Skip to guide
NIHAOWRLD / 001

Guide / Security

Keep authority separate from identity.

Ranks and badges describe community identity; they never grant administrative authority.

Start here. Use the Security workspace to review factors and sessions. Administrative actions require a live grant and a strong authenticated session.

  1. 01

    Protect sign-in

    Use a passkey or authenticator where available. Complete the stronger verification prompt before protected administrative actions.

  2. 02

    Review active sessions

    Inspect sessions you recognize and revoke access you no longer trust. A revoked or suspended session must not regain access through an older page or direct request.

  3. 03

    Separate rank from authority

    Community rank, badge, featured status, and profile appearance do not confer administrator access. Owner protection and live delegated grants remain independent.

  4. 04

    Report without oversharing

    Bug reports include a bounded page and device context, never sign-in secrets, private form values, or profile drafts. Add only the minimum proof needed to reproduce a problem.