IRIDESC E UX · COMMAND
v30 · Program Primary Revision
INTERNALSTEP-BY-STEP

HVN Viewer Accounts

Separation from Command identity, readiness checklist, account testing, and data-handling boundaries.

Viewer-account principle

HVN viewer accounts are separate from Command employee authentication. Never reuse Command roles, Access admin login, or internal tokens as a viewer-account system.

Before enabling viewer accounts

☐ Public privacy disclosure covers account data
☐ Terms cover account behavior/termination
☐ Password/reset flow works end-to-end if password auth is used
☐ Email sender/domain configured if resets require email
☐ Rate limiting/abuse controls considered
☐ Session cookie security verified
☐ Account deletion/privacy-request workflow exists
☐ No raw verification identity documents stored in D1

Account test sequence

  1. Create disposable viewer account.
  2. Verify email/reset if enabled.
  3. Sign out/sign in.
  4. Test bad password/expired reset.
  5. Test session persistence and logout.
  6. Switch market/location settings.
  7. Verify account does not grant any Command access.
  8. Delete/disable the disposable account and verify expected data lifecycle.

Data boundary

D1 may store viewer account/profile/application state as designed. R2 may store ordinary user assets only when the product explicitly supports them. Do not store raw government IDs or other high-risk identity documents in generic D1/R2 tables simply because storage exists.