Account recovery
Future recovery will handle forgotten passwords, expired links, invalid tokens, changed email addresses, and account assistance without revealing whether an email has an account.
Protected family access
Private archive access will be available only to approved accounts after authentication and authorization controls are activated.

A sign-in proves identity. Server-side role, account-status, explicit-permission, and database-policy checks must separately authorize every protected request.
Family access will be invitation-only. Open public registration is not enabled.
Authentication foundation
Email/password and passwordless email-link patterns are prepared for a later reviewed strategy. Neither method is active.
Recovery and invitations
Family access will not use open self-registration.
Future recovery will handle forgotten passwords, expired links, invalid tokens, changed email addresses, and account assistance without revealing whether an email has an account.
An administrator-issued invitation will establish an intended email, initial role, expiration, approval state, and revocation history.
Approved archive access-help instructions will be added before activation. No private contact details are published here.
Least privilege
Authentication alone never grants administrator or restricted-record access.
Roles do not replace record-level permissions or RLS.
Only an active account may proceed to authorization checks.