Authentication foundation

Sign-in architecture

Email/password and passwordless email-link patterns are prepared for a later reviewed strategy. Neither method is active.

Recovery and invitations

Controlled access assistance

Family access will not use open self-registration.

Account recovery

Future recovery will handle forgotten passwords, expired links, invalid tokens, changed email addresses, and account assistance without revealing whether an email has an account.

Invitation required

An administrator-issued invitation will establish an intended email, initial role, expiration, approval state, and revocation history.

Access help

Approved archive access-help instructions will be added before activation. No private contact details are published here.

Read how the archive protects family information

Least privilege

Roles and account status are separate checks

Authentication alone never grants administrator or restricted-record access.

Future roles

  • Family Member
  • Restricted Family Member
  • Contributor
  • Steward
  • Administrator

Roles do not replace record-level permissions or RLS.

Future account states

  • Invited
  • Active
  • Pending Approval
  • Suspended
  • Disabled
  • Archived

Only an active account may proceed to authorization checks.