DocumentationAdministration

Rust · 0.1.0

Administration

Manage users and instance-wide policies while keeping account access, space membership and memo visibility distinct.

Separate the three access decisions

Instance administration governs the service as a whole. Space membership controls a collaboration group. Memo visibility and share links govern individual records. Giving someone an account, putting a memo into a space and creating a share link are different actions; validate the intended result with the actual recipient's permissions.

You want to…Start here
Change registration, access policy or a providerInstance settings
Manage a user's role or account stateUsers and roles
Invite someone into a collaborative collectionSpaces
Share one memoVisibility and share links

Use a repeatable change procedure

Perform one policy change at a time. Keep an administrator recovery route before altering sign-in. If a setting is deployment-managed, the application is not its editing authority; ask the deployment operator to update the mounted configuration.

  • Record what behavior should change and for which accounts
  • Check the current value and save a non-secret rollback note
  • Apply the smallest change through the correct settings section
  • Verify with a regular account and a signed-out session where relevant
  • Record the outcome and revoke any temporary access used for the check

Test the user experience, not just the admin view

An administrator's successful request does not prove that ordinary members can perform the same operation. Check a test user's sign-in, allowed memo list, target-space membership and attachment access. When a permission error occurs, identify the resource and its owner before widening a role or making content public.

Handle removal as a data decision

Account archival, membership removal, memo archival and deletion have different consequences. Before deleting a space, preserve records that must survive: its current memos are deleted with it. Review token, identity-provider and share-link access separately when a person no longer needs access. Use backup and restore before bulk administrative work.

Guides in this section