Skip to main content

Users & Identity

The Users & Identity area gives authorized Starfire operators a platform-wide view of account state without requiring direct database access. The NEXUS People & Identity 4.0 work expands this beyond a basic user table into a deeper account-management and diagnostics surface.

User detail

A user record can bring together operational context such as:
  • account identity and verification state
  • plan and subscription context
  • organization memberships
  • credit balance and monthly allowance
  • usage
  • storage
  • projects
  • files and artifacts
  • FORGE builds
  • research runs
  • sessions and devices
  • developer access
  • security events
  • audit history
Not every operator should be able to modify every field.

Account states

The administration model is designed to support more nuance than only active/banned. Account states can include concepts such as:
A state change should preserve the reason, timing, and administrator context when supported by the active backend.

Restrictions

A user can be restricted without deleting or completely disabling the account. Examples of narrower restrictions can include:
  • uploads disabled
  • FORGE disabled
  • Developer Platform disabled
  • web search disabled
  • lower file limits
  • model restrictions
  • reduced research/build limits
This is safer and more flexible than using a full suspension for every policy or support issue.

Per-user feature overrides

Some features can use an inherited default plus a user-specific override:
Potential override categories can include FORGE, Knowledge, web search, developer access, experimental models, memory, uploads, or other configurable features.

Model access

User detail can show effective model access and limits based on plan, platform configuration, organization policy, and user overrides. Administrators should distinguish:
  • inherited access
  • explicitly allowed
  • explicitly denied
  • unavailable because the model/provider itself is not healthy or published

Credit administration

Authorized billing/support operators can inspect where credits are being consumed and, when permitted, apply audited adjustments such as bonuses, temporary credits, allowance changes, or hard ceilings. Do not use manual credit changes to hide a broken subscription or reconciliation problem.

Sessions & devices

Operators can use session/device state when responding to account-security or support issues. Administrative actions can include revoking sessions or requiring recovery steps according to permission and policy.

Support diagnostics

A support operator often needs diagnostics—not unrestricted account control. Support Mode is intended to expose information such as account status, client version, sync health, request IDs, failed API requests, and storage/indexing state with a narrower permission boundary.
User administration is highly privileged. Viewing operational metadata does not automatically authorize viewing private user content, modifying billing, changing model access, or assuming the user’s identity.

RBAC & Support Mode

Control who can perform user, billing, security, and support actions.

Security & Audit

Review sessions, events, admin actions, and account-security signals.