CRAYS

Settings

UsersRolesModulesIntegrationsData sync

Unified operating platform

Deal Manager

Event-driven dashboards

Settings

Admin areas

OverviewUsersRolesPermissionsModulesOrganizationsStudiosBillingIntegrationsSecurityAudit LogNotificationsBrandingData Sync
Admin / ManagementFoundation

Users

Manage global accounts, identities, invitations and account lifecycle.

Identity store

Configured

Owner

Platform Admin

Core records

4

Permission gates

2

Account identity

CRAYS account mapping

Provider access, CRAYS ID, Nostr identity, role binding and scope review are managed as one account lifecycle.

contract ready

CRAYS ID

NIP-05reserved per account

Access methods

6mapped to one account

Role binding

16required bindings

Key handoff

One-timeno plaintext storage

Identity lifecycle

Contract stages before live account data can be returned.

1
Provider subjectExternal access method is normalized into one stable provider subject.Platform Admin
blocked until provider
2
CRAYS accountProvider subject maps to a CRAYS-owned account, status and default role.Platform Admin
blocked until persistence
3
CRAYS IDEach account receives a readable NIP-05 handle such as username@crays.net.Security
contract ready
4
Nostr identityEach account receives a CRAYS-issued public identity and signer state.Security
contract ready
5
Role bindingEvery role assignment is bound to the account public identity.Security
contract ready
6
Scope reviewOrganization, studio, deal, project and member scopes are reviewed before access.Operations
manual review
7
Audit readyIdentity, role and key-state decisions create audit events before live use.Security
contract ready

Nostr mapping

CRAYS ID
npub / public key
NIP-05 state
Signer proof
Role binding

Key handoff states

Not createdhidden

Create CRAYS-issued identity after account mapping.

One-time pendingvisible

Show the private key one time, require backup confirmation and remove it from the response path.

Confirmedvisible

Keep public identity, signer state and audit record only.

Not applicablehidden

Use linked external signer proof without CRAYS-generated private key material.

Access method contracts

Every method maps into one CRAYS account and requires Nostr identity.

Contact linkblocked until provider

Simple first access for candidates, partners and members.

provider

Social providerblocked until provider

Consumer-friendly first access through approved identity providers.

provider

Enterprise SSOblocked until provider

Federated access for banks, landlords, suppliers and CRAYS teams.

provider

Passkeyblocked until provider

Phishing-resistant access for high-risk roles.

provider

MFAblocked until policy

Additional proof for sensitive finance, admin and document actions.

provider

Nostr signercontract ready

Portable CRAYS identity proof through a signed challenge.

crays

Role binding policy

Every role assignment is bound to the same public identity before product permissions can be used.

ManagementAdminDeal ManagerExpansion ManagerFinanceHRFranchise CandidateFranchise PartnerStudio ManagerBank PartnerInvestorLandlordVendorReviewerGym MemberGuest

Identity guardrails

Provider identity proves the person; CRAYS grants product access.
Every mapped account receives a CRAYS ID and CRAYS-issued Nostr identity.
Every active role assignment requires public identity binding.
Private keys are shown only once during handoff and are never stored as plaintext.
No live account data, secrets or private keys are returned by the settings contract.
Role, organization, studio, deal, project, member and document scopes are checked server-side.

Permission matrix

Initial CRAYS-native permissions for this settings area.

Read usersView global accounts, memberships and identity state.

Allowed roles

CRAYS ManagementAdminCRAYS HRReviewer

Scopes

globalorganization
Administer usersInvite, suspend, restore and review account access.

Allowed roles

Admin

Scopes

global

Identity store

Schema version

0001_core_identity

Core tables

10

Protected tables

10

Migration

not_run

Account, role, organization, Nostr challenge and audit records are defined as a CRAYS-owned persistence contract.

Core records

AccountIdentityMembershipInvitation

Guardrails

Provider proves identity
CRAYS grants access
No secret values in UI

Integration boundary

This page defines CRAYS policy and admin structure only. Real reads and writes must pass future API, permission and audit checks.