Public platform guide

How GCSI works

A clear public record of what the platform can do, who can do it, what happens after an action, and how notifications, review and recoverability work.

Operating model

Four rules behind the platform

These rules apply across recipes, knowledge contributions, moderation and account communication.

01

Human publication authority

Submitting content does not make it public. Publication and sensitive editorial decisions remain controlled by authorised people.

02

Clear ownership

Members control their own profile and permitted contributions. Administrators have defined moderation and publication powers rather than silent ownership of a contributor’s work.

03

Recoverable actions

Where practical, hide, archive and delete actions preserve a private record so mistakes can be investigated or reversed instead of destroying context.

04

Traceable communication

Important platform events create durable records. Email delivery is separate from the underlying action, so a failed email cannot repeat a publication or deletion.

Permissions

Who can do what

Capabilities increase with account verification and assigned roles. A higher role does not remove audit or review safeguards.

Visitor

Anyone using the public website without signing in.

Can
  • Read published Knowledge Hub articles
  • Browse published recipes
  • Use public restaurant, research and Academy information
  • Open public member profiles when a member has chosen to publish one
Cannot
  • Post comments
  • Save or like as a member
  • Submit recipes
  • Access private editorial, administration or account records

Member

A person with an active, verified GCSI account.

Can
  • Like and save recipes
  • Submit moderated recipe comments
  • Manage account, profile and notification preferences
  • Suggest evidence-based Knowledge Hub edits where the contribution interface is available
Cannot
  • Publish content directly
  • Approve their own contribution
  • See another member’s private records or communication history

Approved recipe contributor

An active member whose recipe-submission access has been approved by a GCSI administrator. This is an additional capability, not a separate core account role.

Can
  • Submit an original recipe and photographs
  • Edit their own recipe
  • Delete their own recipe with a recoverable soft-delete
  • Respond to requested changes and resubmit for review
Cannot
  • Publish their own recipe
  • Edit or delete another contributor’s recipe
  • Bypass gluten-safety, nutrition-claim or publication checks

Reviewer / editorial role

A member granted a defined editorial role for Knowledge Hub governance.

Can
  • Review or assess assigned contributions according to role
  • Record editorial decisions
  • Use the review trail and conflict safeguards
Cannot
  • Self-review where safeguards prohibit it
  • Publish outside the authority granted to the role

Administrator

A restricted GCSI administration account.

Can
  • Approve recipe contributors
  • Edit, publish, hide, archive, restore or soft-delete recipes
  • Moderate recipe comments and reports
  • Manage editorial operations and newsletters
  • Preview/test branded emails
  • Inspect delivery health, privacy-limited communication history and email suppressions
Cannot
  • Erase the audit trail through normal editorial controls
  • See reusable verification codes or reset tokens in communication history
  • Send test-email previews to arbitrary third-party addresses
  • Turn a safety claim into a guarantee of zero-risk dining

Feature reference

Functions and workflows

Each section explains the normal path a person follows rather than exposing internal implementation details.

Live

Accounts, sign-in and profiles

Verified member accounts with privacy-controlled profiles, context-preserving authentication and member-visible session security.

#
  1. Create an account with email and a profile ID, or continue with a verified Google identity.
  2. Email sign-up requires a six-digit verification step before the account becomes active. Verification codes are short-lived, single-use and are not displayed in administrator logs.
  3. When a visitor starts a sign-in-required action from a recipe, GCSI preserves the safe internal return destination and brings the person back to that recipe after authentication instead of sending them to an unrelated dashboard page.
  4. Profile visibility is private by default and can be changed in Account settings.
  5. Password recovery and important account-security messages use the sign-in email and cannot be disabled when required to operate or protect the account.
  6. Account settings show the active session generation for this account using a protected session fingerprint and a broad browser/device label. Raw PHP session identifiers and IP addresses are not stored in the member session registry.
  7. A member can choose Sign out other sessions. GCSI invalidates every other current or older account session while keeping the device used for the security action signed in.
Live

Recipe contribution and publication

Contributor-owned submissions with administrator publication authority and revision feedback.

#
  1. A GCSI administrator first approves recipe-submission access for an eligible member.
  2. The contributor opens Recipes → Submit a recipe and enters the recipe, safety notes, nutrition information and original photographs.
  3. The submitted recipe remains private while it is reviewed.
  4. An administrator can publish it, request specific changes, reject it, or keep it private.
  5. Requested-change feedback remains attached to the recipe management record so the contributor can revise it without relying on an email alone.
  6. After publication, a contributor edit returns the recipe to private review before the revised version can be public again.
  7. Recipe submission uses a guided section navigator so contributors can see where they are and move directly between dish basics, timing, method, gluten safety, nutrition and photographs.
  8. Draft recovery runs quietly while a contributor works. Recovery information is surfaced when it is actually useful, such as after an interrupted or invalid submission, rather than occupying permanent form space.
  9. Nutrition information remains visible when a contributor reaches that section. Europe and United States previews use the same stored recipe values but show the terminology and units appropriate to each public presentation.
Live

Editing, hiding and deleting recipes

Clear ownership controls with recoverable removal rather than silent destruction.

#
  1. A recipe contributor can open their own recipe management screen to edit or delete their recipe.
  2. Administrators use a compact Manage control on the public recipe page and the full controls inside the administration editor.
  3. Hide/archive removes a recipe from public view while retaining its record for possible restoration.
  4. Delete is a soft-delete: the public recipe is removed, the action is audited, and the record can be restored administratively if deletion was accidental.
  5. Deleting or hiding a recipe does not silently erase contributor attribution or audit history.
Live

Recipe comments and reports

Member participation with moderation and a private reporting route.

#
  1. Signed-in members can submit recipe comments and permitted photographs.
  2. Comments are moderated before becoming public.
  3. A member can privately report a recipe concern to GCSI.
  4. The reporter can receive status updates when a report is investigated, resolved, dismissed or reopened.
  5. A private report is not automatically disclosed to the recipe author.
Live

Knowledge Hub contributions

Referenced improvements are reviewed before changing public guidance.

#
  1. Members can propose supported corrections or edits where contribution tools are enabled.
  2. The public article remains unchanged while the contribution is reviewed.
  3. Reviewers record a decision and the contribution history remains attributable.
  4. Accepted changes become part of the public version only after the required human review.
Live

Notifications, email and newsletter

Account-connected updates with member-controlled categories/frequency, deterministic priority and grouping of related activity.

#
  1. Essential account messages include verification, password recovery, important security/privacy notices and the one-time welcome message.
  2. Activity notifications cover eligible contribution, recipe, community, research, Academy, restaurant and platform events.
  3. Members choose whether optional activity email arrives as events happen, weekly, monthly or not by email at all.
  4. Newsletter consent is separate, off by default and never required for an account.
  5. The protected delivery worker processes queued activity, essential and newsletter email independently of page requests, with retry controls and durable event keys designed to prevent duplicate business actions.
  6. Hard-bounce, complaint and administrator suppression records can stop further delivery without exposing raw recipient addresses in the suppression registry. A soft bounce is recorded but does not automatically become a permanent suppression.
  7. In-app notifications remain connected to the member account and can be read independently of email delivery.
  8. The in-app notification centre orders action-required activity such as review assignments or requested changes ahead of routine account activity, followed by important decisions and then normal activity.
  9. Related notifications about the same record are grouped into one logical update. Opening or marking that group read updates the underlying notification records together.
  10. Priority changes ordering and presentation only. It never bypasses a member’s category or email-frequency preferences and does not convert optional activity into essential account email.
Live

Privacy and analytics choice

Google Analytics is consent-gated and limited to eligible public pages.

#
  1. GCSI does not load the Google Analytics tag on an eligible public page until the visitor chooses to allow analytics, unless that device already holds a prior allow choice.
  2. Choosing Only necessary keeps analytics off. The visitor can change the choice later from Cookie settings in the public-site footer.
  3. The analytics integration uses measurement ID G-QB2ZH9G6TD. Advertising storage, ad user data and ad personalisation are disabled in the GCSI integration.
  4. Administration, authentication/recovery, dashboard, settings, profile management, recipe submission, saved recipes and private recipe-management surfaces are excluded from this analytics integration.
  5. The analytics choice is stored on the visitor’s device so the preference can be applied on later eligible public pages.
Live · administrator only

Communication delivery, previews and audit

Administrators can inspect delivery, preview branded templates and manage suppression without exposing reusable account-security credentials.

#
  1. The delivery-health view shows configuration readiness, queue state and recent worker/delivery outcomes without displaying credentials or recipient lists.
  2. Email & notification history distinguishes verification, password reset, welcome, activity and newsletter records and shows sent, failed, pending, retry or skipped states where available.
  3. The Communications studio can render the same branded HTML template used for production delivery and can send a marked test only to the currently signed-in administrator’s own verified account.
  4. Email suppressions record protected recipient identifiers for hard-bounce, complaint or manual-suppression events. Provider feedback requires a separately signed webhook integration before automatic callbacks become active.
  5. Recipient email addresses are masked in administration history; known members may be identified by their account name/profile ID.
  6. Verification codes and password-reset tokens are never displayed in communication history. Account codes are stored as one-way HMAC values rather than reusable plaintext.
  7. A “sent” delivery state means the configured mail transport accepted the message; it does not prove that a person opened or read the email.
Live

Review, permissions, audit and recoverability

Important editorial and administrative actions are role-controlled, recorded and designed to be recoverable where appropriate.

#
  1. Publication decisions remain human-controlled.
  2. Role checks restrict administration and editorial actions; an administration Roles & permissions matrix documents the current production authority model.
  3. Conditional permissions such as recipe contribution, recipe ownership and assigned review still require the underlying capability or assignment in addition to an account role.
  4. Audit records capture relevant actions with actor, time and context.
  5. Observability pages are designed to inspect system state rather than modify application data simply by being viewed.
  6. Notification delivery is decoupled from the underlying content action, so an email failure does not repeat or roll back a recipe or editorial decision.
Live

Public service status and incident history

A public, dependency-light record of confirmed GCSI service incidents without exposing private operational diagnostics.

#
  1. Anyone can open /status to see confirmed incidents affecting Website & public content, Member accounts, or Email & notifications.
  2. The public status page is deliberately separate from GCSI’s private operational-health dashboard. Internal alerts and diagnostic thresholds do not automatically become public outage claims.
  3. An administrator first creates a private incident draft, checks the impact and public wording, then explicitly publishes the incident when the facts are sufficiently confirmed.
  4. Published incidents receive timestamped Investigating, Identified, Monitoring and Resolved updates. Resolving an incident moves it into the public history rather than silently deleting it.
  5. The absence of a published incident means no confirmed incident is currently published; it is not a promise of uninterrupted service or exhaustive monitoring.
  6. The public incident ledger is file-backed and does not require the application database to render. If that ledger cannot be read, the page shows Status information temporarily unavailable rather than a green state.

Communication policy

What notification or email follows which event

Essential account messages, optional activity updates and the newsletter are intentionally separate. Newsletter consent is never required to use a GCSI account.

Essential account email Optional activity email Separate newsletter consent
AreaEventWho receives itIn-appEmailUser control
Account Verify email New email-account member No Essential · immediate Required to activate an email/password account
Account Welcome to GCSI Newly activated member Yes Essential · one time Account service message
Account Password recovery Account owner No Essential · immediate Cannot be disabled
Account Important privacy/security notice Affected member(s) Yes Essential Cannot be disabled when needed to operate or protect the account
Recipes Contributor access approved/revoked Member Yes Optional activity Contribution notification preference
Recipes Recipe submitted Eligible participant(s) Yes Optional activity where configured Contribution notification preference
Recipes Changes requested Recipe contributor Yes Optional activity Contribution notification preference
Recipes Recipe published / accepted Recipe contributor Yes Optional activity Contribution notification preference
Recipes Recipe rejected, hidden, restored or admin-deleted Recipe contributor Yes Optional activity Contribution notification preference
Community Moderated comment becomes public on your recipe Recipe contributor Yes Optional activity Community notification preference
Community Recipe report status changes Person who filed the report Yes Optional activity Community notification preference
Knowledge Contribution reviewed / accepted / rejected / further review Contributor Yes Optional activity Contribution notification preference
Knowledge Review assignment Eligible reviewer Yes Optional activity Contribution notification preference
Academy Learning progress, credential or expiry Learner Yes Optional activity when implemented for that event Academy notification preference
Research Eligible study / research update / result Relevant member Yes Optional activity when implemented for that event Research notification preference
Restaurant Index Evidence or reassessment update Relevant member Yes Optional activity when implemented for that event Restaurant notification preference
Newsletter GCSI newsletter Explicitly subscribed, verified members No Optional newsletter Separate opt-in; can be withdrawn at any time
Delivery principle. In-app notifications are the durable account record for eligible activity. Optional email may be immediate or grouped into a weekly/monthly digest according to member settings. Essential verification, recovery and security messages are not placed behind optional marketing preferences.

Version history

Public release record

This guide changes when public behaviour or permissions change materially.

Versionv2026.08.8
  • A public /status page now provides confirmed service incidents and recent resolved incident history using coarse, public-safe service components.
  • Public incident publication is human-controlled: internal monitoring can trigger investigation but does not automatically publish an outage or expose private diagnostics.
  • The public status ledger is intentionally independent of MySQL so a database incident cannot by itself prevent the public incident record from rendering.
  • Administrators draft incident wording privately before publication, then publish timestamped updates through resolution; published incidents remain in public history.
Versionv2026.08.7
  • The public cookie choice now uses familiar Necessary only and Accept analytics language; optional analytics remain off until consent and technical provider details remain available in Privacy.
  • Recipe submission now uses a persistent guided section navigator and a persistent review action bar while draft recovery continues quietly in the background.
  • Optional nutrition entry stays visible and the Europe/United States preview now changes labels immediately, including before every nutrition value has been entered.
  • Public recipe pages now separate Report a concern from the primary Like, Save, Comment and Share actions, use visual cooking facts, correct gallery arrows and a single verified identity mark.
  • After submission, contributors stay in recipe submission and receive a warmer confirmation with a direct path to their submission status.
Versionv2026.08.6
  • Account-connected notifications now use three deterministic presentation priorities: Action needed, Important and Activity.
  • Related in-app notifications about the same record are grouped so repeated routine events do not push review assignments, requested changes or important decisions out of view.
  • The immediate optional-email worker processes action-required notifications before routine optional activity while still respecting the member’s category and frequency preferences.
  • Administration moderation inboxes now share the same queue navigation and status language across Knowledge corrections, recipe reviews, community posts, recipe reports and integrity reports.
Versionv2026.08.5
  • Account settings now include a Security section showing active signed-in sessions with broad browser/device labels and localised last-active times.
  • Members can sign out every other session while keeping the current device signed in; older sessions created before the device registry are invalidated as well.
  • The member session registry stores a protected HMAC fingerprint and session generation rather than raw PHP session identifiers, and it does not store IP addresses or raw user-agent strings.
Versionv2026.08.4
  • Google Analytics measurement G-QB2ZH9G6TD is now available on eligible public pages only after the visitor allows analytics.
  • A GCSI analytics preference banner and reusable Cookie settings control let visitors allow or turn off analytics on their device.
  • Advertising storage, ad user data and ad personalisation remain disabled in the GCSI analytics integration, and private account/administration/contribution-management surfaces are excluded.
  • The Privacy page now documents the current analytics choice and relevant platform privacy behaviour.
Versionv2026.08.3
  • A searchable “What do you want to do?” task navigator now connects common actions directly to the detailed public workflow.
  • Administration gained a branded email preview and safe test-send studio; tests can only be sent to the signed-in administrator’s own verified email.
  • Email hard-bounce, complaint and manual-suppression records can stop further account, activity and newsletter delivery; provider callbacks require a separately signed integration.
  • Administration gained a current Roles & permissions matrix that distinguishes core roles from conditional capabilities such as recipe-contributor approval and assigned review.
  • Production releases now include automated communication-contract checks, documentation-impact enforcement and browser smoke tests for critical public UX and protected-route reliability.
Versionv2026.08.2
  • Authentication now preserves the originating recipe context for sign-in-required recipe actions such as Like and Save.
  • Administrator navigation was unified so administration destinations remain consistent across modules.
  • Recipe Community moderation was redesigned as a focused administration workspace.
  • Notification and email health was changed to read-only, failure-tolerant observability.
  • Administrators gained privacy-limited Email & notification history for verification, password reset, welcome, activity and newsletter delivery records.
  • Communication history deliberately excludes reusable verification codes and reset tokens; “sent” means transport accepted the message, not that it was opened.
Versionv2026.08.1
  • Versioned public platform guide introduced.
  • Recipe owner/admin management and recoverable deletion documented.
  • Account, recipe and community notification flows formalised.
  • Email delivery health and retry-safe notification projection introduced for administrators.
  • Newsletter consent separated from activity-notification settings.

This page documents platform behaviour and governance. It is not a medical guarantee, legal guarantee, or statement that dining can be made completely free of risk.