IRIDESC E UX · COMMAND
v30 · Program Primary Revision
HVN Viewer Accounts
Separation from Command identity, readiness checklist, account testing, and data-handling boundaries.
Viewer-account principle
HVN viewer accounts are separate from Command employee authentication. Never reuse Command roles, Access admin login, or internal tokens as a viewer-account system.
Before enabling viewer accounts
☐ Public privacy disclosure covers account data
☐ Terms cover account behavior/termination
☐ Password/reset flow works end-to-end if password auth is used
☐ Email sender/domain configured if resets require email
☐ Rate limiting/abuse controls considered
☐ Session cookie security verified
☐ Account deletion/privacy-request workflow exists
☐ No raw verification identity documents stored in D1
☐ Terms cover account behavior/termination
☐ Password/reset flow works end-to-end if password auth is used
☐ Email sender/domain configured if resets require email
☐ Rate limiting/abuse controls considered
☐ Session cookie security verified
☐ Account deletion/privacy-request workflow exists
☐ No raw verification identity documents stored in D1
Account test sequence
- Create disposable viewer account.
- Verify email/reset if enabled.
- Sign out/sign in.
- Test bad password/expired reset.
- Test session persistence and logout.
- Switch market/location settings.
- Verify account does not grant any Command access.
- Delete/disable the disposable account and verify expected data lifecycle.
Data boundary
D1 may store viewer account/profile/application state as designed. R2 may store ordinary user assets only when the product explicitly supports them. Do not store raw government IDs or other high-risk identity documents in generic D1/R2 tables simply because storage exists.