Skip to content

Assessment Editor

Verified Role confirmed via live testing on 2026-03-16.

Assessment Editor Dashboard — showing sidebar with 10 items (excessive permissions bug)
PropertyValue
Usernameassessment-editor
PurposeCreate and edit NCAP vehicle safety assessments
ScopeDraft and Re-Edit stages of the assessment workflow
PrincipleCan author content but cannot approve, publish, or govern

The Editor currently sees 10 sidebar items — significantly more than the intended 4.

Dashboard
└─ Overview (/admin/dashboard)
Assessments (/admin/assessments)
Protocols (/admin/protocols)
Vehicles
├─ Makes (/admin/vehicles/makes)
├─ Manufacturers (/admin/vehicles/manufacturers)
└─ Manufacturer Re... (/admin/manufacturer-requests)
System Configuration
├─ Lookup Tables (/admin/admin/lookups)
└─ Child Restraints (/admin/admin/crs)
Website Manager
└─ Media Library (/admin/content/media)
  • URL: /admin/
  • Stats cards: Total Vehicles (57), Assessments (58), Avg. Adult (5.0), Avg. Child (4.9), Makes (10)
  • Quick Actions: New Assessment, Add Vehicle, Content Pages
  • Assessment Summary: Counts by status — Draft, Re-Edit, Under Review, Approved, Published, Unpublished, Archived
  • Additional sections: Star Rating Distribution, Recent Activity
  • Read-only informational page
Assessment Editor — Assessments list with +New Assessment, Export CSV, and delete icons on all rows
  • URL: /admin/assessments
  • Action buttons: ”+ New Assessment” (green), “Export CSV” (outlined)
  • Filters: Search text, Status dropdown, Adult rating, Child rating
  • Columns: Vehicle, Year, Status, Adult rating, Child rating, Completion %, Actions
  • Per-row actions: View (eye icon), Delete (trash icon)
  • Statuses observed: Draft, Published, Under Review
  • URL: /admin/protocols
  • Read-only — only a view (eye) icon per row, no create/edit/delete
  • Columns: Code, Name (English), Name (Arabic), Status, Versions, Actions
  • Data: 1 protocol — SAUDI_NCAP / Saudi NCAP / Active / 1 version
  • URL: /admin/vehicles
  • Card grid with logo, English/Arabic name, model count per make
  • ”+ Add Make” button available
  • Makes include: Toyota, Honda, Nissan, Hyundai, Kia, GMC, Ford, BMW, Mercedes-Benz, Lexus
  • URL: /admin/vehicles/makes
  • Title: “Manufacturers (Makes)” — confusing naming (see ISS-010)
  • Columns: Logo, Name (Arabic), Name (English), Slug, Country, Status, Models, Actions
  • Per-row actions: Edit (pencil), Delete (trash)
  • Full CRUD available
  • URL: /admin/vehicles/manufacturers
  • ”+ Add Manufacturer” button
  • Columns: Name (Arabic), Name (English), Brands, Actions
  • Per-row actions: Edit (pencil), Delete (trash)
  • Full CRUD available
  • URL: /admin/manufacturer-requests
  • Read-only — no create/edit/delete buttons
  • Columns: Company (with contact), Vehicle, Status, Date
  • URL: /admin/admin/lookups
  • Card grid with 4 categories: Body Types (9), Fuel Types (5), Drive Types (4), Transmission Types (4)
  • View-only at top level; sub-pages may have edit capability
  • URL: /admin/admin/crs
  • ”+ Add CRS” button, search field
  • Columns: Brand, Name (EN), Name (AR), Category, Type, ISOFIX, Active, Actions
  • Full CRUD available
  • URL: /admin/content/media
  • Upload zone (drag & drop), accepted: JPG, PNG, WebP, SVG, PDF (max 100MB)
  • Folder navigation, content type filters (All, Images, PDF Reports, Videos)
URLResult
/admin/usersPage Not Found
/admin/monitoringPage Not Found
/admin/administrationPage Not Found

All restricted URLs show “Page Not Found” instead of “Access Denied” (see ISS-006).

ActionScreen
View dashboard with statsOverview
Create new assessmentsAssessments
View/open assessmentsAssessments
Delete assessments (currently — bug)Assessments
Export CSVAssessments
Search/filter assessmentsAssessments
View protocols (read-only)Protocols
Add/edit/delete makesMakes
Add/edit/delete manufacturersManufacturers
View test requestsManufacturer Test Requests
View lookup tablesLookup Tables
Add/edit/delete CRSChild Restraints
Upload mediaMedia Library
ActionEvidence
Access user management/admin/users → Page Not Found
Access monitoring/audit logs/admin/monitoring → Page Not Found
Create or edit protocolsNo add/edit buttons
Manage content pagesNo Pages link in sidebar
Approve/reject assessmentsNo approve/reject buttons
Publish/unpublish assessmentsNo publish actions
  1. Broader access than intended — Editor has Vehicles, System Config, and Media Library access that should be Super Admin-only
  2. Delete on all rows — Trash icon appears on Published assessments, not just own Drafts
  3. Two views for Makes — Card view (/admin/vehicles) and table view (/admin/vehicles/makes)
  4. Content Pages anomaly — Dashboard shows quick action card but no sidebar entry
  5. Sidebar truncation — “Manufacturer Representatives” shows as “Manufacturer Re…”