More screenshots

    Works with the AI tools you already use

    CClaude CodeCCursorCCodex CLIGGitHub CopilotGGemini CLIVVS CodeWWindsurf+15 more

    User Profile & Account Settings UI Architect

    1

    The agent separates information according to scope: Personal settings affect the individual user.

    Secure checkout via Stripe

    0 installsSecurity scanned

    See it in action

    You say

    Product name: TeamHarbor Product type: Multi-tenant B2B SaaS collaboration platform Platforms: Responsive web application iOS companion app Android companion app Primary users: Small-business owners Operations managers Project managers Employees External collaborators User roles: Personal User Workspace Owner Workspace Administrator Billing Administrator Member Restricted Member Guest Collaborator Account model: One personal account can belong to multiple workspaces. Each workspace has separate members, roles, billing, integrations, and data. A user can hold a different role in each workspace. Public profile: Display name Profile photo Job title Short biography Timezone Workspace-visible contact details No fully public web profile in the initial release Private profile: Login email Recovery email Phone number Language Region Accessibility preferences Security methods Session history Authentication methods: Email and password Google sign-in Microsoft sign-in Enterprise single sign-on for approved workspaces Authenticator-app two-factor authentication Passkeys planned but not confirmed Login identifier: Primary verified email address Security features: Password changes Two-factor authentication Recovery codes Active sessions Session revocation Security alerts Enterprise SSO Exact passkey support requires verification Team and role model: Workspace Owner Administrator Billing Administrator Member Restricted Member Guest Exact permissions are supplied through a separate permission matrix Billing model: Workspace-level billing Workspace Owner or Billing Administrator can manage billing Personal users cannot change workspace billing without permission Subscription model: Free Professional Business Enterprise Monthly and annual billing Exact prices, trials, renewal dates, proration, refunds, and cancellation behavior require verification Payment methods: Card payments Invoice billing for approved Enterprise accounts Exact provider behavior requires verification Invoice requirements: Invoice list Invoice number Issue date Amount Currency Status Download Billing entity Tax information where applicable Notification channels: Email Push In-app Browser SMS for approved security events only Notification topics: Security Billing Workspace invitations Mentions Direct messages Task assignments Project updates Weekly digest Product education Marketing Privacy requirements: Workspace profile visibility Email discoverability Activity visibility Personalization Contact matching Blocked users Data export Consent history where required Consent requirements: Marketing consent Product analytics consent in relevant regions Contact-matching consent where applicable Exact legal model requires review Connected accounts: Google Microsoft Apple for mobile where supported Enterprise SSO Users must not disconnect their only login method Integrations: Google Calendar Microsoft Outlook Slack Google Drive Dropbox Zapier-style automation Exact scopes and synchronization behavior require verification Data export: Personal-account export Workspace export for authorized owners Exact contents and completion timing require verification Deactivation: Personal deactivation may be supported Workspace suspension is separate Exact behavior requires verification Account deletion: Users can request personal-account deletion. Workspace owners must transfer ownership or close the workspace first. Billing, retention, backup, legal-hold, and recovery behavior require verification. Suspension or restriction: Security lock Billing suspension Workspace restriction Policy restriction Deletion pending Regional requirements: United States European Union United Kingdom Canada Australia Accessibility target: WCAG 2.2 AA-oriented implementation review Mobile-platform accessibility review Keyboard navigation Screen-reader support 200% zoom Large text Reduced motion Localization: English German French Spanish Portuguese Japanese planned Support text expansion Right-to-left languages planned later Technology stack: Next.js React TypeScript Tailwind CSS shadcn/ui React Native Existing design system Stripe-style billing provider Enterprise identity provider Exact service integrations require verification Need output: Complete profile and account-settings architecture Account model Information architecture Responsive web settings Mobile settings Public and private profiles Personal information Security center Authentication methods Two-factor authentication Sessions and devices Connected accounts Integrations Workspace members Roles Ownership transfer Billing Subscriptions Invoices Payment failures Notifications Privacy Consent Preferences Appearance Language Accessibility settings Data export Account status Restriction states Deactivation Deletion Error states Responsive behavior Accessibility Localization Analytics Experiment roadmap Developer handoff Acceptance criteria Regression tests QA checklist Risk assessment Need variations: Simple MVP Settings Enterprise Trust Center Mobile-First Account Settings Special constraints: Do not invent prices. Do not invent proration. Do not invent retention periods. Do not invent deletion timing. Do not expose private member data. Do not hide cancellation. Do not hide account deletion. Do not allow unsafe disconnection of the only login method. Do not use unsupported security scores. Do not mix personal and workspace settings.

    Your agent does

    === USER PROFILE & ACCOUNT SETTINGS ARCHITECTURE === Product: TeamHarbor Platforms: Responsive web, iOS, and Android Account Model: One personal identity with membership in multiple independent workspaces. Primary Settings Principle: Every setting must clearly indicate whether it affects the individual user, current workspace, or organization. === EXECUTIVE SUMMARY === TeamHarbor requires three distinct settings scopes: 1. Personal Account 2. Current Workspace 3. Organization or Enterprise Controls The current workspace should remain visible in the settings header whenever a workspace-level setting is being changed. Personal security, login identity, language, accessibility, and private profile information should remain consistent across workspaces. Workspace members, roles, billing, integrations, workspace security, and ownership should remain workspace-specific. The highest-risk areas are: - confusion between personal and workspace settings - unsafe login-provider disconnection - unclear billing ownership - incomplete ownership-transfer handling - hidden cancellation or deletion consequences - ambiguous privacy scope - inconsistent save behavior === SETTINGS INFORMATION ARCHITECTURE === Personal Account: - Profile - Personal Information - Security - Sessions and Devices - Notifications - Privacy - Preferences - Connected Login Methods - Personal Data - Account Actions Workspace: - General - Members - Roles and Permissions - Integrations - Workspace Notifications - Security - Billing - Subscription - Invoices - Data - Ownership - Workspace Actions Enterprise: - Single Sign-On - Provisioning - Security Policies - Audit Controls - Billing Administration - Exact capabilities require verification === WEB SETTINGS NAVIGATION === Desktop: Persistent left sidebar with scope switcher above the category list. Header: - Current settings scope - Current workspace - User role - Unsaved-change state where relevant Content: Single primary column for forms. Optional secondary summary for billing or security. Avoid excessive form width. Mobile: Settings index → Category → Subsection → High-risk full-screen flow where necessary Do not reproduce the full desktop sidebar on mobile. === PROFILE ARCHITECTURE === Workspace-Visible Profile: - Display name - Profile photo - Job title - Short biography - Timezone - Approved contact information Private Account Information: - Login email - Recovery email - Phone number - Region - Language - Accessibility preferences Rules: - Explain visibility for every workspace-visible field. - Show a profile preview before saving major public changes. - Keep legal or billing identity outside the public profile. - Use fictional or masked profile data in examples. === EMAIL MANAGEMENT === Current Login Email: s***@example.com Status: Verified Change Flow: Current Email → Enter New Email → Reauthenticate → Verify New Email → Confirm Change Required States: - Verification pending - New email already in use - Reauthentication failed - Verification expired - Change completed - Change failed Do not state that notifications are sent to the previous address unless verified. === SECURITY CENTER === Security Overview: - Password - Two-Factor Authentication - Recovery Codes - Active Sessions - Login Providers - Enterprise SSO - Recent Security Activity Do Not: Display an unsupported numeric security score. Priority Status: Show specific actions such as: Two-factor authentication is not enabled. A recovery method requires attention. A session was recently added. Only use verified security states. === TWO-FACTOR AUTHENTICATION === Method: Authenticator App Flow: 1. Explain the security benefit. 2. Reauthenticate. 3. Display setup code. 4. Verify one-time code. 5. Generate recovery codes. 6. Confirm secure storage. 7. Activate. 8. Show success. States: - Off - Setup Started - Verification Pending - Active - Recovery Required - Disable Pending - Failed Never display real recovery secrets in public documentation. === SESSIONS AND DEVICES === Display: - Device - Operating system - Browser or app - Approximate location where approved - Last active - Current session Actions: - Sign Out - Sign Out All Other Sessions High-Risk Action: Require confirmation and verified reauthentication where approved. === CONNECTED LOGIN METHODS === Google: Connected Microsoft: Connected Password: Set Rule: A user may disconnect a provider only when another verified authentication method remains available. Unsafe Disconnection: Given Google is the only available login method, when the user selects Disconnect, then TeamHarbor prevents the action and explains how to add a password or another verified provider first. === WORKSPACE MEMBERS === Member Row: - Name - Email - Role - Status - Last active where approved - Actions Member Actions: - Change Role - Resend Invitation - Suspend Access - Remove Member Role Change: Show the difference between current and new permissions before confirmation. Removal: Explain access loss, assigned work, shared resources, and verified content-transfer behavior. === OWNERSHIP TRANSFER === Prerequisites: - New owner is an eligible active member. - New owner accepts ownership where required. - Billing and security dependencies are reviewed. Flow: Select New Owner → Review Consequences → Reauthenticate → Confirm → Process → Notify Stakeholders Do not invent transfer timing or reversibility. === BILLING OVERVIEW === Scope: Current Workspace Billing Owner: Workspace Owner or Billing Administrator Display: - Current plan - Status - Verified price - Currency - Billing cadence - Renewal or end date - Default payment method - Billing contact - Invoice access - Cancellation state Every value requires verified billing data. === SUBSCRIPTION STATES === - Free - Trial Eligible - Trial Active - Active - Payment Failed - Grace Period - Cancelled With Access Remaining - Expired - Enterprise Managed Do not invent trial availability, grace periods, proration, refunds, or renewal dates. === CHANGE PLAN FLOW === Current Plan → Compare Plans → Review Feature Differences → Review Effective Date → Review Billing Impact → Confirm → Process → Result The billing impact must come from the verified billing service. === PAYMENT FAILURE === Heading: Payment Method Needs Attention Message: We could not complete the latest billing action. Required Context: - Affected workspace - Current access status - Verified next step - Update Payment Method - Contact Billing Support Do not state when another charge attempt will occur unless verified. === INVOICES === Columns: - Invoice - Date - Amount - Currency - Status - Download Mobile: Convert each invoice into an accessible summary card. Empty State: No invoices are available for this workspace. === NOTIFICATION SETTINGS === Topics: - Security - Billing - Workspace Invitations - Mentions - Direct Messages - Task Assignments - Project Updates - Weekly Digest - Product Education - Marketing Channels: - Email - Push - In-App - Browser - SMS for approved security events Required Communications: Security and billing notifications may remain mandatory according to verified product and legal requirements. Save Model: Immediate save for low-risk toggles with visible success and failure feedback. === PRIVACY CENTER === Categories: - Workspace Profile Visibility - Contact Discoverability - Activity Visibility - Personalization - Product Analytics - Marketing Consent - Contact Matching - Blocked Users - Data Export - Account Deletion Plain-Language Example: Label: Allow workspace members to find me by email Description: When enabled, members of workspaces you belong to may find your account using your verified email address. Use only if that behavior is accurate. === PERSONAL PREFERENCES === - Language - Region - Timezone - Date Format - Time Format - Theme - Density - Reduced Motion - Accessibility Preferences - Default Workspace Changing region should not imply changes to pricing, tax, legal terms, or availability unless verified. === DATA EXPORT === Personal Export: Available to the individual user. Workspace Export: Available only to authorized workspace roles. Flow: Choose Scope → Review Included Data → Reauthenticate → Request Export → Processing → Ready → Expired or Failed Do not promise preparation time without verified service behavior. === ACCOUNT STATUS STATES === Active: Full verified access. Email Verification Pending: Limited account behavior according to verified rules. Security Locked: Access restricted pending approved recovery. Workspace Restricted: Workspace actions limited while personal account remains accessible where supported. Billing Suspended: Billing-dependent workspace access affected according to verified rules. Deletion Pending: Account status and remaining access depend on verified deletion behavior. === PERSONAL ACCOUNT DELETION === Entry: Personal Account → Account Actions → Delete Account Before Confirmation: - Explain personal-data impact. - Explain workspace-membership impact. - Explain workspace-ownership blockers. - Explain subscription impact. - Offer personal export where supported. - Require verified reauthentication. - Explain verified retention and recovery behavior. Ownership Block: Given the user owns an active workspace, when account deletion begins, then the flow explains that ownership must be transferred or the workspace must be closed through the verified process. Do not hide the deletion action behind unrelated retention steps. === SAVE BEHAVIOR === Immediate Save: - Notification preferences - Theme - Low-risk visibility controls Explicit Save: - Profile forms - Personal information - Workspace details Review and Confirm: - Login email - Security methods - Role changes - Billing changes - Ownership transfer - Deactivation - Deletion === RESPONSIVE ARCHITECTURE === Desktop: - Scope switcher - Persistent settings navigation - Focused content column - Accessible tables for sessions, members, and invoices Tablet: - Collapsible navigation - Single-column forms - Reduced table columns - Full-width dialogs where required Mobile: - Settings index - Shallow navigation - Card-based sessions and invoices - Full-screen security and deletion flows - Keyboard-safe forms - Large-text support - Separated Account Actions section - No page-level horizontal scrolling === ACCESSIBILITY REQUIREMENTS === - Semantic headings - Clear form labels - Accessible descriptions - Error associations - Visible keyboard focus - Logical screen-reader order - Accessible toggles - Large touch targets - Non-color status indicators - Accessible tables - Dialog focus management - Bottom-sheet focus behavior - 200% zoom and reflow - Large-text support - Reduced motion - Clear destructive-action language - No claim of conformance without testing === ANALYTICS EVENT MAP === Event: settings_opened Properties: - category - scope - platform Event: two_factor_enabled Properties: - method_category - platform Event: integration_disconnected Properties: - integration_id - scope Event: plan_change_started Properties: - current_plan - target_plan - workspace_type Event: data_export_requested Properties: - export_scope - platform Event: account_deletion_started Properties: - account_state - ownership_block_present Privacy: Do not record passwords, recovery codes, full payment details, private profile values, exported content, or authentication secrets. === EXPERIMENT ROADMAP === Experiment 1: Settings Scope Labels Hypothesis: Persistent Personal or Workspace labels will reduce incorrect-setting changes. Primary Metric: Completed setting changes without immediate reversal Guardrail: Settings abandonment Experiment 2: Security Center Summary Hypothesis: Displaying specific security actions will increase qualified security setup. Primary Metric: Completed two-factor authentication setup Guardrail: Recovery-related support contact Experiment 3: Notification Matrix Hypothesis: Separating topics from channels will improve preference comprehension. Primary Metric: Successful preference changes Guardrail: Immediate preference reversal Do not test hiding billing, privacy, cancellation, or deletion information. === DEVELOPER HANDOFF === Primary Routes: - /settings/profile - /settings/account - /settings/security - /settings/sessions - /settings/notifications - /settings/privacy - /settings/preferences - /settings/data - /settings/account-actions - /workspace/[id]/settings/members - /workspace/[id]/settings/integrations - /workspace/[id]/settings/billing - /workspace/[id]/settings/security - /workspace/[id]/settings/data Route names should follow the actual project architecture. Required Components: - SettingsShell - SettingsScopeSwitcher - SettingsNavigation - SettingsSection - ProfileForm - SecuritySummary - SessionList - ConnectedProviderCard - IntegrationCard - BillingSummary - SubscriptionStatus - InvoiceList - NotificationMatrix - PrivacyControl - MemberList - RoleChangeDialog - OwnershipTransferFlow - DataExportPanel - AccountStatusBanner - AccountDeletionFlow === ACCEPTANCE CRITERIA === Settings Scope: Given a user belongs to multiple workspaces, when the user opens a workspace setting, then the active workspace and setting scope remain visible. Public and Private Identity: Given a user edits a display name and billing name, when changes are reviewed, then the interface explains where each value appears. Unsafe Provider Disconnection: Given a connected provider is the only login method, when the user attempts to disconnect it, then the action is blocked until another verified recovery method exists. Billing Transparency: Given a billing administrator opens Subscription, when data loads, then the verified plan, status, price, currency, cadence, renewal or end date, and cancellation state are visible. Notification Save: Given a notification preference is changed, when saving completes or fails, then the final state is explicit and no silent failure occurs. Deletion Ownership Block: Given the user owns a workspace, when personal deletion begins, then the flow presents the verified ownership-transfer or workspace-closure requirement. Accessibility: Given settings are viewed at 200% zoom, when the interface reflows, then navigation, forms, tables, dialogs, and account actions remain readable and operable. === REGRESSION TEST MATRIX === Account Roles: - Personal User - Workspace Owner - Administrator - Billing Administrator - Member - Restricted Member - Guest Authentication: - Password - Google - Microsoft - SSO - Two-Factor Enabled - Two-Factor Disabled - Recovery Required Billing: - Free - Trial - Active - Payment Failed - Cancelled - Expired - Enterprise Managed Account Status: - Active - Verification Pending - Restricted - Suspended - Deactivated - Deletion Pending Responsive: - Small Mobile - Standard Mobile - Tablet - Laptop - Desktop - 200% Zoom - Large Text Accessibility: - Keyboard - Screen Reader - Visible Focus - Reflow - Reduced Motion - Dialogs - Tables - Forms === QA CHECKLIST === Account Model: - Verify scopes. - Verify ownership. - Verify roles. - Verify billing owner. Profile: - Verify public fields. - Verify private fields. - Verify visibility. - Verify validation. - Verify save behavior. Security: - Verify password. - Verify two-factor authentication. - Verify recovery. - Verify sessions. - Verify provider disconnection. Billing: - Verify plan. - Verify currency. - Verify cadence. - Verify renewal. - Verify payment methods. - Verify invoices. - Verify failures. - Verify cancellation. Notifications: - Verify topics. - Verify channels. - Verify required messages. - Verify immediate save. - Verify failure recovery. Privacy: - Verify plain language. - Verify scope. - Verify discoverability. - Verify consent. - Verify export. - Verify deletion. Team: - Verify invitations. - Verify role changes. - Verify removal. - Verify ownership transfer. - Verify workspace departure. Accessibility: - Verify headings. - Verify labels. - Verify errors. - Verify focus. - Verify keyboard operation. - Verify screen readers. - Verify zoom. - Verify large text. - Verify non-color states. === RISKS === Risk: Users modify the wrong workspace. Mitigation: Keep the active scope and workspace visible throughout the settings experience. Risk: A user disconnects the only login method. Mitigation: Require another verified authentication or recovery method first. Risk: Billing information is incomplete. Mitigation: Display verified plan, price, cadence, renewal, payment, and cancellation status together. Risk: Privacy controls use vague language. Mitigation: Describe the actual data use and consequence in plain language. Risk: Deletion is presented as complete when retained records remain. Mitigation: Use verified retention, backup, legal-hold, and recovery information. Risk: Sensitive values enter analytics. Mitigation: Use event metadata that excludes passwords, payment details, recovery secrets, private profile values, and exported content. === KNOWN LIMITATIONS === - Authentication behavior requires technical and security verification. - Authorization requires the approved permission matrix. - Billing and subscription behavior require payment-provider validation. - Consent and privacy require qualified legal review. - Retention and deletion require verified policy and backend behavior. - Accessibility requires implementation testing. - Localization requires professional review. - Analytics require privacy validation. - The architecture does not guarantee security, compliance, reduced churn, fewer support requests, or higher conversion. === FINAL INTEGRITY NOTE === All authentication, authorization, billing, subscriptions, payments, refunds, permissions, consent, privacy, data retention, data export, account recovery, suspension, deletion, security, legal disclosures, and platform-specific behavior must be verified before implementation. Do not describe account deletion as immediate, complete, reversible, or irreversible unless the actual behavior is confirmed. The account-settings architecture is designed to improve clarity, trust, security awareness, self-service completion, accessibility, and implementation consistency. It does not guarantee lower churn, fewer support requests, legal compliance, security, privacy, or higher conversion.

    What you get

    Architect multi-tenant workspace settings and role-based permissions.Design secure authentication, passkey, and account recovery flows.Model billing summaries, subscription changes, and invoice management.Create localized notification centers and plain-language privacy controls.

    About this skill

    User Profile & Account Settings UI Architect helps SaaS teams, mobile app builders, marketplace founders, fintech products, membership platforms, agencies, product designers, and developers create clear, secure, transparent, and implementation-ready profile and settings experiences.

    The skill supports web applications, mobile applications, responsive SaaS products, multi-tenant platforms, marketplaces, subscription services, e-commerce accounts, enterprise portals, productivity tools, education products, creator platforms, booking systems, financial applications, AI products, internal tools, and team-based workspaces.

    It begins by defining the account model, user roles, ownership model, login identity, profile identity, billing responsibility, workspace structure, data ownership, account states, and regional or platform-specific constraints.

    The agent separates information according to scope:

    Personal settings affect the individual user.

    Profile settings control public or member-visible identity.

    Workspace settings affect a selected team or workspace.

    Organization settings affect organization-wide behavior.

    Billing settings affect the verified billing owner.

    Security settings affect authentication, recovery, sessions, and account protection.

    This separation prevents users from changing the wrong account, workspace, identity, payment method, notification scope, or visibility setting.

    The skill creates settings information architecture for desktop and mobile products. It determines which categories are required, how deeply they should be nested, whether a sidebar, grouped index, tab system, search interface, or mobile stack is appropriate, and how users return to their prior context.

    Supported settings categories can include Profile, Personal Information, Account, Security, Billing, Subscription, Notifications, Privacy, Connected Accounts, Integrations, Preferences, Appearance, Language, Accessibility, Team, Workspace, Data, Support, Legal Information, and Account Actions.

    Profile architecture can distinguish public profile information from private account data. Public fields may include display name, profile image, professional headline, biography, portfolio, website, location, skills, seller details, creator information, or approved credentials.

    Private information may include legal name, login email, contact email, phone number, billing address, region, timezone, language, recovery details, and other verified account attributes.

    Every field can be specified with purpose, visibility, required status, validation, edit permissions, save behavior, error handling, accessibility requirements, and moderation dependencies.

    The skill distinguishes display names, legal names, billing names, login identifiers, contact information, recovery information, and public identity so users understand where each value appears and how it is used.

    Email-management flows can cover login email, contact email, billing email, recovery email, verification, pending changes, reauthentication, duplicate-account conflicts, notifications to the previous address, failed verification, and safe recovery.

    Phone-management flows can distinguish contact, login, recovery, verification, and billing purposes.

    Security-center architecture can include password status, passkeys, two-factor authentication, recovery methods, backup codes, connected login providers, active sessions, trusted devices, recent security activity, suspicious activity, reauthentication, and security alerts.

    The skill avoids unsupported security scores. Instead, it presents specific protections that are active, unavailable, incomplete, or require attention.

    Password flows can include creating, changing, resetting, or removing a password when another verified login method exists. The skill also handles accounts managed through social login or enterprise single sign-on.

    Passkey flows can include availability, setup, device compatibility, multiple passkeys, revocation, recovery implications, unsupported states, and verification requirements.

    Two-factor authentication flows can support approved authenticator apps, SMS, email, hardware keys, backup codes, and other verified methods. The skill defines setup, verification, activation, recovery, regeneration, disabling, failure, and reauthentication states.

    Session and device management can show current sessions, device type, operating system, browser or app, approximate location where approved, last activity, current-session status, trusted status, and revocation actions.

    The agent defines safe actions for signing out one session, signing out all other sessions, revoking a trusted device, and reviewing recent activity.

    Connected-account architecture can support Apple, Google, Microsoft, GitHub, enterprise single sign-on, social providers, and other verified authentication methods.

    The skill prevents unsafe disconnection when a connected provider is the user's only verified method of access. It defines the required recovery or alternative-login setup before disconnection.

    Integration settings can support calendars, storage providers, communication services, CRMs, payment tools, productivity platforms, analytics services, marketplace systems, and approved third-party applications.

    Each integration can show purpose, status, granted permissions, shared data, synchronization state, reconnect options, disconnection consequences, ownership, errors, and accessibility requirements.

    Billing architecture can include current plan, subscription status, price, currency, billing cadence, renewal or end date, payment method, billing contact, tax information, usage, limits, credits, discounts, invoices, payment failures, and verified billing ownership.

    Subscription flows can cover free, trial-eligible, trial-active, active, pending, payment-failed, grace-period, cancelled-with-access, expired, suspended, enterprise-managed, and unavailable states.

    Plan-change flows can explain differences between plans, effective dates, feature impact, usage impact, billing impact, confirmation, processing, success, and failure.

    The skill never invents proration, trial duration, renewal dates, refund eligibility, cancellation terms, payment timing, or pricing.

    Payment-method interfaces can support cards, bank debit, digital wallets, platform billing, invoice billing, backup methods, expiring methods, failed methods, and verification states while masking sensitive information.

    Invoice systems can include invoice number, date, amount, currency, status, billing entity, payment method, downloadable documents, and empty or error states.

    Payment-failure flows explain what failed, whether account access is affected, whether retrying is safe, how to update payment information, and which support route is available.

    Notification architecture separates topics, delivery channels, frequency, urgency, account scope, and quiet hours.

    Possible channels include email, push, SMS, browser, in-app, digest, or other verified delivery methods.

    Possible topics include security, billing, account changes, messages, mentions, product activity, reminders, marketplace activity, system updates, marketing, and product education.

    The skill creates notification matrices showing which channels are available for each topic, which communications are required, which are optional, what defaults apply, and which dependencies exist.

    Required security, billing, legal, or service communications are explained clearly rather than displayed as optional preferences.

    Privacy-center architecture can include profile visibility, activity visibility, discoverability, contact matching, search indexing, personalization, tracking, data sharing, blocked users, consent history, connected data, data export, and deletion.

    Privacy labels use plain language. Vague labels such as “Enhanced Experience” are replaced with explicit descriptions of the relevant behavior, provided that the descriptions accurately reflect the product.

    Visibility controls can distinguish public, member-only, connection-only, team-only, organization-only, and private states.

    Discoverability controls can cover email lookup, phone lookup, contact matching, internal search visibility, external indexing, and other verified discovery methods.

    Personalization controls can explain what data is used, why it is used, what changes when personalization is disabled, and which account or workspace the preference affects.

    Consent interfaces can show consent type, policy version, date, current status, withdrawal actions, and verified consequences. Legal and regional requirements remain subject to qualified review.

    Preference architecture can cover language, region, timezone, date format, time format, currency display, appearance, theme, density, accessibility, default workspace, startup screen, content preferences, and other product-specific choices.

    Appearance settings can support system, light, dark, reduced motion, contrast options, and text-related preferences where implemented.

    Regional preferences clarify whether changing the region affects content, prices, taxes, payment methods, legal terms, availability, currency, or date and time formatting.

    Team and workspace settings can include memberships, roles, invitations, permissions, ownership, billing responsibility, workspace security, member removal, workspace departure, and ownership transfer.

    The skill clearly labels whether a setting affects the user, current workspace, or organization.

    Role-change flows explain the current role, available roles, permission differences, affected access, confirmation, notifications, and recovery.

    Member-removal flows can explain access loss, assigned work, content ownership, billing impact, transfer requirements, and re-invitation where supported.

    Ownership-transfer flows can require eligibility verification, selection of the new owner, consequence review, reauthentication, confirmation, stakeholder notification, and error recovery.

    Data controls can include export requests, export scope, identity verification, preparation, readiness, expiration, failure, download history, import validation, partial success, and verified retention information.

    The skill does not promise export timing or data inclusion without evidence.

    Account-status architecture can support active, verification-pending, limited, restricted, suspended, deactivated, deletion-pending, closed, and recovered states.

    Restriction and suspension interfaces explain what is unavailable, what remains accessible, why the state exists where appropriate, the next action, appeal options where supported, and support access.

    Deactivation is treated separately from deletion. The agent defines profile visibility, login access, subscription impact, retained data, notification behavior, reactivation, and workspace consequences only when supported.

    Account-deletion flows make deletion discoverable and explain verified consequences before the final action.

    Deletion architecture can cover affected personal data, public profile content, workspace ownership, team membership, subscription status, billing obligations, connected accounts, data export, reauthentication, typed confirmation where justified, processing, completion, failure, and verified recovery behavior.

    The skill rejects hidden deletion, unnecessary support-only barriers, emotional manipulation, confirm-shaming, misleading colors, false urgency, and unsupported claims that deletion is immediate or complete.

    Save behavior is standardized according to risk:

    Immediate saving can be used for low-risk toggles.

    Explicit Save can be used for multi-field forms.

    Review and Confirm can be used for billing, security, identity, role, ownership, and destructive changes.

    Every model includes loading, success, failure, dirty-state handling, conflict behavior, cancellation, and recovery.

    The skill creates consistent confirmation patterns using inline messages, toasts, banners, dialogs, or full-screen flows according to the importance and persistence of the change.

    Error architecture can cover validation, authentication, authorization, network, server, billing, payment, integration, stale data, conflicts, expired sessions, verification, deletion, and unknown failures.

    Error messages communicate what happened, what was preserved when verified, and what the user can do next.

    Loading and progress states can cover profile-image uploads, payment updates, integration setup, security activation, data export, plan changes, session revocation, and account deletion.

    The agent avoids fake progress percentages, unsupported completion estimates, and success messages that appear before confirmation.

    Empty states can cover missing profile photos, no integrations, no invoices, no additional sessions, no blocked users, no export history, no team members, and other first-use account areas.

    Responsive architecture adapts the settings experience for desktop, tablet, and mobile instead of merely shrinking the desktop interface.

    Desktop settings may use a persistent sidebar, content panel, tables, multi-column billing summaries, and contextual support.

    Mobile settings use shallow navigation, clear categories, readable forms, card-based alternatives to dense tables, predictable Back behavior, safe-area support, virtual-keyboard handling, separated destructive actions, and no page-level horizontal scrolling.

    Accessibility requirements cover semantic headings, landmarks, labels, descriptions, error relationships, keyboard operation, visible focus, focus management, screen-reader order, touch targets, text resizing, zoom, reflow, contrast, non-color status, reduced motion, dialog behavior, bottom sheets, tables, large text, and destructive-action clarity.

    Localization planning covers long settings labels, legal explanations, deletion language, role names, billing terminology, dates, times, currencies, addresses, phone numbers, right-to-left interfaces, text expansion, and dynamic type.

    Analytics recommendations can track settings navigation, successful self-service actions, failed recovery, security adoption, invoice access, payment recovery, notification changes, privacy changes, integration management, data export, deactivation, and deletion.

    Analytics must not include passwords, recovery codes, complete payment details, sensitive profile data, private files, raw device identifiers, authentication secrets, or confidential setting values.

    The skill also creates account-settings audits, trust-risk reports, severity-ranked findings, experiment roadmaps, screen inventories, developer handoffs, implementation sequences, acceptance criteria, regression tests, QA checklists, open questions, and structured JSON specifications.

    It prioritizes clarity, security awareness, privacy, transparent billing, safe account recovery, consistent save behavior, accessible self-service, truthful account deletion, responsive quality, and implementation readiness.

    The core commercial promise is: create profile and settings experiences that help users confidently manage their identity, security, billing, privacy, preferences, integrations, teams, data, and account lifecycle without confusion or hidden consequences.

    How to install

    Drop the file into your AI Agent. Works with Claude, Cursor, ChatGPT, and 20+ more.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean today

    Listedtoday

    Frequently Asked Questions