Controlled invitation
A future account can activate only after separate membership, role, and conflict-clearance confirmation.

Milestone 7 · open for validation
KIIRAAY is validating protected accounts, sessions, and authorization architecture before creating a single member user.
Trust chain
Controls repeat server-side, as close as possible to every data read and action.
A future account can activate only after separate membership, role, and conflict-clearance confirmation.
Prefer phishing-resistant authentication; prohibit password-only and SMS as an authentication factor.
Use a revocable server session, HttpOnly/Secure/SameSite cookie, short lifetime, and sensitive reauthentication.
Separate role, territory, and every capability; require two approvers for high-risk actions.
Invalidate sessions and grants on suspension, expiry, role change, or emergency.
Test horizontal and vertical access, deep links, caches, recovery, and revocation.
MySQL lab · no real account
Three fixed choices examine assurance, sessions, authorization, and revocation without receiving a secret or identifying a person.
No account, password, passkey, TOTP secret, token, cookie, session, assignment, or grant is created.
Milestone boundary
The provider, human authorities, residency, recovery, thresholds, and procedures still require approval.
Review the Milestone 8 pilotNo email, phone, member identifier, or password is accepted.
No cookie, token, TOTP secret, passkey, or recovery code is produced.
No role assignment, territorial grant, or map permission is created.
Political routes, APIs, tiles, layers, exports, and publishing remain absent.