Getting started
Profile and access
Every workspace user has one of three roles, and password recovery always goes through a verified OTP challenge rather than an unauthenticated reset link.
How it works
- Forgot-password starts a dedicated reset challenge, verified by OTP before a new password is accepted
- A resend path exists if the original code expires before it's used
- Roles (OWNER, ADMIN, MEMBER) gate which workspace actions a user can take
Good to know
- A forced reset path exists for cases where a temporary password must be replaced before continued access
- Profile changes and role assignment are workspace-scoped and don't cross tenant boundaries

