CRAYS

Settings

UsersRolesModulesIntegrationsData sync

Unified operating platform

Deal Manager

Event-driven dashboards

Settings

Admin areas

OverviewUsersRolesPermissionsModulesOrganizationsStudiosBillingIntegrationsSecurityAudit LogNotificationsBrandingData Sync
AdminPolicy

Security

Manage security posture, session policy, sensitive actions and key guardrails.

Auth boundary

Provider ready

Issued identity

Every account

Role binding

16 / 16

Identity store

Configured

Owner

Security

Core records

4

Permission gates

1

Permission matrix

Initial CRAYS-native permissions for this settings area.

Administer securityManage security policy, sensitive actions and key guardrails.

Allowed roles

Admin

Scopes

global

Auth boundary

Connection state

Provider ready

Configured keys

6 / 8

Callback path

/auth/callback

Provider identity is accepted only after CRAYS maps account, role, organization and scopes.

Nostr identity

Identifier

NIP-05 handle

Stable key

npub / public key

Issued by

CRAYS

Proof methods

NIP07, NIP46, NIP98

Role binding

Required for every role

Every account receives a CRAYS NIP-05 handle and key pair. The private key is handed over once, then role binding uses the public key.

Identity store

Schema version

0001_core_identity

Core tables

10

Protected tables

10

Migration

not_run

Account, role, organization, Nostr challenge and audit records are defined as a CRAYS-owned persistence contract.

Core records

PolicyChallengeSensitive ActionKey Guardrail

Guardrails

Private keys are never stored
Sensitive actions require confirmation
Audit trail is mandatory

Integration boundary

This page defines CRAYS policy and admin structure only. Real reads and writes must pass future API, permission and audit checks.