
Step 03 — Authority workspace
Local Authority Portal
The current portal uses local accounts, a free-text 'Local Authority' field at registration and no multi-factor authentication. The proposed model authenticates officers against their own organisation and derives authority membership from the identity itself.
Proposed access model
Microsoft Entra ID single sign-on, MFA enforced
Officers sign in with their existing local authority account. No new password to manage, no separate credential store to breach, and conditional access policies stay under the authority's control.
Authority membership from the identity, not a text box
The tenant or verified domain determines which authority a user belongs to, removing the free-text field that currently allows arbitrary self-declaration.
Roles, least privilege and auditable actions
Reader, contributor, authority approver and CARO administrator. Every publish, edit and download of restricted material is logged with actor, time and object.
No third-party session replay on authenticated pages
Session-replay tooling currently loads on the portal login page. In the proposed build no replay or behavioural scripts run anywhere, and analytics load only after consent — never on authenticated views.
What officers do here
- Submit and update projects and case studies for CARO review
- Track their authority's climate action plan record and documents
- Access restricted guidance, templates and training material
- Register for CARO training and retrieve recordings
- Manage their authority's contact and team listings
- Export their authority's project set for internal reporting