Database

Database access rules protect organization records as well as the checks in the application. Members receive access separately for each board or committee; committee-only access does not open the main board's internal material.

Two-Factor Required For Board Material

Member and administrator access requires a session that completed two-factor authentication. A stolen password or an API token alone does not unlock confidential agendas, packets, or minutes.

Private File Storage

No document is served from a public URL. Files live in private storage, and only records explicitly marked public are reachable by visitors.

Expiring Download Links

Downloads are issued as signed links that expire within a minute or two, so a shared or logged link cannot be replayed later.

Document And Permission Audit Logs

Administrators review Document Access Log and Permission Changes under Administration, then Security & Audit. Document access records the issuing of secure download links, rather than proving a file was opened or read.

Changes to membership, roles, titles, and board access are recorded automatically in an append-only permission log. Administrators can review and export records, but cannot edit or delete the permission history.

Automated Leak Testing

Privacy regression tests check that public responses exclude internal notes and other non-public fields. These checks support ongoing security review; they are not a guarantee against every possible incident or a compliance certification.

Inactivity Protection

The signed-in workspace signs out after 90 minutes of inactivity, with a warning two minutes beforehand. Activity is shared across browser tabs, and open live votes keep the session active.

What Is Public By Design

Only records your administrators explicitly mark public appear on the public site: published meetings and their public agenda items, attachments marked public, board member profiles with the fields you enable, and policy or library items marked public. Everything else — drafts, closed sessions, private packets, personnel material — is invisible to visitors, including through site search.