← Auth / Security

Profile / Account

auth / security · wireframes · user-facing shell loading

Personal account: your details, password change, sessions.

Wireframe
  1. 1 Email — read-only, the login identifier. Changed by the administrator in Admin Panel.
  2. 2 Role — read-only; users cannot change their own role. Assigned by an Owner / Admin in Admin Panel.
  3. 3 Language and region — a personal override of the organization defaults (timezone, UI language, date format). Affects display only. Mechanics — Language and region.
  4. 4 MFA v2 — required for Owner / Admin, optional for Member. Setup — Two-factor authentication.
  5. 5 Active sessions — a device list with per-device revocation. Screen — session management.
  6. 6 “Sign out on all devices” ends every session; a regular “Sign out” ends only the current one. Mechanics — Ending a session.
  7. 7 Password rules — Password policy. The new password must differ from the current one.
  8. 8 Strength indicator — a strength estimate as you type.
  9. 9 Changing the password requires entering the current one. Mechanics — Change password. v2: the current password replaces sudo-mode via re-auth-modal.
  10. 10 An optional name labels the key above its prefix; “Rename” edits it in place — the name is the owner's, even when an Owner / Admin set a starting value at issue. An unnamed key shows the prefix alone.
  11. 11 API keys — the user issues and revokes their own keys. “Create key” opens the creation dialog. Mechanics — API keys.
  12. 12 Each type has two independent toggles, in-app and email; turn off either or both — there are no bindings or locks. Organization types (Sync · Security · Budget · System · Discovery) are visible only to Owner / Admin — they alone are the recipients of these alerts. Shared team webhooks (Slack / Ops) and organization defaults — Notifications in Admin Panel.
  13. 13 Personal types (Agent — runs of the user’s own agents; Account — role, temporary password) reach every user, including members — these are targeted events aimed at the person themselves. Email for them is off by default (opt-in); in-app shows immediately.