Who may cover for whom here — declaring emergency cover, and reading where the glass was broken¶
Audience: whoever governs the roles in a project — the quality manager or project administrator who decides which role may stand in for which, and who later has to explain both the arrangement and every time it was used.
Scope configuration → Emergency cover — the last tab of the project's configuration page, behind the gear — holds two things that belong together: who may take over whose role here when somebody is unreachable, and where that was actually needed.
The tab's own line says it: "Who may cover for whom here when a role-holder is unreachable, and where the glass was actually broken." Its content is loaded when you open the tab, not when the page opens — these are two reads the rest of the configuration surface does not make, and a tab nobody opened should not spend them.
This tab is governance: it declares and reads arrangements about roles, and it holds no act of your own. Breaking the glass yourself is a personal act and lives under your own name in the top bar (break-glass §2) — which is also the only place the person who uses a declared cover can reach it, since covering for a colleague needs no administrative permission and this page does.
1. What a declared cover is¶
A cover is one edge: a holder of role A may take over role B — here, in this project. Declaring it does not staff anybody and does not change what anybody holds today. It changes what the system will offer somebody who is refused: a person holding A who runs into an act only B may do meets a refusal that carries a door, and can take B on themselves for a declared window (break-glass §1).
The declaration is the qualification statement. "We judged holders of Regulatory Expert competent to cover QMB" is precisely what an auditor asks about substitution arrangements — and here it is a witnessed judgment with a name and a date rather than tribal knowledge on a piece of paper. That is why the act is recorded, and why every edge in the list carries the date it was declared on.
It is per project. An edge declared in one project says nothing about any other, because competence to cover is a judgment about this operating model, not a global fact about two role names.
2. Declaring and withdrawing¶
The form is one sentence with two blanks: A holder of (role) may take over (role) → Declare cover. Both lists offer the roles activated in this project — the same roles the staffing surface can bind, read under the same authority the declaration itself needs, so what you are offered and what the server will accept are one rule rather than two.
Three things are worth knowing before you declare:
- A role cannot cover itself. That one is caught on the screen — the button stays disabled — because the server's answer to it would only be a sentence about a nonsense request.
- Only roles that carry content work can be taken over. The rule is stated under the form: "A role holding administrative authority is refused — cover for an absent administrator comes from the organization level." An edge into an administrative role would hand the master key through a side door, which is the one thing this mechanism must never do. The target list is deliberately not pre-filtered: the classification behind the rule is not something this screen is always allowed to read, and a client-side guess that quietly hid a legitimate role would be worse than a refusal that explains itself. So the refusal is the server's, in the server's own words, shown to you verbatim.
- Nothing here is transitive. A covers B plus B covers C grants a holder of A nothing at all toward C. Every edge is its own declared judgment, and competence does not compose.
Withdrawing an edge is the ✕ at the end of its row, behind a confirmation that names both roles and the consequence: "Regulatory Expert will no longer be able to take over QMB here. Anyone covering right now keeps their window until it closes." That last half is the honest part — withdrawal governs the next cover, and never yanks a role out from under somebody mid-act.
When nothing is declared, the section says so plainly rather than showing an empty box: "No cover is declared for this project. Nobody can take over a role here except through project administration." And in a project where no role is activated yet, there is nothing to declare cover between, which it also says.
3. Where the glass was broken¶
Under the matrix stands the second half of the tab: every timed staffing, extension, early end, expiry and cover declaration in this project, newest first.
Each line carries when, what, who, and the facts of the act itself — the role, the declared window, what the person was attempting, and which door they came through (project administration or a declared cover). The vocabulary is small and deliberate:
| The line reads | What it records |
|---|---|
| Took a role | somebody staffed themselves for a declared window — with the role, the window, the door and the note they left (for: move SOP-014 into Processes) |
| Extended | a fresh act with its own window, standing beside the original |
| Ended early | the role was given back before the window closed (through: given back early, when the holder ended it themselves) |
| Window closed | the declared window ran out — the actor column reads the system, because there was no person, and an audit line should never look blank |
| Cover declared / Cover withdrawn | the governance act above: which role may take over which |
Nothing is re-sorted and nothing is invented: the order is the server's, the times are the recorded moments in your language's format, and the acts are named in words.
Why this trail has its own surface. During the first months of an installation, this list is a rollout diagnostic: every break-glass act marks a place where the declared operating model missed reality — a permission nobody held, a role nobody was staffed into, a project that could not do its own work. Read together they say where the model needs fixing, which is a question about the system rather than about the people who worked around it. That is only readable because these are dedicated acts; had the same rescues been done as ordinary staffing, the signal would be buried in ordinary staffing.
If nothing has ever been needed here, the section says exactly that: "Nobody has broken the glass in this project."
4. Who may read and write it¶
They are two different authorities, and the tab says so rather than blurring them.
- Declaring and withdrawing needs the per-project authority over which roles exist here — the same permission the Document-types tab is gated on (activate roles and document types here). It is governance of the operating model, and it lives with the rest of it.
- Reading the trail needs access to this project's content. The history is an audit read, and an audit read is bound to the project it belongs to. A governor who administers this project without reading it is told so, without a request being sent: "Reading this project's break-glass history needs access to its content, which you do not have here. The history exists — ask someone who reads this project." A boundary stated is honest; an empty list would read as "we never broke glass here", which would be a lie.
As everywhere, the screen only reflects what you may do — the server decides, and a request made without the authority is refused whatever the screen shows.
5. What emergency cover is not¶
- It is not planned absence. The windows are short and the question is "the role-holder is unreachable and the act is stuck now". A colleague on holiday is covered by ordinary, deliberate staffing of a deputy, decided in advance by whoever staffs. Folding planned absence into the self-service path would normalize the exceptional act, which is the failure this whole design exists to prevent: the matrix is glass to break, not a rota.
- It is not impersonation. A substitute approving as QMB is a different person approving, and the record says so: she held QMB, from then until then — never she acted for him. That distinction is the entire reason four-eyes means anything.
- It does not cross projects. Cover between scopes would be staffing, not substitution, and staffing is what the administration surfaces are for.
- It is not a permission grant. An edge grants nothing by itself. Until somebody is refused something and chooses to take the role, with a window and a record, an edge is a statement of judgment and nothing more.
Governing decisions: ADR-0131 (role substitution as declared adoption edges — per-scope, own-name, content-class targets only, no transitive and no cross-scope edges), ADR-0130 (the timed-staffing mechanism the edges stand on, and the trail that records it), ADR-0128 (the permission classification that makes "content role" a structural fact the refusal can be built on), ADR-0117 (acting-as and impersonation rejected — why cover is staffing in your own name), ADR-0073 (the scope-configuration surface: a new governance area earns a tab), ADR-0012 (permissions are enforced server-side), ADR-0007 (never show an affordance the server refuses; refusals are shown in the server's own words). Regulatory frame: ISO 13485 §5.5.1 (responsibility and authority — including who may deputize for whom), §4.2.5 (control of records).