Guide / Security
Keep authority separate from identity.
Ranks and badges describe community identity; they never grant administrative authority.
Start here. Use the Security workspace to review factors and sessions. Administrative actions require a live grant and a strong authenticated session.
- 01
Protect sign-in
Use a passkey or authenticator where available. Complete the stronger verification prompt before protected administrative actions.
- 02
Review active sessions
Inspect sessions you recognize and revoke access you no longer trust. A revoked or suspended session must not regain access through an older page or direct request.
- 03
Separate rank from authority
Community rank, badge, featured status, and profile appearance do not confer administrator access. Owner protection and live delegated grants remain independent.
- 04
Report without oversharing
Bug reports include a bounded page and device context, never sign-in secrets, private form values, or profile drafts. Add only the minimum proof needed to reproduce a problem.