Primary Continuum owner. Ownership and recovery cannot be silently transferred or self-granted.
Access & Security
Review canonical account identity and tracked Owner browser sessions. Access grants, capability and Authority remain separate and are not created by authentication.
Identity & credentials
Display identity, login email, Owner/User role presentation, password changes, future passkeys and recovery methods belong here.
A valid authenticated browser session is required before Continuum projects account identity. The page never infers an account from Restricted Node or Check In authentication.
Signed-in sessions
Server-side AccessSession state is authoritative. Session management never becomes an access grant, capability or Authority editor.
Continuum loads the backend session ID, creation time, expiry and current-session flag through the tracked Owner browser session when that backend capability is available in the current environment.
No session truth is inferred from the Restricted Node bootstrap session, navigation state or browser-local data.
Current session
Server-marked currentCanonical session state has not been loaded.
Other sessions
0 activeOther sessions will appear only from the protected backend contract.
What this session contract can verify
AccessSession v1 exposes stable session ID, creation time, expiry and whether a session is current. It does not expose device, browser, IP address or revoked-session history. Revoked and expired active sessions disappear from the active list. The Owner browser path always requires a tracked cookie-backed current session. Legacy sid-less bearer JWT compatibility is not used as the normal browser path; if a tracked-session requirement cannot be satisfied, the UI fails closed.
Who can use Continuum
An Account is not a Directory Person, and Account roles never create consequential Authority by themselves.
Owner-created email and private-link invitations, pending activation state, and Account lifecycle belong to canonical Account administration. This Access & Security page remains focused on tracked sessions and security boundaries.
Trusted administration within explicit granted scope. Admin does not automatically inherit Owner powers.
Normal product access inside explicit server-owned grants.
Selected resources or time-bounded access with server-authoritative scope and expiry.
Account & access events
Account & Settings now reads the production Account security-event feed. This Access page keeps session controls separate and does not invent revoked or expired session history the API does not expose.
Open Account history. Session lists on this page remain limited to the active-session contract.