Security & Permissions · August 2026 · V1

Security & Permissions

Make access understandable before it becomes a hidden database rule: who can see, change, administer, share, export, or perform sensitive actions.

Account Security

Sign-in methods, recovery, sessions/devices, security events and sensitive account actions.

Household Roles

Member roles and permissions without confusing family relationships with authorization.

Record Privacy

Member-specific or restricted information, visibility indicators, and reason for restriction.

Sharing & Export Controls

Who may share externally, export data, preserve evidence, or grant successor access.

Example capabilityViewEditAdmin
Household record
Sensitive member recordPolicyPolicyPolicy
Administration
Critical rule: unauthorized and restricted are explicit product states. The UI must never infer permission from role labels, household relationships, or client-side assumptions.