DocumentationAdministration
Rust · 0.1.0
Users and roles
Distinguish instance administration from space membership.
Instance accounts
Instance users have an administrator or ordinary-user role and an active or archived state. Administrative membership management is separate from signing up to an instance. Review registration settings before inviting people. Use a normal account to confirm the experience available to members rather than relying on an administrator session.
Space roles
A space has its own membership and invitations. Creating a space makes the creator its initial administrator. Inviting an existing active account and accepting the invitation establishes membership. Instance administration is not the same as being a space member, and ownership or membership changes should be checked against the operation's access rules.
Destructive changes
Read confirmation dialogs carefully. Deleting a space permanently removes the memos currently placed in it; memo relations do not expand that deletion into unrelated notes. Do not treat account archival, memo archival and deletion as interchangeable. Keep a recoverable backup before bulk administrative changes.
Create and suspend a test member
As an instance administrator, open Settings → Member and choose Create. Enter a unique username and an initial password, choose the ordinary User role unless this person needs instance administration, then save. In a separate session sign in as the new user and confirm the expected ordinary interface. Deliver credentials through an appropriate private channel, never through a public memo. In the member’s action menu, Archive changes an active account to archived; Restore changes it back. Verify the username in the confirmation. Deletion is a separate permanent-data operation and is not needed to suspend access.
Then add space membership separately
An existing account does not automatically join every space. Use Spaces to invite it, choose its space role and have the recipient accept. In a test, keep one ordinary account outside the space and confirm that it cannot read a SPACE memo. Never use an instance administrator session for this negative access test, because administrators have privileged named-resource access.