This section ffers you a summary of the user interface offered to Admin users.
Anytime you log in as administrator via the Login page the application takes you to your personal administrative Homepage; This page includes some documentation about GlobaLeaks that is intended to clarify you all the up-to-date documentation in matter of software security, best practices and community support.
From this Home page you may access all the common user facilities already described in the general User Documentation.
A menu on the right offers you links to the different administative sections:
- Site settings
- Case management
- Notification settings
- Network settings
- Advanced settings
- System overview
This is the section that offers you all the main customization possibilities necessary for implementing a basic and functional whistleblowing site.
This section is furtherly divided in:
- Main configuration
- Theme customization
- Text customization
In this section is configurable the logo and all the texts of the main user interfaces.
In this section you could enable all the languages required by your project and configure the default language.
Thanks to the Localization Lab and our great voluneer comminity, the software is already available and continously made available in a lot of languages. This aspect of internationalization is crucial in many projects. In case you are starting a project and the required languages are not available we strongly invite you to register on our web translation platform offered by Transifex and support yourself the translation. Internationalization and Localization is in fact are crucial for the success of a whistleblowing project. Thank you!
Here could be confiured overrides for any of the texts of the platform and of their translation.
This sections is where users could be created and managed. The system with the basic configuration completed with the initial Platform wizard is configured with an Administrator and a Recipient.
Depending on your project needs here you could create users with different roles and manage their respective privileges.
This section is where whistleblowing questionnaires could be created and managed.
By default the software implements a Default Questionnaire with a single Step and the following three questions:
One question “Short description” of type “Multi-line text input” enabling whistleblower to provide a short summary of the fact reported;
One question “Full description” of type “Multi-line text input” enabling whistleblowers to describe the fact reported in detail;
One question “Attachments” of type “Attachment” enabling users to load one or more attachments.
The system with its basic configuration completed with the initial Platform wizard is also already configured with this Default Questionnaire pre-associated to the Default Context.
Depending on your project needs you could create specific questionnaire for each of your different submissions’ contexts.
Depending on your project needs you may evaluate defining some questions once as Question Templates and reuse the same question in multiple questionnaires.
The software enables to organise questionnaire in one or multiple steps. For example the default qeustionnaire is organized with a single step including all the questions.
The software enables you to create questions of the following types:
- Single-line text input
- Multi-line text input
- Selection box
- Multiple choice input
- Terms of service
- Date range
- Question group
General question properties¶
Each of the software question types make it possible to configure the following properties:
Question: The text of the question
Hint: A hint that will be shown via an popover an a question mark near the question.
Description: A description text that will be shown below the question
Required: Set this field if you want this question to be mandatory
Preview: Set this field if you want the answers to this question to appear in the preview section of the submission list
Question properties by question type¶
Single and Multi line text input¶
Selection box, Multiple choice input, Checkbox¶
This section is where whistleblowing contexts (channels) could be created and managed.
A whistleblowing channel is typically defined by the following main characteristics
Name: the name of the channel Image: an image to identify the channel Description: a description of the channel Recipients: the set of recipients that will receive submissions sent to this channel Questionnaire: the questionnaire that will be proposed to whistlelowers selecting this channel Submission expiration: the data retention policy for the channel
The system with the basic configuration completed with the initial platform wizard is configured with a single Context called Default, on which is associated a recipient and the default questionnaire.
Depending on your project needs here you could create additional Contexts and configure their respective recipients and properties.
The software enables to configure a data retention policy for each channel. This is a fundamental property of the whistleblowing channel that makes it possible to configure automatic secure deletion of submissions after a certain period of time. This setting should be configured in relation to the risk of the channel in order to limit unndeded exposure of the submissions received therein.
By default a context is configured with a submission expiration of 30 days.
This section is intended to host all the main case management feature that will be offered by the software. Currently it hosts the possibility to define submissions statuses and substatuses intended to be used by Recipients while working on the submissions.
By default the system includes the following submission statuses:
Within this section you may add additional Statuses between the State Open and Closed and you can furtherly define Substatuses for the Closed status (e.g. Archived / Spam)
This is the section where are configured all the aspects related to the mail notifications sent by the software.
- The section is furtherly divided in:
- Main configuration
- Notification templates
Here are configured the techinical details about SMTP.
By default Globaleaks comes with a working configuration that is based on systems offered by the GlobaLeaks developers to the community of users and testers; even though this configuration is designed by their owners with special care in relation to security and privacy you are invited to consider using alternative systems for your production enviroment.
In this section are configured the notification templates.
By default globaleaks includes text and translations for each of the templates that are provided to be fully functional and studied with particular care in relation to security and privacy. Depending on your project needs you may override the default text with your customized texts.
In this section are configured the newtork settings.
- The section is furtherly divided in:
- IP Access control
Here you can configure all the aspects related to the access of the platform via the HTTPS Protocol.
In particular here are configured:
- The domain name used by your project
- The HTTPS key and certificates
To ease the deployment and the maintainance and reduce the costs of your project, consider using the software includes support for the Let’sEncrypt HTTPS certificates.
Here you can configure all the aspects related to the access of the platform via the Tor Protocol.
IP Access Control¶
Here you can configure IP based Access Control.
Suggested configurations are:
- Prevent Whistleblowers to report from whithin their respective work space.
- Restrict Recipients access to their intranet.