Profile
Identity profile
SkyForge reads this identity from the authenticated session and does not maintain a second user directory.
Operator
—
- Full name
- Operator
- —
- Tenant
- —
- Username
- —
Name, email, password and MFA changes belong to the configured StratoID / Authentik authority. SkyForge deliberately refuses to show a successful local edit when no authoritative identity mutation has occurred.
Account security boundary
What SkyForge owns versus what the identity platform owns.
- SkyForge: application roles, tenant-scoped API keys, session visibility, audit evidence and control-plane authorization.
- Identity authority: passwords, MFA factors, primary email, recovery, federation and account lifecycle.
- Platform policy: SpiceDB / authorization decisions remain deny-by-default for protected operations.