More screenshots
Works with the AI tools you already use
User Profile & Account Settings UI Architect
The agent separates information according to scope: Personal settings affect the individual user.
$7.99
User Profile & Account Settings UI Architect
Example session with this skill installed
Product name
TeamHarbor
Product type
Multi-tenant B2B SaaS collaboration platform
Platforms
Responsive web application
iOS companion app
Android companion app
Primary users
Small-business owners
Operations managers
Project managers
Employees
External collaborators
User roles
Personal User
Workspace Owner
Workspace Administrator
Billing Administrator
Member
Restricted Member
Guest Collaborator
Account model
One personal account can belong to multiple workspaces.
Each workspace has separate members, roles, billing, integrations, and data.
A user can hold a different role in each workspace.
Public profile
Display name
Profile photo
Job title
Short biography
Timezone
Workspace-visible contact details
No fully public web profile in the initial release
Private profile
Login email
Recovery email
Phone number
Language
Region
Accessibility preferences
Security methods
Session history
Authentication methods
Email and password
Google sign-in
Microsoft sign-in
Enterprise single sign-on for approved workspaces
Authenticator-app two-factor authentication
Passkeys planned but not confirmed
Login identifier
Primary verified email address
Security features
Password changes
Two-factor authentication
Recovery codes
Active sessions
Session revocation
Security alerts
Enterprise SSO
Exact passkey support requires verification
Team and role model
Workspace Owner
Administrator
Billing Administrator
Member
Restricted Member
Guest
Exact permissions are supplied through a separate permission matrix
Billing model
Workspace-level billing
Workspace Owner or Billing Administrator can manage billing
Personal users cannot change workspace billing without permission
Subscription model
Free
Professional
Business
Enterprise
Monthly and annual billing
Exact prices, trials, renewal dates, proration, refunds, and cancellation behavior require verification
Payment methods
Card payments
Invoice billing for approved Enterprise accounts
Exact provider behavior requires verification
Invoice requirements
Invoice list
Invoice number
Issue date
Amount
Currency
Status
Download
Billing entity
Tax information where applicable
Notification channels
Email
Push
In-app
Browser
SMS for approved security events only
Notification topics
Security
Billing
Workspace invitations
Mentions
Direct messages
Task assignments
Project updates
Weekly digest
Product education
Marketing
Privacy requirements
Workspace profile visibility
Email discoverability
Activity visibility
Personalization
Contact matching
Blocked users
Data export
Consent history where required
Consent requirements
Marketing consent
Product analytics consent in relevant regions
Contact-matching consent where applicable
Exact legal model requires review
Connected accounts
Google
Microsoft
Apple for mobile where supported
Enterprise SSO
Users must not disconnect their only login method
Integrations
Google Calendar
Microsoft Outlook
Slack
Google Drive
Dropbox
Zapier-style automation
Exact scopes and synchronization behavior require verification
Data export
Personal-account export
Workspace export for authorized owners
Exact contents and completion timing require verification
Deactivation
Personal deactivation may be supported
Workspace suspension is separate
Exact behavior requires verification
Account deletion
Users can request personal-account deletion.
Workspace owners must transfer ownership or close the workspace first.
Billing, retention, backup, legal-hold, and recovery behavior require verification.
Suspension or restriction
Security lock
Billing suspension
Workspace restriction
Policy restriction
Deletion pending
Regional requirements
United States
European Union
United Kingdom
Canada
Australia
Accessibility target
WCAG 2.2 AA-oriented implementation review
Mobile-platform accessibility review
Keyboard navigation
Screen-reader support
200% zoom
Large text
Reduced motion
Localization
English
German
French
Spanish
Portuguese
Japanese planned
Support text expansion
Right-to-left languages planned later
Technology stack
Next.js
React
TypeScript
Tailwind CSS
shadcn/ui
React Native
Existing design system
Stripe-style billing provider
Enterprise identity provider
Exact service integrations require verification
Need output
Complete profile and account-settings architecture
Account model
Information architecture
Responsive web settings
Mobile settings
Public and private profiles
Personal information
Security center
Authentication methods
Two-factor authentication
Sessions and devices
Connected accounts
Integrations
Workspace members
Roles
Ownership transfer
Billing
Subscriptions
Invoices
Payment failures
Notifications
Privacy
Consent
Preferences
Appearance
Language
Accessibility settings
Data export
Account status
Restriction states
Deactivation
Deletion
Error states
Responsive behavior
Accessibility
Localization
Analytics
Experiment roadmap
Developer handoff
Acceptance criteria
Regression tests
QA checklist
Risk assessment
Need variations
Simple MVP Settings
Enterprise Trust Center
Mobile-First Account Settings
Special constraints
Do not invent prices.
Do not invent proration.
Do not invent retention periods.
Do not invent deletion timing.
Do not expose private member data.
Do not hide cancellation.
Do not hide account deletion.
Do not allow unsafe disconnection of the only login method.
Do not use unsupported security scores.
Do not mix personal and workspace settings.
- Read your context and instructions
- Compiled the user profile
- Generated the document
=== USER PROFILE & ACCOUNT SETTINGS ARCHITECTURE ===
Product
TeamHarbor
Platforms
Responsive web, iOS, and Android
Account Model
One personal identity with membership in multiple independent workspaces.
Primary Settings Principle
Every setting must clearly indicate whether it affects the individual user, current workspace, or organization.
=== EXECUTIVE SUMMARY ===
TeamHarbor requires three distinct settings scopes:
- Personal Account
- Current Workspace
- Organization or Enterprise Controls
The current workspace should remain visible in the settings header whenever a workspace-level setting is being changed.
Personal security, login identity, language, accessibility, and private profile information should remain consistent across workspaces.
Workspace members, roles, billing, integrations, workspace security, and ownership should remain workspace-specific.
The highest-risk areas are
- confusion between personal and workspace settings
- unsafe login-provider disconnection
- unclear billing ownership
- incomplete ownership-transfer handling
- hidden cancellation or deletion consequences
- ambiguous privacy scope
- inconsistent save behavior
=== SETTINGS INFORMATION ARCHITECTURE ===
Personal Account
- Profile
- Personal Information
- Security
- Sessions and Devices
- Notifications
- Privacy
- Preferences
- Connected Login Methods
- Personal Data
- Account Actions
Workspace
- General
- Members
- Roles and Permissions
- Integrations
- Workspace Notifications
- Security
- Billing
- Subscription
- Invoices
- Data
- Ownership
- Workspace Actions
Enterprise
- Single Sign-On
- Provisioning
- Security Policies
- Audit Controls
- Billing Administration
- Exact capabilities require verification
=== WEB SETTINGS NAVIGATION ===
Desktop
Persistent left sidebar with scope switcher above the category list.
Header
- Current settings scope
- Current workspace
- User role
- Unsaved-change state where relevant
Content
Single primary column for forms.
Optional secondary summary for billing or security.
Avoid excessive form width.
Mobile
Settings index
→ Category
→ Subsection
→ High-risk full-screen flow where necessary
Do not reproduce the full desktop sidebar on mobile.
=== PROFILE ARCHITECTURE ===
Workspace-Visible Profile
- Display name
- Profile photo
- Job title
- Short biography
- Timezone
- Approved contact information
Private Account Information
- Login email
- Recovery email
- Phone number
- Region
- Language
- Accessibility preferences
Rules
- Explain visibility for every workspace-visible field.
- Show a profile preview before saving major public changes.
- Keep legal or billing identity outside the public profile.
- Use fictional or masked profile data in examples.
=== EMAIL MANAGEMENT ===
Current Login Email
s***@example.com
Status
Verified
Change Flow
Current Email
→ Enter New Email
→ Reauthenticate
→ Verify New Email
→ Confirm Change
Required States
- Verification pending
- New email already in use
- Reauthentication failed
- Verification expired
- Change completed
- Change failed
Do not state that notifications are sent to the previous address unless verified.
=== SECURITY CENTER ===
Security Overview
- Password
- Two-Factor Authentication
- Recovery Codes
- Active Sessions
- Login Providers
- Enterprise SSO
- Recent Security Activity
Do Not
Display an unsupported numeric security score.
Priority Status
Show specific actions such as
Two-factor authentication is not enabled.
A recovery method requires attention.
A session was recently added.
Only use verified security states.
=== TWO-FACTOR AUTHENTICATION ===
Method
Authenticator App
Flow
- Explain the security benefit.
- Reauthenticate.
- Display setup code.
- Verify one-time code.
- Generate recovery codes.
- Confirm secure storage.
- Activate.
- Show success.
States
- Off
- Setup Started
- Verification Pending
- Active
- Recovery Required
- Disable Pending
- Failed
Never display real recovery secrets in public documentation.
=== SESSIONS AND DEVICES ===
Display
- Device
- Operating system
- Browser or app
- Approximate location where approved
- Last active
- Current session
Actions
- Sign Out
- Sign Out All Other Sessions
High-Risk Action
Require confirmation and verified reauthentication where approved.
=== CONNECTED LOGIN METHODS ===
Google
Connected
Microsoft
Connected
Password
Set
Rule
A user may disconnect a provider only when another verified authentication method remains available.
Unsafe Disconnection
Given Google is the only available login method,
when the user selects Disconnect,
then TeamHarbor prevents the action and explains how to add a password or another verified provider first.
=== WORKSPACE MEMBERS ===
Member Row
- Name
- Role
- Status
- Last active where approved
- Actions
Member Actions
- Change Role
- Resend Invitation
- Suspend Access
- Remove Member
Role Change
Show the difference between current and new permissions before confirmation.
Removal
Explain access loss, assigned work, shared resources, and verified content-transfer behavior.
=== OWNERSHIP TRANSFER ===
Prerequisites
- New owner is an eligible active member.
- New owner accepts ownership where required.
- Billing and security dependencies are reviewed.
Flow
Select New Owner
→ Review Consequences
→ Reauthenticate
→ Confirm
→ Process
→ Notify Stakeholders
Do not invent transfer timing or reversibility.
=== BILLING OVERVIEW ===
Scope
Current Workspace
Billing Owner
Workspace Owner or Billing Administrator
Display
- Current plan
- Status
- Verified price
- Currency
- Billing cadence
- Renewal or end date
- Default payment method
- Billing contact
- Invoice access
- Cancellation state
Every value requires verified billing data.
=== SUBSCRIPTION STATES ===
- Free
- Trial Eligible
- Trial Active
- Active
- Payment Failed
- Grace Period
- Cancelled With Access Remaining
- Expired
- Enterprise Managed
Do not invent trial availability, grace periods, proration, refunds, or renewal dates.
=== CHANGE PLAN FLOW ===
Current Plan
→ Compare Plans
→ Review Feature Differences
→ Review Effective Date
→ Review Billing Impact
→ Confirm
→ Process
→ Result
The billing impact must come from the verified billing service.
=== PAYMENT FAILURE ===
Heading
Payment Method Needs Attention
Message
We could not complete the latest billing action.
Required Context
- Affected workspace
- Current access status
- Verified next step
- Update Payment Method
- Contact Billing Support
Do not state when another charge attempt will occur unless verified.
=== INVOICES ===
Columns
- Invoice
- Date
- Amount
- Currency
- Status
- Download
Mobile
Convert each invoice into an accessible summary card.
Empty State
No invoices are available for this workspace.
=== NOTIFICATION SETTINGS ===
Topics
- Security
- Billing
- Workspace Invitations
- Mentions
- Direct Messages
- Task Assignments
- Project Updates
- Weekly Digest
- Product Education
- Marketing
Channels
- Push
- In-App
- Browser
- SMS for approved security events
Required Communications
Security and billing notifications may remain mandatory according to verified product and legal requirements.
Save Model
Immediate save for low-risk toggles with visible success and failure feedback.
=== PRIVACY CENTER ===
Categories
- Workspace Profile Visibility
- Contact Discoverability
- Activity Visibility
- Personalization
- Product Analytics
- Marketing Consent
- Contact Matching
- Blocked Users
- Data Export
- Account Deletion
Plain-Language Example
Label
Allow workspace members to find me by email
Description
When enabled, members of workspaces you belong to may find your account using your verified email address.
Use only if that behavior is accurate.
=== PERSONAL PREFERENCES ===
- Language
- Region
- Timezone
- Date Format
- Time Format
- Theme
- Density
- Reduced Motion
- Accessibility Preferences
- Default Workspace
Changing region should not imply changes to pricing, tax, legal terms, or availability unless verified.
=== DATA EXPORT ===
Personal Export
Available to the individual user.
Workspace Export
Available only to authorized workspace roles.
Flow
Choose Scope
→ Review Included Data
→ Reauthenticate
→ Request Export
→ Processing
→ Ready
→ Expired or Failed
Do not promise preparation time without verified service behavior.
=== ACCOUNT STATUS STATES ===
Active
Full verified access.
Email Verification Pending
Limited account behavior according to verified rules.
Security Locked
Access restricted pending approved recovery.
Workspace Restricted
Workspace actions limited while personal account remains accessible where supported.
Billing Suspended
Billing-dependent workspace access affected according to verified rules.
Deletion Pending
Account status and remaining access depend on verified deletion behavior.
=== PERSONAL ACCOUNT DELETION ===
Entry
Personal Account
→ Account Actions
→ Delete Account
Before Confirmation
- Explain personal-data impact.
- Explain workspace-membership impact.
- Explain workspace-ownership blockers.
- Explain subscription impact.
- Offer personal export where supported.
- Require verified reauthentication.
- Explain verified retention and recovery behavior.
Ownership Block
Given the user owns an active workspace,
when account deletion begins,
then the flow explains that ownership must be transferred or the workspace must be closed through the verified process.
Do not hide the deletion action behind unrelated retention steps.
=== SAVE BEHAVIOR ===
Immediate Save
- Notification preferences
- Theme
- Low-risk visibility controls
Explicit Save
- Profile forms
- Personal information
- Workspace details
Review and Confirm
- Login email
- Security methods
- Role changes
- Billing changes
- Ownership transfer
- Deactivation
- Deletion
=== RESPONSIVE ARCHITECTURE ===
Desktop
- Scope switcher
- Persistent settings navigation
- Focused content column
- Accessible tables for sessions, members, and invoices
Tablet
- Collapsible navigation
- Single-column forms
- Reduced table columns
- Full-width dialogs where required
Mobile
- Settings index
- Shallow navigation
- Card-based sessions and invoices
- Full-screen security and deletion flows
- Keyboard-safe forms
- Large-text support
- Separated Account Actions section
- No page-level horizontal scrolling
=== ACCESSIBILITY REQUIREMENTS ===
- Semantic headings
- Clear form labels
- Accessible descriptions
- Error associations
- Visible keyboard focus
- Logical screen-reader order
- Accessible toggles
- Large touch targets
- Non-color status indicators
- Accessible tables
- Dialog focus management
- Bottom-sheet focus behavior
- 200% zoom and reflow
- Large-text support
- Reduced motion
- Clear destructive-action language
- No claim of conformance without testing
=== ANALYTICS EVENT MAP ===
Event
settings_opened
Properties
- category
- scope
- platform
Event
two_factor_enabled
Properties
- method_category
- platform
Event
integration_disconnected
Properties
- integration_id
- scope
Event
plan_change_started
Properties
- current_plan
- target_plan
- workspace_type
Event
data_export_requested
Properties
- export_scope
- platform
Event
account_deletion_started
Properties
- account_state
- ownership_block_present
Privacy
Do not record passwords, recovery codes, full payment details, private profile values, exported content, or authentication secrets.
=== EXPERIMENT ROADMAP ===
Experiment 1:
Settings Scope Labels
Hypothesis
Persistent Personal or Workspace labels will reduce incorrect-setting changes.
Primary Metric
Completed setting changes without immediate reversal
Guardrail
Settings abandonment
Experiment 2:
Security Center Summary
Hypothesis
Displaying specific security actions will increase qualified security setup.
Primary Metric
Completed two-factor authentication setup
Guardrail
Recovery-related support contact
Experiment 3:
Notification Matrix
Hypothesis
Separating topics from channels will improve preference comprehension.
Primary Metric
Successful preference changes
Guardrail
Immediate preference reversal
Do not test hiding billing, privacy, cancellation, or deletion information.
=== DEVELOPER HANDOFF ===
Primary Routes
- /settings/profile
- /settings/account
- /settings/security
- /settings/sessions
- /settings/notifications
- /settings/privacy
- /settings/preferences
- /settings/data
- /settings/account-actions
- /workspace/[id]/settings/members
- /workspace/[id]/settings/integrations
- /workspace/[id]/settings/billing
- /workspace/[id]/settings/security
- /workspace/[id]/settings/data
Route names should follow the actual project architecture.
Required Components
- SettingsShell
- SettingsScopeSwitcher
- SettingsNavigation
- SettingsSection
- ProfileForm
- SecuritySummary
- SessionList
- ConnectedProviderCard
- IntegrationCard
- BillingSummary
- SubscriptionStatus
- InvoiceList
- NotificationMatrix
- PrivacyControl
- MemberList
- RoleChangeDialog
- OwnershipTransferFlow
- DataExportPanel
- AccountStatusBanner
- AccountDeletionFlow
=== ACCEPTANCE CRITERIA ===
Settings Scope
Given a user belongs to multiple workspaces,
when the user opens a workspace setting,
then the active workspace and setting scope remain visible.
Public and Private Identity
Given a user edits a display name and billing name,
when changes are reviewed,
then the interface explains where each value appears.
Unsafe Provider Disconnection
Given a connected provider is the only login method,
when the user attempts to disconnect it,
then the action is blocked until another verified recovery method exists.
Billing Transparency
Given a billing administrator opens Subscription,
when data loads,
then the verified plan, status, price, currency, cadence, renewal or end date, and cancellation state are visible.
Notification Save
Given a notification preference is changed,
when saving completes or fails,
then the final state is explicit and no silent failure occurs.
Deletion Ownership Block
Given the user owns a workspace,
when personal deletion begins,
then the flow presents the verified ownership-transfer or workspace-closure requirement.
Accessibility
Given settings are viewed at 200% zoom,
when the interface reflows,
then navigation, forms, tables, dialogs, and account actions remain readable and operable.
=== REGRESSION TEST MATRIX ===
Account Roles
- Personal User
- Workspace Owner
- Administrator
- Billing Administrator
- Member
- Restricted Member
- Guest
Authentication
- Password
- Microsoft
- SSO
- Two-Factor Enabled
- Two-Factor Disabled
- Recovery Required
Billing
- Free
- Trial
- Active
- Payment Failed
- Cancelled
- Expired
- Enterprise Managed
Account Status
- Active
- Verification Pending
- Restricted
- Suspended
- Deactivated
- Deletion Pending
Responsive
- Small Mobile
- Standard Mobile
- Tablet
- Laptop
- Desktop
- 200% Zoom
- Large Text
Accessibility
- Keyboard
- Screen Reader
- Visible Focus
- Reflow
- Reduced Motion
- Dialogs
- Tables
- Forms
=== QA CHECKLIST ===
Account Model
- Verify scopes.
- Verify ownership.
- Verify roles.
- Verify billing owner.
Profile
- Verify public fields.
- Verify private fields.
- Verify visibility.
- Verify validation.
- Verify save behavior.
Security
- Verify password.
- Verify two-factor authentication.
- Verify recovery.
- Verify sessions.
- Verify provider disconnection.
Billing
- Verify plan.
- Verify currency.
- Verify cadence.
- Verify renewal.
- Verify payment methods.
- Verify invoices.
- Verify failures.
- Verify cancellation.
Notifications
- Verify topics.
- Verify channels.
- Verify required messages.
- Verify immediate save.
- Verify failure recovery.
Privacy
- Verify plain language.
- Verify scope.
- Verify discoverability.
- Verify consent.
- Verify export.
- Verify deletion.
Team
- Verify invitations.
- Verify role changes.
- Verify removal.
- Verify ownership transfer.
- Verify workspace departure.
Accessibility
- Verify headings.
- Verify labels.
- Verify errors.
- Verify focus.
- Verify keyboard operation.
- Verify screen readers.
- Verify zoom.
- Verify large text.
- Verify non-color states.
=== RISKS ===
Risk
Users modify the wrong workspace.
Mitigation
Keep the active scope and workspace visible throughout the settings experience.
Risk
A user disconnects the only login method.
Mitigation
Require another verified authentication or recovery method first.
Risk
Billing information is incomplete.
Mitigation
Display verified plan, price, cadence, renewal, payment, and cancellation status together.
Risk
Privacy controls use vague language.
Mitigation
Describe the actual data use and consequence in plain language.
Risk
Deletion is presented as complete when retained records remain.
Mitigation
Use verified retention, backup, legal-hold, and recovery information.
Risk
Sensitive values enter analytics.
Mitigation
Use event metadata that excludes passwords, payment details, recovery secrets, private profile values, and exported content.
=== KNOWN LIMITATIONS ===
- Authentication behavior requires technical and security verification.
- Authorization requires the approved permission matrix.
- Billing and subscription behavior require payment-provider validation.
- Consent and privacy require qualified legal review.
- Retention and deletion require verified policy and backend behavior.
- Accessibility requires implementation testing.
- Localization requires professional review.
- Analytics require privacy validation.
- The architecture does not guarantee security, compliance, reduced churn, fewer support requests, or higher conversion.
=== FINAL INTEGRITY NOTE ===
All authentication, authorization, billing, subscriptions, payments, refunds, permissions, consent, privacy, data retention, data export, account recovery, suspension, deletion, security, legal disclosures, and platform-specific behavior must be verified before implementation.
Do not describe account deletion as immediate, complete, reversible, or irreversible unless the actual behavior is confirmed.
The account-settings architecture is designed to improve clarity, trust, security awareness, self-service completion, accessibility, and implementation consistency. It does not guarantee lower churn, fewer support requests, legal compliance, security, privacy, or higher conversion.
user-profile-account-settings-ui-archite.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
User Profile & Account Settings UI Architect helps SaaS teams, mobile app builders, marketplace founders, fintech products, membership platforms, agencies, product designers, and developers create clear, secure, transparent, and implementation-ready profile and settings experiences.
The skill supports web applications, mobile applications, responsive SaaS products, multi-tenant platforms, marketplaces, subscription services, e-commerce accounts, enterprise portals, productivity tools, education products, creator platforms, booking systems, financial applications, AI products, internal tools, and team-based workspaces.
It begins by defining the account model, user roles, ownership model, login identity, profile identity, billing responsibility, workspace structure, data ownership, account states, and regional or platform-specific constraints.
The agent separates information according to scope
Personal settings affect the individual user.
Profile settings control public or member-visible identity.
Workspace settings affect a selected team or workspace.
Organization settings affect organization-wide behavior.
Billing settings affect the verified billing owner.
Security settings affect authentication, recovery, sessions, and account protection.
This separation prevents users from changing the wrong account, workspace, identity, payment method, notification scope, or visibility setting.
The skill creates settings information architecture for desktop and mobile products. It determines which categories are required, how deeply they should be nested, whether a sidebar, grouped index, tab system, search interface, or mobile stack is appropriate, and how users return to their prior context.
Supported settings categories can include Profile, Personal Information, Account, Security, Billing, Subscription, Notifications, Privacy, Connected Accounts, Integrations, Preferences, Appearance, Language, Accessibility, Team, Workspace, Data, Support, Legal Information, and Account Actions.
Profile architecture can distinguish public profile information from private account data. Public fields may include display name, profile image, professional headline, biography, portfolio, website, location, skills, seller details, creator information, or approved credentials.
Private information may include legal name, login email, contact email, phone number, billing address, region, timezone, language, recovery details, and other verified account attributes.
Every field can be specified with purpose, visibility, required status, validation, edit permissions, save behavior, error handling, accessibility requirements, and moderation dependencies.
The skill distinguishes display names, legal names, billing names, login identifiers, contact information, recovery information, and public identity so users understand where each value appears and how it is used.
Email-management flows can cover login email, contact email, billing email, recovery email, verification, pending changes, reauthentication, duplicate-account conflicts, notifications to the previous address, failed verification, and safe recovery.
Phone-management flows can distinguish contact, login, recovery, verification, and billing purposes.
Security-center architecture can include password status, passkeys, two-factor authentication, recovery methods, backup codes, connected login providers, active sessions, trusted devices, recent security activity, suspicious activity, reauthentication, and security alerts.
The skill avoids unsupported security scores. Instead, it presents specific protections that are active, unavailable, incomplete, or require attention.
Password flows can include creating, changing, resetting, or removing a password when another verified login method exists. The skill also handles accounts managed through social login or enterprise single sign-on.
Passkey flows can include availability, setup, device compatibility, multiple passkeys, revocation, recovery implications, unsupported states, and verification requirements.
Two-factor authentication flows can support approved authenticator apps, SMS, email, hardware keys, backup codes, and other verified methods. The skill defines setup, verification, activation, recovery, regeneration, disabling, failure, and reauthentication states.
Session and device management can show current sessions, device type, operating system, browser or app, approximate location where approved, last activity, current-session status, trusted status, and revocation actions.
The agent defines safe actions for signing out one session, signing out all other sessions, revoking a trusted device, and reviewing recent activity.
Connected-account architecture can support Apple, Google, Microsoft, GitHub, enterprise single sign-on, social providers, and other verified authentication methods.
The skill prevents unsafe disconnection when a connected provider is the user's only verified method of access. It defines the required recovery or alternative-login setup before disconnection.
Integration settings can support calendars, storage providers, communication services, CRMs, payment tools, productivity platforms, analytics services, marketplace systems, and approved third-party applications.
Each integration can show purpose, status, granted permissions, shared data, synchronization state, reconnect options, disconnection consequences, ownership, errors, and accessibility requirements.
Billing architecture can include current plan, subscription status, price, currency, billing cadence, renewal or end date, payment method, billing contact, tax information, usage, limits, credits, discounts, invoices, payment failures, and verified billing ownership.
Subscription flows can cover free, trial-eligible, trial-active, active, pending, payment-failed, grace-period, cancelled-with-access, expired, suspended, enterprise-managed, and unavailable states.
Plan-change flows can explain differences between plans, effective dates, feature impact, usage impact, billing impact, confirmation, processing, success, and failure.
The skill never invents proration, trial duration, renewal dates, refund eligibility, cancellation terms, payment timing, or pricing.
Payment-method interfaces can support cards, bank debit, digital wallets, platform billing, invoice billing, backup methods, expiring methods, failed methods, and verification states while masking sensitive information.
Invoice systems can include invoice number, date, amount, currency, status, billing entity, payment method, downloadable documents, and empty or error states.
Payment-failure flows explain what failed, whether account access is affected, whether retrying is safe, how to update payment information, and which support route is available.
Notification architecture separates topics, delivery channels, frequency, urgency, account scope, and quiet hours.
Possible channels include email, push, SMS, browser, in-app, digest, or other verified delivery methods.
Possible topics include security, billing, account changes, messages, mentions, product activity, reminders, marketplace activity, system updates, marketing, and product education.
The skill creates notification matrices showing which channels are available for each topic, which communications are required, which are optional, what defaults apply, and which dependencies exist.
Required security, billing, legal, or service communications are explained clearly rather than displayed as optional preferences.
Privacy-center architecture can include profile visibility, activity visibility, discoverability, contact matching, search indexing, personalization, tracking, data sharing, blocked users, consent history, connected data, data export, and deletion.
Privacy labels use plain language. Vague labels such as “Enhanced Experience” are replaced with explicit descriptions of the relevant behavior, provided that the descriptions accurately reflect the product.
Visibility controls can distinguish public, member-only, connection-only, team-only, organization-only, and private states.
Discoverability controls can cover email lookup, phone lookup, contact matching, internal search visibility, external indexing, and other verified discovery methods.
Personalization controls can explain what data is used, why it is used, what changes when personalization is disabled, and which account or workspace the preference affects.
Consent interfaces can show consent type, policy version, date, current status, withdrawal actions, and verified consequences. Legal and regional requirements remain subject to qualified review.
Preference architecture can cover language, region, timezone, date format, time format, currency display, appearance, theme, density, accessibility, default workspace, startup screen, content preferences, and other product-specific choices.
Appearance settings can support system, light, dark, reduced motion, contrast options, and text-related preferences where implemented.
Regional preferences clarify whether changing the region affects content, prices, taxes, payment methods, legal terms, availability, currency, or date and time formatting.
Team and workspace settings can include memberships, roles, invitations, permissions, ownership, billing responsibility, workspace security, member removal, workspace departure, and ownership transfer.
The skill clearly labels whether a setting affects the user, current workspace, or organization.
Role-change flows explain the current role, available roles, permission differences, affected access, confirmation, notifications, and recovery.
Member-removal flows can explain access loss, assigned work, content ownership, billing impact, transfer requirements, and re-invitation where supported.
Ownership-transfer flows can require eligibility verification, selection of the new owner, consequence review, reauthentication, confirmation, stakeholder notification, and error recovery.
Data controls can include export requests, export scope, identity verification, preparation, readiness, expiration, failure, download history, import validation, partial success, and verified retention information.
The skill does not promise export timing or data inclusion without evidence.
Account-status architecture can support active, verification-pending, limited, restricted, suspended, deactivated, deletion-pending, closed, and recovered states.
Restriction and suspension interfaces explain what is unavailable, what remains accessible, why the state exists where appropriate, the next action, appeal options where supported, and support access.
Deactivation is treated separately from deletion. The agent defines profile visibility, login access, subscription impact, retained data, notification behavior, reactivation, and workspace consequences only when supported.
Account-deletion flows make deletion discoverable and explain verified consequences before the final action.
Deletion architecture can cover affected personal data, public profile content, workspace ownership, team membership, subscription status, billing obligations, connected accounts, data export, reauthentication, typed confirmation where justified, processing, completion, failure, and verified recovery behavior.
The skill rejects hidden deletion, unnecessary support-only barriers, emotional manipulation, confirm-shaming, misleading colors, false urgency, and unsupported claims that deletion is immediate or complete.
Save behavior is standardized according to risk
Immediate saving can be used for low-risk toggles.
Explicit Save can be used for multi-field forms.
Review and Confirm can be used for billing, security, identity, role, ownership, and destructive changes.
Every model includes loading, success, failure, dirty-state handling, conflict behavior, cancellation, and recovery.
The skill creates consistent confirmation patterns using inline messages, toasts, banners, dialogs, or full-screen flows according to the importance and persistence of the change.
Error architecture can cover validation, authentication, authorization, network, server, billing, payment, integration, stale data, conflicts, expired sessions, verification, deletion, and unknown failures.
Error messages communicate what happened, what was preserved when verified, and what the user can do next.
Loading and progress states can cover profile-image uploads, payment updates, integration setup, security activation, data export, plan changes, session revocation, and account deletion.
The agent avoids fake progress percentages, unsupported completion estimates, and success messages that appear before confirmation.
Empty states can cover missing profile photos, no integrations, no invoices, no additional sessions, no blocked users, no export history, no team members, and other first-use account areas.
Responsive architecture adapts the settings experience for desktop, tablet, and mobile instead of merely shrinking the desktop interface.
Desktop settings may use a persistent sidebar, content panel, tables, multi-column billing summaries, and contextual support.
Mobile settings use shallow navigation, clear categories, readable forms, card-based alternatives to dense tables, predictable Back behavior, safe-area support, virtual-keyboard handling, separated destructive actions, and no page-level horizontal scrolling.
Accessibility requirements cover semantic headings, landmarks, labels, descriptions, error relationships, keyboard operation, visible focus, focus management, screen-reader order, touch targets, text resizing, zoom, reflow, contrast, non-color status, reduced motion, dialog behavior, bottom sheets, tables, large text, and destructive-action clarity.
Localization planning covers long settings labels, legal explanations, deletion language, role names, billing terminology, dates, times, currencies, addresses, phone numbers, right-to-left interfaces, text expansion, and dynamic type.
Analytics recommendations can track settings navigation, successful self-service actions, failed recovery, security adoption, invoice access, payment recovery, notification changes, privacy changes, integration management, data export, deactivation, and deletion.
Analytics must not include passwords, recovery codes, complete payment details, sensitive profile data, private files, raw device identifiers, authentication secrets, or confidential setting values.
The skill also creates account-settings audits, trust-risk reports, severity-ranked findings, experiment roadmaps, screen inventories, developer handoffs, implementation sequences, acceptance criteria, regression tests, QA checklists, open questions, and structured JSON specifications.
It prioritizes clarity, security awareness, privacy, transparent billing, safe account recovery, consistent save behavior, accessible self-service, truthful account deletion, responsive quality, and implementation readiness.
The core commercial promise is: create profile and settings experiences that help users confidently manage their identity, security, billing, privacy, preferences, integrations, teams, data, and account lifecycle without confusion or hidden consequences.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 2 months ago
- Passed all security checks, Safe to install