Change your own address, and a platform tab for every account

Featurekamo-internal
Ya
4 Septemba 2026, 20:16 UTC
Mwandishi
Kamo
Ahadi ya
285ad5d

Two surfaces, joined by one distinction the platform has never explained to anybody: a user account is the PERSON, and a member is one organization's relationship with that person. My Profile gains a Personal email address card, in the Access room beside the password because that is what it is — one of the three identifiers sign-in accepts, and the address a password reset is mailed to. Filing it under contact details would be filing a key under stationery. It commits itself rather than going through the room's save bar: a change is a request, a letter and a confirmation, and a Save button that wrote a sign-in identifier with no proof the mailbox exists would be the entire problem in one control. The account belongs to the organization named by security_provider_id, and only that one may change it. The card is therefore visible everywhere and editable in one place — hiding it in the others would leave a member hunting for a setting that appears to have been deleted. Where it cannot be edited it says whose it is, and offers both ways back: switching from the top-left menu without leaving the app, and signing in directly at that organization's own sign-in address (or, when it has none yet, at the shared one, named as such). Both come from OrgEntryDomainResolver, so the host is never one that fails to resolve. An explainer sits under the card on EVERY organization, not only inside the refusal. "User account" versus "member account" is a distinction nobody outside the platform has any reason to know, and it becomes load-bearing at exactly the moment somebody is refused something — which is the worst possible time to meet an idea for the first time. /account gains a fourth tab, Users, gated on the new MANAGE_USERS platform right. The right already carries the "current organization must be the platform organization" precondition — PlatformRightsResolver returns nothing at all to a session inside a tenant — so the tab does not check the organization separately; a second authority there could only ever disagree with the server's. Search and paging are the server's too: the grid's own filter searches the rows it happens to hold, which on a platform-wide table means reporting "no results" for an account that exists. The drawer behind a row is banded by consequence rather than by topic. Identity edits into a draft and saves once; account state commits per switch and reports how many sessions went with it; recovery is set apart and confirmed. God accounts and the System User render read-only, because the server refuses them and composing an edit that was never going to land is worse than being told first. Also fixes the security-provider banner that has been on this page all along. It built its link from `org.domain` plus THIS organization's member id — a hostname that is not the workspace host, at a member id that does not exist over there. It now points at the sign-in screen the server resolves.

Mabadiliko yote

Je, unaona nini kuhusu usafiri?

Kila moja ya hizi updates ardhi katika nafasi yako ya kazi moja kwa moja. Kuanza bure na kuangalia kukua wiki baada ya wiki.

Kuwa Huru MileleMtazamo wa bei