Verified ownership and recovery
Email verification, secure local-account reset, and recovery controls must be designed together.
Identity architecture ยท foundation contract
The intended provider options resolve to a canonical person record. A successful sign-in establishes who the user is; it does not establish a tenant, role, or permission.
Required before production
Email verification, secure local-account reset, and recovery controls must be designed together.
Linking a provider must require fresh proof and must not trust an email match alone.
Issuance, rotation, expiry, revocation, device visibility, and secure cookies need an approved operational model.
Sign-in, failure, verification, recovery, MFA, linking, session, and administrator actions require durable evidence.
Current truth
This foundation defines the boundary and proves tenant authorization with an explicit local development identity. Provider selection, callbacks, secrets, policy updates, and production operations remain separate decisions.