Work / DwarSeva Societies / Wiki / Concepts
role-gate
Conceptcanonicalverified 2026-10-04
CONCEPT.ROLE-GATESummary
The mobile app is three apps behind one gate: index.tsx reads the signed-in user's first society membership and redirects to the resident, admin or guard tab set.
Why it matters
Nothing in the app lets a user choose a role. The gate decides, from data, and every screen that finishes a sign-in or an onboarding step returns to it with router.replace("/"). Get the gate wrong and a user lands in an app they cannot use.
Implications
- Signed out → sign in. Signed in with no membership → not-in-society.
isSuperAdmin,SOCIETY_ADMINorSUPER_ADMIN→ the admin tabs.SECURITY_HEADorSECURITY_GUARD→ the guard tabs. Anything else → the resident tabs.- The gate reads
societyMemberships[0]. The layouts then re-check with the selected membership (useScope().activeRole), which can differ for a user in two societies. - A security head cannot use the app. The gate sends
SECURITY_HEADto the guard tabs;guard/_layout.tsxredirects every role butSECURITY_GUARDto Profile. - A guard cannot reach Profile or log out. The guard tabs set
headerShown: false, so the avatar that opens Profile never renders. - A member whose membership is
PENDING_APPROVALpasses the gate and is stopped inside the tabs byActiveSocietyProtected— thelockedstate. - The redirects name route groups (
/(roles)/admin), not screens. Whether expo-router resolves a group with no index route to its first tab has not been verified on a device.
Related
Sources
- apps/mobile/src/app/index.tsx
- apps/mobile/src/app/(roles)/guard/_layout.tsx
- apps/mobile/src/components/society/ActiveSocietyProtected.tsx